What is exfiltration over a remote-access session?¶
The practical answer¶
Exfiltration over a remote-access session involves moving or viewing data through software used to control a device remotely.
The key evidential caution¶
The dangerous assumption is that a remote session proves file transfer occurred.
It may not.
Remote tools may allow:
Key points¶
- file upload and download
- clipboard transfer
- screen viewing
- printing
- drive redirection
- copy and paste
- session recording
- command execution
Evidence to preserve¶
Investigators should preserve:
Key points¶
- the session identifier
- operator account
- source and target devices
- file-transfer logs
- clipboard or drive-redirection settings
- session recording
- chat records
- timestamps
- files accessed
- network activity
A remote operator may view information on screen without creating a separate copied file.
Conversely, files may be transferred through the tool even where ordinary network logs show only encrypted traffic to the remote-service provider.
Evidential limits¶
Do not assume the vendor account holder personally performed the transfer.
The account may be compromised or shared.
Likewise, remote viewing does not automatically establish that the operator retained the information.
Remote viewing may still create serious disclosure even without a file transfer. An operator may read, photograph or transcribe information displayed on screen. That possibility should be reported cautiously because technical records may prove viewing without proving what the remote operator retained outside the session.
If the tool supports clipboard, printing or drive redirection, preserve whether those features were enabled during the session. Configuration can show opportunity, while session records or resulting files are needed to show use.
Record that distinction clearly.
Operational takeaway¶
Identify which remote-session features were used and preserve session, transfer and file-access records before concluding that data was removed.