What is encrypted exfiltration?¶
Encrypted exfiltration transfers data through an encrypted channel or after encrypting the data itself. Encryption is routine in web, VPN and cloud services, so it proves neither malicious concealment nor exfiltration.
Identify where encryption occurred¶
Distinguish encrypted transport, an encrypted archive, a tunnel, application-layer encryption and password-protected content. Preserve the creating process, source files, archive or object metadata, destination, timing, volume and provider records.
The sequence matters. A locally created encrypted archive followed by a matching upload is stronger than unidentified encrypted traffic. Encryption may instead occur inside the destination service after an ordinary upload.
Work around unreadable content carefully¶
Lawfully recovered keys or passwords may permit direct comparison. Without them, correlate size, creation time, process, source access and destination object; do not assume contents from timing alone.
Metadata can still prove a transfer route and completed object while content scope remains uncertain. Report those propositions separately rather than allowing encryption to inflate or erase the evidence.
Key takeaway
Treat encryption as a feature of an evidenced transfer and prove source, process, destination and completion independently of content visibility.