Critical severityHARDEC6 steps · 5 phases
Data Exfiltration Response
Response to data exfiltration (large outbound traffic, cloud storage, DNS tunnel) and breach notification process.
Information note
Informational note: In data exfiltration response, precisely determining what data left, over which channel, and when is critical for legal obligations. Cloud storage services and DNS tunneling (MITRE T1048) are frequently used evasion paths; combine proxy logs, NetFlow, and DLP alerts in the correlation engine. After the incident, review the data classification policy and egress filtering controls.
1
Preparation
1 steps- DLP + egress monitoring
DLP, data classification, egress traffic baselines, cloud storage logs.
2
Detection & Analysis
1 steps- Determine what was exfiltrated
What data, what volume, which channel (HTTPS/DNS/cloud), which account/host; impact scope.
3
Containment, Eradication & Recovery
2 steps- Stop the flow
Block target IP/domain/service, lock account, isolate host, stop exfiltration tools.
- Close access
Remove initial access and persistence, fix shares/permissions, reset credentials.
4