What is cloud-based exfiltration?¶
Cloud-based exfiltration is unauthorised movement or exposure of data through cloud storage, collaboration or online applications. Traffic to a provider is weak evidence unless it can be resolved to the account, object and action involved.
Identify both ends of the upload¶
Preserve provider, tenant and account IDs, object or file ID, source device and process, local account, time, size, destination path and upload result. Provider audit and access records may show object creation, sharing and later downloads.
A request can begin and fail, while a created object may contain only part of the selected data. Connect local files or staged material to provider-side content using hashes, names, sizes or application records.
Account for sync and existing cloud data¶
A local copy into a watched folder can trigger automatic transfer. Preserve the sync client, configuration and account session so manual copying and provider upload are not collapsed into one act.
Data already in the service may be exposed by a new share or public link without a fresh upload. Permission changes, recipient access and link identifiers can therefore be as important as transfer logs.
Key takeaway
Prove cloud exfiltration through a specific source, process, provider account, object and completed upload or exposure action - not provider traffic alone.