Access, staging and transfer evidence
Data Exfiltration Forensic Investigation
Independent examination of endpoint, identity, cloud, email, removable-media and network records to test whether data was accessed, staged, transferred or found outside the authorised environment.
Direct access to Alistair Ewing · Free initial consultation · Written estimate before work
Do not turn possible access into a claim of proven theft
Data exfiltration is often suspected because files were opened, an archive was created, a cloud tool was installed, a USB device was connected, an outbound connection appeared or an attacker claimed to hold information. Those observations matter, but they answer different questions. A defensible investigation separates opportunity, access, collection, attempted transfer, observed transfer and external possession.
The evidence may span employee endpoints, compromised accounts, email, collaboration platforms, cloud storage, removable media, remote access and network controls. The useful source set depends on who or what is suspected, the relevant data, the event window, retention and the exact proposition to be tested. Broad searches without a defined purpose can add cost and privacy risk without improving the answer.
The report records what each source shows and where a conclusion depends on inference rather than a recorded event. It may establish the transfer of identified files, support a more limited conclusion about staging or volume, or explain why the available records cannot distinguish successful transfer from preparatory activity. Legal and regulatory teams then apply that technical picture to their own duties.
Questions an exfiltration review may address
- Which data repositories, user folders, mailboxes, shares or cloud locations were available to the relevant account or device.
- Whether records show searches for identified files, or those files being accessed, selected, copied, synchronised, compressed, staged or deleted.
- Whether removable media, personal email, file-sharing services, cloud storage, remote sessions or transfer tools were used during the relevant period.
- Whether proxy, firewall, network-flow, DNS or service-provider records support attempted or successful outbound transfer.
- Whether a transfer can be linked to particular files or content, only to a session or volume, or to neither.
- Whether activity is better explained by authorised work, backup, synchronisation, security tooling, administration or another reasonable process.
- Which accounts, endpoints and external services are implicated, without assuming that an account record identifies the person responsible.
- What evidence is missing and how that affects confidence, estimates of the affected data and further collection decisions.
Sources that may help distinguish the stages
- File-system, recent-item, archive, application, execution and user-activity artefacts from relevant endpoints or images.
- Removable-media history and file-system records from available authorised devices.
- Email, mailbox, message trace, collaboration and attachment records.
- Cloud storage, SaaS, identity, authentication and administrative audit logs.
- Endpoint detection and response (EDR), data loss prevention (DLP), security information and event management (SIEM) and other retained security telemetry with the original alert context.
- Firewall, proxy, DNS, VPN, network-flow and remote-access records within their retention windows.
- File hashes, names, sizes, timestamps, repository inventories and defined sensitive-data lists.
- Incident notes, interviews or business records used only as context and tested against the technical sources.
Exfiltration evidence ladder
Five stages that should not be collapsed into one conclusion
1. Opportunity or access
An identity or device could reach the repository, or records show that files were opened. This does not establish copying or transfer.
2. Collection or staging
Files were gathered, copied locally, synchronised or placed in an archive. The destination and purpose may still be unresolved.
3. Attempted transfer
A tool, command, upload request or connection is observed, but the records do not establish whether it completed or what was received.
4. Observed transfer
Endpoint, service or network records support a completed transfer. The volume may be clearer than the exact files.
5. External possession or publication
Evidence from a recipient, external service or published sample supports possession elsewhere. The identity of the person responsible and the completeness of the material can remain uncertain.
Internal and external scenarios
The same question can arise from different events
A departing employee may be suspected of using USB storage, personal email or a file-sharing account. A compromised identity may have accessed cloud files before a ransomware event. An authorised administrator or backup process may also produce large transfers. The investigation tests the records against the proposed scenarios and normal business activity rather than treating every transfer as misconduct.
Where an external attacker is suspected, the data assessment is aligned with the broader incident chronology. Where an employee or contractor is involved, authority, employment process, privacy, device ownership and legal-hold requirements should be addressed with the instructing team before collection.
Potential deliverables
Technical findings that legal and response teams can use
- A source-by-source exfiltration evidence matrix.
- A chronology of access, staging, transfer and response events.
- A schedule of identified files, repositories, accounts, devices and external services.
- A reasoned confidence assessment with alternative explanations and gaps.
- A focused technical report, conference note or expert report according to the instruction.
Why certainty may be limited
- Many network and cloud records retain connection or volume information without the transferred content.
- TLS encryption, shared services, NAT, proxies and privacy controls can limit destination and content visibility.
- File access, archive creation, USB connection or use of a transfer application does not alone prove successful exfiltration.
- Logs may be short-lived, disabled, sampled, overwritten or changed by containment and account remediation.
- Account and device activity does not automatically identify the person responsible, purpose or authorisation.
- An attacker’s claim, file listing or sample needs separate validation and may be incomplete or misleading.
- Technical findings inform, but do not decide, employment, notification, liability, privilege or criminal questions.
What helps define a useful scope
- Party, organisation, employee, contractor, insurer and adviser names for conflict checking.
- The suspected event, whether the concern relates to an employee, contractor or external compromise, the relevant dates and why exfiltration is suspected.
- The data or repositories in issue and whether a known file list, hash set or data classification exists.
- The endpoints, accounts, cloud services, removable media and network controls potentially involved.
- Available logs, forensic images, exports, retention deadlines and actions already taken.
- The precise questions about access, staging, transfer, content or external possession to be tested.
- The legal, regulatory, employment, insurer or board timetable and the form of output required.
Please do not attach evidence, passwords or confidential case papers to the public enquiry. A secure route is agreed only after the conflict check.
Independent technical references
Logging and data-protection context
The NCSC introduction to logging for security purposes explains why usable logs need a defined purpose, suitable detail and protection. Its guidance on reducing data exfiltration by malicious insiders covers the wider organisational context.
The ICO’s ransomware and data-protection compliance guidance discusses evidence, exfiltration assessment and personal-data breach considerations. The technical report informs the organisation and its advisers; it does not make the notification decision for them.
Frequently asked questions
What is the difference between data access and data exfiltration?
Access evidence may show that an account had permission to reach data or that files were opened. Exfiltration requires evidence relevant to moving data outside the authorised environment. The investigation separates access, staging, attempted transfer, observed transfer and external possession.
Can network logs show exactly which files were stolen?
Sometimes an application or service audit identifies the objects. Often a network record shows only a destination, connection, timing or volume, especially where traffic was encrypted. The report should state the level of detail the records actually support.
Does creating a ZIP archive prove data theft?
No. It can be strong evidence of collection or staging when aligned with relevant files and later activity, but archives also have legitimate uses. Destination, transfer records, timing and business context matter.
Does a connected USB device prove files were copied to it?
No. Device history may show connection and timing. File-system or endpoint records may provide more, but the removable device itself and a reliable correlation are often needed to establish copied content.
Can you investigate uploads to personal email or cloud storage?
Potentially, using authorised endpoint, mailbox, browser, cloud, DLP and network records. Coverage depends on the service, encryption, retention and lawful access. The scope should identify the suspected route rather than search every possible service.
Can you prove that no data left the organisation?
Usually no. A thorough review can state what was checked and whether evidence of transfer was found, but incomplete logging and unobserved routes mean absence of evidence cannot normally prove a universal negative.
Does encryption without theft still matter for data protection?
It can. Loss of availability can itself be relevant to a personal-data breach even if exfiltration is not established. The organisation and its advisers decide notification and risk questions using the technical findings and current ICO guidance.
Can this be combined with a ransomware or employee investigation?
Yes. The exfiltration analysis can form part of a broader incident or workplace investigation, but it should retain its own questions and evidence matrix so a general chronology does not overstate the data conclusion.
Read all questions about fees, timing, evidence and instructing Alistair
Initial enquiry
Need to test a suspected data-transfer claim?
Describe the allegation, relevant dates, data in issue, suspected route, systems and records available, and the decision the work must inform. Do not send evidential files or sensitive data through the website.

