What is cloud-based exfiltration?¶
The practical answer¶
Cloud-based exfiltration is the unauthorised transfer of data into a cloud service, storage account, collaboration platform or online application.
The key evidential caution¶
The dangerous assumption is that traffic to a familiar cloud provider is legitimate.
It may not be.
An offender may use:
Key points¶
- personal cloud storage
- newly created accounts
- compromised business accounts
- file-sharing links
- web uploads
- synchronisation clients
- cloud APIs
- collaboration platforms
What investigators should establish¶
Investigators should identify:
Key points¶
- the exact provider
- account or tenant
- object or file identifier
- uploading device and process
- source account
- time
- data size
- destination folder or object
- sharing or download activity
- provider-held access records
A connection to the provider alone is weak evidence because the organisation may use the same service legitimately.
The specific account, object and action matter.
Evidential limits¶
Do not assume that an upload completed merely because a request began.
Likewise, a created object may contain partial or different data from what was selected locally.
Provider retention and audit coverage vary and should be checked during casework.
Cloud synchronisation can transfer files automatically after they are placed in a monitored folder. In that case, the local copy event, synchronisation client and provider upload may represent separate stages. Preserve the client configuration and account session so the transfer is not wrongly attributed to a direct manual upload.
Provider-side sharing or link creation may expose data without a conventional upload where the file already existed in the service. Preserve permission changes, link identifiers and recipient access as well as upload events.
Operational takeaway¶
Identify the precise cloud account, object, source process and upload result, and distinguish normal provider use from unauthorised transfer.