What is exfiltration over email or messaging?¶
The practical answer¶
Exfiltration over email or messaging involves sending data through communication services to another account, address or user.
The key evidential caution¶
The dangerous assumption is that attaching or composing a message proves the data was delivered.
It may not.
Data may be sent through:
Key points¶
- email attachments
- links to shared files
- message attachments
- copied text
- screenshots
- exported conversations
- automated forwarding
- bots or APIs
Evidence to preserve¶
Investigators should preserve:
Key points¶
- the message or draft
- sender and recipient identifiers
- attachments or links
- message IDs
- timestamps
- delivery status
- mailbox or platform audit records
- device and process evidence
- later access by the recipient where available
A draft may show preparation without sending.
A sent message may fail delivery.
A delivered message does not prove the recipient opened or used the data.
Evidential limits¶
Likewise, a forwarding rule may send messages automatically without a separate user action each time.
Do not assume the apparent recipient account identifies the offender. The account may be false, compromised or shared.
Communication platforms may also retain deleted or edited messages, attachment identifiers and delivery receipts for a limited period. Request preservation early where provider-held evidence is likely to matter. A user may also send a link rather than the data itself, requiring separate examination of the linked storage service.
Where automatic forwarding is involved, identify when the rule was created, which messages matched and whether delivery succeeded. The offender may obtain continuing copies without manually sending each item.
Operational takeaway¶
Separate message preparation, sending, delivery and recipient access, and preserve the communication, attachment and account records for each stage.