Network Perimeter

Outbound Data Exfiltration

Most organisations inspect inbound traffic but have no visibility into what leaves.

What it is

Attackers exfiltrate data through DNS tunnelling, HTTPS to attacker-controlled infrastructure, and legitimate cloud storage services (Mega, Dropbox, OneDrive) that bypass firewall rules allowing common cloud destinations. Without Secure Web Gateway (SWG) and CASB controls, outbound traffic to the internet and to cloud services is uninspected and uncontrolled.

Attack techniques

  • Exfiltration via DNS tunnel (T1048.003)
  • Exfiltration to cloud storage (T1537)
  • Exfiltration via HTTPS C2 (T1041)
  • Use of legitimate cloud services for staging (T1567)

Business impact

Data exfiltration is often the first step toward double extortion. Without outbound traffic controls, it is undetectable until after the fact.