The Exfiltration Was Slow, Quiet, and Consistent for Eight Months

The forensic analysis determined that data had been leaving the environment since the previous March. Not in bulk transfers that would have triggered volume-based alerts.

RCDr. Richard Chingombe · Founder, Verisq·5 min read·Practitioner perspective, not legal advice

In small, consistent batches that looked like normal API traffic to any monitoring system calibrated for anomalous volume. The attacker had studied the environment's baseline before beginning the exfiltration. They knew what normal looked like. They stayed within it. The security team's detection capability had been designed to find the abnormal. This exfiltration was carefully normal.

The Detection Problem

Most data exfiltration detection is designed around deviations from baseline: large file transfers, unusual data access volumes, unexpected outbound connections, data movement to unfamiliar destinations. These detections catch the attacker who moves quickly, who is not familiar with the target environment, and who prioritizes speed over stealth. They do not catch the attacker who is patient, who studied the environment before beginning, and who moves within the baseline that the detection system treats as normal.

Patient, low-and-slow exfiltration is among the hardest detection problems in enterprise security. The signals it produces — slightly elevated API call rates, modest increases in outbound data volume, regular access to data stores that are accessed regularly — are individually indistinguishable from legitimate operational activity. The pattern that reveals the exfiltration is only visible in aggregate, across time, with the benefit of knowing what to look for.

Eight months of exfiltration before detection is not a failure of security investment. The organization had security controls. It had monitoring. It had anomaly detection. The attacker operated within the envelope that those controls defined as normal. The detection failure was not in the controls themselves — it was in the assumption that attacker behavior would look abnormal when measured against a baseline of normal operations.

An attacker who understands your detection baseline can operate within it indefinitely. The detection capability you have built is a signal that tells sophisticated attackers what behavior they need to mimic. Build detection that does not depend entirely on behavioral anomaly.

What Patient Exfiltration Looks Like

The attacker's methodology, reconstructed from the forensic timeline, was methodical. Initial access was established through a compromised service account credential. The first two weeks were reconnaissance: the attacker mapped accessible data stores, identified the specific records of value, and observed the access patterns of legitimate users and automated processes to understand what normal traffic looked like. The exfiltration began in the third week, at a rate calibrated to stay within the observed baseline.

The data left through an API endpoint that was regularly used by legitimate integrations. The attacker's exfiltration requests were formatted identically to legitimate integration requests. The destination was a cloud storage account the attacker had established before the campaign. The outbound connections went to a cloud provider whose IP ranges were on the organization's allowlist because the same cloud provider hosted legitimate services.

Every element of the attack was designed to look like normal operations. The legitimate integration traffic was the camouflage. The detection systems, designed to find anomalies against a baseline of legitimate traffic, found nothing to flag.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

The Detection Layers That Low-and-Slow Defeats

Volume-Based Thresholds

Data loss prevention systems and network monitoring tools commonly trigger alerts when data transfer volumes exceed defined thresholds. A threshold calibrated to alert at 10 times the normal daily volume will not detect exfiltration running at 1.1 times the normal daily volume for eight months. The total data exfiltrated may be far larger than any single day's threshold, but the daily rate never crosses the alert boundary. Volume thresholds detect volume anomalies. Patient exfiltration avoids volume anomalies.

Destination-Based Detection

Monitoring outbound connections for unfamiliar or suspicious destinations will not detect exfiltration through a destination that is on the allowlist because it shares an IP range with a legitimate service. The attack used a cloud storage account in the same provider whose ranges were trusted. The destination looked familiar. The traffic to that destination was carrying exfiltrated data.

Behavioral Anomaly Detection

User and entity behavioral analytics that flag deviations from established baselines will not detect a service account whose behavior has been carefully calibrated to remain within its established baseline. The service account accessed the same data stores it normally accessed, at rates consistent with its normal behavior, through the same paths it normally used. The behavior was normal. The purpose was not.

Building Detection That Addresses Patient Exfiltration

Detection that addresses patient exfiltration requires moving beyond anomaly detection toward content-aware and context-aware inspection. Content inspection that examines what data is leaving the environment — not only how much — can identify exfiltration of specific sensitive data categories regardless of whether the volume is anomalous. A DLP policy that detects outbound transfers containing customer personal data identifiers will catch the low-rate transfer that volume thresholds miss.

Destination analysis that goes beyond IP range allowlisting to assess the purpose and business context of outbound connections can identify connections that are technically to allowlisted destinations but that lack the business context that legitimate integrations would have. The attacker's cloud storage account has no business relationship with the organization. The legitimate integration services do. Business context verification does not stop at IP range.

Data access auditing at the record level — tracking which specific records are accessed, by which identities, at what rate, and whether that rate is consistent with the operational purpose of the accessing identity — produces a signal that volume-based monitoring misses. A service account that has accessed the same 50,000 customer records 240 times over eight months has done something that no legitimate integration requires. Record-level access auditing makes that pattern visible.

Build detection that asks what is leaving, not only how much. Patient attackers win against volume thresholds.

Audit at the record level. Inspect the content of what leaves. Verify the business context of outbound destinations. The attacker who defeats your volume thresholds is visible in all three.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.