Data exfiltration occurs when an adversary covertly transfers stolen data out of a network, sometimes using disguised DNS queries to avoid detection. Recognizing the signs of this technique is essential for identifying and stopping unauthorized data theft.
Data Exfiltration
If we're seeing some sort of strange communication coming across our network, then one of the things we need to look into is whether there's some sort of data exfiltration. Data exfiltration is when an adversary is trying to get data out of the network. Maybe they stole it off of a server and now they're trying to tunnel it to the outside world.
There are stealth techniques they can use to do this data exfiltration. One of them is using DNS queries. A DNS query is what resolves a domain name. In this case, we've got some strange host with example.com. If we spot that there are a lot of these example.coms going out, but they're all different host names, and really strange host names at that, this is a sign that this is data that's being stolen from us.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →