Data leaves the building in shapes: staging, compression, scope drift, then egress. Most of those shapes happen before the bytes move. Vedric reads the precursor pattern instead of waiting for the alert that comes after the data is already gone.
THE PROBLEM
Network-egress alerts are excellent at telling you something already happened. They are a poor primary signal because the work that mattered - the staging, the compression, the access drift, the scope change - happened upstream. A real data-exfiltration detection layer reads the precursors, then correlates them with the egress event into one storyline an analyst can act on.
Match on file content and patterns. Miss when the staging files do not contain a regex-recognizable secret, when the format has been changed, or when the data moves in chunks that fall under the rule threshold.
Sees the bytes leave. Excellent for forensics, weak for prevention. By the time NetFlow shows the spike, the actor is already past the egress decision.
Sees compression and copy events but does not connect them to scope drift, temporal drift, or privilege drift on the same identity. The pattern is invisible to per-event detection.
Watches sanctioned cloud surfaces. Misses on-premise staging, USB transfer, encrypted transport, or use of cloud surfaces that are sanctioned-but-unusual for this user.
Vedric correlates the four behavioral shapes that precede most exfiltration: scope drift, temporal drift, compression and staging activity, and egress destinations outside the user pattern. A storyline that contains three of those is high-confidence; egress-only is a footnote.
File-access volume rising on systems outside the user normal scope. Compression utilities running outside the user normal toolkit. Bulk reads against repositories the user does not normally touch. These are upstream of egress and are where Vedric promotes the storyline.
Scope drift in week one, temporal drift in week two, an egress to a destination outside the user pattern in week three - same primary identity, same endpoint. Vedric collapses those into one storyline.
When egress correlates with a precursor pattern Vedric was already watching, confidence escalates immediately. The alert that reaches the analyst includes the full chain - not just the egress event.
EXAMPLE SCENARIO · TIMELINE
The actor is a senior researcher leaving the company in two weeks. They have legitimate access to everything they want to take. None of the individual events would trigger DLP.
The egress event was the confirmation. The detection had already materialized two days earlier on the staging pattern. An analyst had a complete chain - staging, compression, scope drift, egress - to bring to legal before the researcher left the building.
Vedric is metadata-only by design. The collector enforces these limits at the source code of the agent.
Read the full privacy stance →Early access is for security teams who treat exfiltration as a pattern to be watched, not a single network event to be alerted on after the data has left.