Skip to content
CIM-164 Cyber Incidents & Offender Methods

What is exfiltration over a remote-access session?

The practical answer

Exfiltration over a remote-access session involves moving or viewing data through software used to control a device remotely.

The key evidential caution

The dangerous assumption is that a remote session proves file transfer occurred.

It may not.

Remote tools may allow:

Key points

  • file upload and download
  • clipboard transfer
  • screen viewing
  • printing
  • drive redirection
  • copy and paste
  • session recording
  • command execution

Evidence to preserve

Investigators should preserve:

Key points

  • the session identifier
  • operator account
  • source and target devices
  • file-transfer logs
  • clipboard or drive-redirection settings
  • session recording
  • chat records
  • timestamps
  • files accessed
  • network activity

A remote operator may view information on screen without creating a separate copied file.

Conversely, files may be transferred through the tool even where ordinary network logs show only encrypted traffic to the remote-service provider.

Evidential limits

Do not assume the vendor account holder personally performed the transfer.

The account may be compromised or shared.

Likewise, remote viewing does not automatically establish that the operator retained the information.

Remote viewing may still create serious disclosure even without a file transfer. An operator may read, photograph or transcribe information displayed on screen. That possibility should be reported cautiously because technical records may prove viewing without proving what the remote operator retained outside the session.

If the tool supports clipboard, printing or drive redirection, preserve whether those features were enabled during the session. Configuration can show opportunity, while session records or resulting files are needed to show use.

Record that distinction clearly.

Operational takeaway

Identify which remote-session features were used and preserve session, transfer and file-access records before concluding that data was removed.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.