What is encrypted exfiltration?¶
The practical answer¶
Encrypted exfiltration is the transfer of data through an encrypted channel or after the data itself has been encrypted.
The key evidential caution¶
The dangerous assumption is that encryption proves malicious concealment.
It does not.
Legitimate services routinely encrypt traffic and stored files.
An offender may use encryption to conceal content, bypass inspection or protect data during transfer.
Investigators should distinguish:
Key points¶
- encrypted network transport
- encrypted archive or file
- encrypted tunnel
- application-layer encryption
- password-protected content
Relevant evidence¶
Relevant evidence may include:
Key points¶
- the process creating the encrypted data
- archive or file metadata
- network destination
- traffic volume and timing
- keys or passwords lawfully recovered
- endpoint and provider records
- later decryption or use
The inability to inspect content does not remove all evidential value.
Metadata may still show the source, destination, process and timing.
But encrypted outbound traffic alone does not prove exfiltration.
It may be ordinary web, VPN or cloud activity.
Encryption may occur before staging, during transfer or within the destination service. Identifying when encryption occurred can help link the source data to the outbound object. A locally created encrypted archive followed by a matching upload is stronger evidence than encrypted traffic alone.
Where keys or passwords are unavailable, avoid assuming the encrypted object contained the suspected data solely because of timing. Correlating size, creation process, source files and destination remains important.
State that uncertainty explicitly and carefully in the final assessment.
Operational takeaway¶
Treat encryption as a feature of the transfer, and prove the source data, process, destination and completion independently of the unreadable content.