What is exfiltration over removable media?¶
The practical answer¶
Exfiltration over removable media involves copying data to a device such as a USB drive, external disk or memory card.
The key evidential caution¶
The dangerous assumption is that connecting removable media proves data was copied to it.
It does not.
What investigators should establish¶
Investigators should establish:
Key points¶
- which device was connected
- device identifiers
- connection and removal times
- which user and host were involved
- what files were accessed or copied
- whether the device was writeable
- whether the device was later recovered
- what file-system evidence exists
Relevant evidence¶
Relevant evidence may include operating-system device logs, endpoint controls, file-copy events, recent-file records, shell or shortcut artefacts and the removable device itself.
A connected device may be used only for charging, software installation or legitimate work.
Evidential limits¶
Likewise, file-access timing close to the connection may support copying but should not be assumed without corroboration.
If the removable device is recovered, preserve it properly before examination.
Do not assume the device owner was the person who performed the copy.
Shared devices, unattended systems and remote control may complicate attribution.
Where endpoint-control software blocks removable media, preserve both the policy and the enforcement event. A connection may be recorded even though writing was prevented. Conversely, some devices may present as ordinary peripherals while containing storage, so the device class and identifiers should be examined carefully.
The recovered removable device may contain deleted files, partial copies or filesystem metadata linking it to the host. Examination should also consider whether the device was reformatted or used on several systems.
Operational takeaway¶
Link the removable device, host, account, file activity and recovered contents before concluding that data was copied out.