Did anything
actually leave?
This is the question that decides your regulatory obligations, your disclosure timeline and your insurance claim. It is answered from egress traffic, over a long window, or it is not answered at all.
Exfiltration is visible as abnormal outbound traffic from a host, measured against what that host normally sends. There is no universal threshold — a backup server pushing terabytes nightly is fine, a workstation pushing 300 MB to a new destination at 02:00 is not. The useful signals are destination novelty, volume relative to that host's own baseline, timing, and regularity. Because the question is nearly always asked weeks after the fact, it is answerable only if the outbound traffic from that period was retained.
Six signals, none of them a threshold.
Volume against the host, not the network
A file server and a laptop have completely different normal egress. A single figure applied across the estate produces noise on the servers and silence on the endpoints.
Compare each host against itself last month. That is the only comparison that carries information.
A destination with no history
Volume to a familiar cloud provider is usually business as usual. The same volume to an address the organisation has never contacted is a different event entirely.
Destination novelty is a stronger signal than destination reputation, and it needs no external feed.
Low and slow
Competent exfiltration is paced to stay under whatever it thinks the threshold is. Small transfers, repeated over days or weeks, are designed to be unremarkable at any single moment.
Only visible as a cumulative total over a long window — which is a retention question rather than a detection one.
Regularity a human would not produce
Transfers at consistent intervals, or an outbound session at the same minute each night. People are irregular; scheduled code is not.
Establishing a period requires several periods of history. A week of retention cannot show a fortnightly pattern.
Direction that inverts
Most endpoints receive far more than they send. A workstation whose outbound suddenly exceeds its inbound has changed role, whatever the absolute numbers are.
The inbound-to-outbound ratio per host is simple, cheap and surprisingly effective.
A protocol carrying the wrong thing
DNS and ICMP were not designed to move files, and both are frequently allowed outbound without inspection. Sustained volume over either is worth a look on its own.
Query volume and response sizes far above this network's norm, particularly to one domain.
Four steps, and one that cannot be reordered.
- 1
Baseline egress per host
Per host and per role, not per network. Without this every subsequent number is uninterpretable.
- 2
Rank destinations by novelty, then by volume
New destinations first. A familiar destination with unusual volume is second. Both matter; the first is more often the answer.
- 3
Sum over weeks, not hours
Low-and-slow is invisible in any single window and obvious in the total. This is the step that most often needs retention nobody has.
- 4
Go to the traffic before remediating
Rebuilding the host destroys the evidence of what left it. Preserve the capture window first — it takes minutes and cannot be undone afterwards.
Why this is a retention question
- The question arrives late. Nobody asks "did anything leave" while it is leaving. They ask weeks later, about a period that has to still exist.
- Baselines are per host and learned. Net-Monitor measures each host against its own history rather than against a threshold somebody picked for the whole estate.
- Encryption does not hide the volume. How much went where, when and how often is all visible without decrypting anything.
- No threat feed is involved. Destination novelty is computed from your own history — which is why it works on destinations no feed has ever heard of.
Short answers.
How do you detect data exfiltration on a network?
By comparing each host's outbound traffic against its own history rather than against a fixed threshold, and by prioritising destinations the organisation has no record of contacting. Volume, timing, regularity and the inbound-to-outbound ratio are the useful fields, and low-and-slow transfers only become visible when summed over weeks.
What volume of outbound traffic is suspicious?
There is no figure worth quoting, because it depends entirely on the host. A backup server moving terabytes overnight is normal; a laptop moving 300 MB to an unfamiliar destination at 02:00 is not, despite being thousands of times smaller. Any single threshold across an estate produces noise in one direction and blindness in the other.
Can exfiltration be found if the traffic is encrypted?
Yes, because the questions that matter here are about volume, destination, timing and frequency — none of which encryption conceals. What you lose is the ability to confirm what the data was, which is a question for the endpoint investigation rather than the network one.
How far back do I need traffic to answer this?
Far enough to cover the period under investigation, which is usually much longer than people expect. Low-and-slow transfers are designed to be invisible in short windows, and the incident is typically discovered long after it began — so retention shorter than the dwell time means the answer does not exist.
Related questions.
Could you prove nothing left?
Proving the negative needs the same evidence as proving the positive. We will show you what you would have to work with.