Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is exfiltration over a remote-access session?

Remote-access software can move or expose data through file transfer, clipboard, drive redirection, printing, screen viewing or commands. A remote session establishes none of those uses by itself.

Determine which feature operated

Preserve session ID, operator account, source and target, product configuration, file-transfer history, clipboard and drive settings, recording, chat, accessed files and network activity. Provider-encrypted traffic may conceal file movement from ordinary network inspection while product logs retain it.

Configuration shows opportunity; session events and resulting files show use. The platform account may be shared or compromised, so controller attribution requires additional evidence.

Report viewing and retention carefully

An operator can read, photograph or transcribe displayed information without transferring a file. That can establish disclosure risk, but technical records may not prove what was retained outside the session.

Conversely, enabled clipboard or printing does not show those features were exercised. State whether the evidence supports viewing, feature use, completed transfer or only capability.

Key takeaway

Identify the specific remote-session feature and evidence of its use, distinguishing viewing, transfer capability, completed movement and operator identity.

Reference: CIM-164Cyber Incidents & Offender Methods