Exfiltration involves transferring data out of the controlled environment.
Indicators may include:
- unusual volumes
- unusual destinations
- connections to certain infrastructures
- transfers at unusual times
- simultaneous access to large amounts of data.
The SIEM can correlate these events with those of endpoints and identities.