What is exfiltration over removable media?¶
This route copies data to a USB drive, external disk, memory card or other removable storage. Device connection proves opportunity, not that a write occurred.
Link device, host and files¶
Preserve stable device identifiers, class, connection and removal times, host, account, write capability and endpoint-control events. File-copy logs, shell artefacts, recent items and the device filesystem can connect particular data to the media.
Nearby file-access times may support but do not prove copying. Charging, installation and authorised work can explain a connection, while policy may record a device even though writing was blocked.
Examine the recovered media and context¶
If recovered, preserve it before examination. Deleted or partial files, filesystem metadata and host traces may reveal copying, reformatting or use on several systems.
Some peripherals expose hidden storage, so confirm device class rather than relying on appearance. Ownership of the media or host does not identify who copied data where systems or devices were shared, unattended or remotely controlled.
Key takeaway
Conclude removable-media exfiltration only by linking a writeable identified device, host session, specific file activity and recovered contents or equivalent copy evidence.