DATA EXFILTRATION DETECTION

Exfiltration is a pattern, not a single egress event.

Data leaves the building in shapes: staging, compression, scope drift, then egress. Most of those shapes happen before the bytes move. Vedric reads the precursor pattern instead of waiting for the alert that comes after the data is already gone.

Request Early AccessView PlatformWindows endpoints today.

THE PROBLEM

By the time the egress alert fires, the data has left.

Network-egress alerts are excellent at telling you something already happened. They are a poor primary signal because the work that mattered - the staging, the compression, the access drift, the scope change - happened upstream. A real data-exfiltration detection layer reads the precursors, then correlates them with the egress event into one storyline an analyst can act on.

WHY CURRENT APPROACHES FALL SHORT

Why egress-only detection is too late.

DLP RULES

Match on file content and patterns. Miss when the staging files do not contain a regex-recognizable secret, when the format has been changed, or when the data moves in chunks that fall under the rule threshold.

NETFLOW ANALYSIS

Sees the bytes leave. Excellent for forensics, weak for prevention. By the time NetFlow shows the spike, the actor is already past the egress decision.

EDR FILE TELEMETRY

Sees compression and copy events but does not connect them to scope drift, temporal drift, or privilege drift on the same identity. The pattern is invisible to per-event detection.

CASB

Watches sanctioned cloud surfaces. Misses on-premise staging, USB transfer, encrypted transport, or use of cloud surfaces that are sanctioned-but-unusual for this user.

HOW VEDRIC HELPS

A storyline that catches the staging, not just the egress.

Vedric correlates the four behavioral shapes that precede most exfiltration: scope drift, temporal drift, compression and staging activity, and egress destinations outside the user pattern. A storyline that contains three of those is high-confidence; egress-only is a footnote.

01 /PRECURSORS

Detection on the staging pattern

File-access volume rising on systems outside the user normal scope. Compression utilities running outside the user normal toolkit. Bulk reads against repositories the user does not normally touch. These are upstream of egress and are where Vedric promotes the storyline.

02 /CORRELATED

Drift across multiple axes, same identity

Scope drift in week one, temporal drift in week two, an egress to a destination outside the user pattern in week three - same primary identity, same endpoint. Vedric collapses those into one storyline.

03 /CONFIDENCE

Egress is the confirmation, not the trigger

When egress correlates with a precursor pattern Vedric was already watching, confidence escalates immediately. The alert that reaches the analyst includes the full chain - not just the egress event.

EXAMPLE SCENARIO · TIMELINE

A senior researcher staging six months of work.

The actor is a senior researcher leaving the company in two weeks. They have legitimate access to everything they want to take. None of the individual events would trigger DLP.

  1. T+01
    T+01 - researcher accesses the project archive at the normal cadence. Baseline stable.
  2. T+02
    T+04 - file-access volume rises against repositories the researcher has not touched in months. Scope drift logged.
  3. T+03
    T+07 - 7zip executed for the first time on this endpoint in the user history. Compression-utility deviation logged.
  4. T+04
    T+09 - bulk reads against the partner-IP archive, accessible to the user, but not normally accessed. Scope drift, second axis.
  5. T+05
    T+10 - multiple correlated drifts on the same identity. Storyline materializes; egress not yet observed.
  6. T+06
    T+12 - outbound transfer to a personal cloud destination outside the user historical destination set. Egress correlated with the existing storyline. Storyline promoted to critical.
OUTCOME

The egress event was the confirmation. The detection had already materialized two days earlier on the staging pattern. An analyst had a complete chain - staging, compression, scope drift, egress - to bring to legal before the researcher left the building.

WHAT VEDRIC SURFACES

Read the staging. Then confirm with the egress.

VEDRIC SURFACES
  • Per-user file-access volume baselines by repository and time window
  • Compression and staging utility execution against historical user pattern
  • Scope drift, privilege drift, and temporal drift correlated as one storyline
  • Egress destination tracking against the user historical destination set
  • Tenant-isolated AI triage that ties all four axes into a single verdict
VEDRIC DOES NOT DO
  • Read file contents to "decide" if data is sensitive
  • Rely on a static block list of compression tools or destinations
  • Capture screenshots, keystrokes, audio, or network payloads
  • Make response decisions without admin approval and a stated reason
  • Operate cross-tenant - every storyline is scoped to a single tenant
PRIVACY-FIRST BY DEFAULT

No keystrokes. No screenshots. No file contents.

Vedric is metadata-only by design. The collector enforces these limits at the source code of the agent.

Read the full privacy stance →
  • No keystrokes
  • No screenshots
  • No webcam
  • No microphone
  • No file contents
  • No private messages
FREQUENTLY ASKED

Questions buyers ask first.

Catch the staging. Confirm with the egress.

Early access is for security teams who treat exfiltration as a pattern to be watched, not a single network event to be alerted on after the data has left.

Request Early AccessTalk to security teamResponse within one business day.