Vedric correlates archive/replication process metadata, removable-media writes, temporal drift, sensitive-extension inventory changes and host-level network aggregates. These signals can justify review; they do not prove which content moved.
THE PROBLEM
Network-egress alerts show that bytes moved, but not necessarily why. Process and command drift, unusual archive-tool use, removable-media writes and after-hours context can make that signal more useful. Vedric correlates those metadata surfaces while leaving content classification and per-file read evidence to DLP or EDR products that actually collect them.
Match on file content and patterns. Miss when the staging files do not contain a regex-recognizable secret, when the format has been changed, or when the data moves in chunks that fall under the rule threshold.
Sees the bytes leave. Excellent for forensics, weak for prevention. By the time NetFlow shows the spike, the actor is already past the egress decision.
Sees compression and copy events but does not connect them to scope drift, temporal drift, or privilege drift on the same identity. The pattern is invisible to per-event detection.
Watches sanctioned cloud surfaces. Misses on-premise staging, USB transfer, encrypted transport, or use of cloud surfaces that are sanctioned-but-unusual for this user.
Vedric correlates supported metadata shapes: temporal drift, archive/replication tool use, removable-media write counts and bytes, sensitive-extension inventory changes, and host-level outbound-byte/new-destination-count anomalies. Analysts still determine intent and content sensitivity.
First-time archive or replication utilities, command-line drift, removable-media writes, and a sensitive-extension inventory change can add staging context. Vedric does not observe bulk reads or repository-level file access.
Command-scope drift in week one, temporal drift in week two, and host-level outbound-byte/new-destination-count drift in week three can be correlated on the same endpoint and identity where attribution evidence exists.
When host-level outbound-byte or new-destination-count drift correlates with supported precursor metadata, confidence can rise. The evidence remains labeled by collector so an analyst can see what was and was not observed.
EXAMPLE SCENARIO · TIMELINE
The actor is a senior researcher leaving the company in two weeks. They have legitimate access to everything they want to take. None of the individual events would trigger DLP.
The correlated metadata justified investigation before offboarding. It did not establish which files moved; the analyst would combine it with authorized DLP, storage, or forensic evidence before making that claim.
Vedric minimizes content by design. The collector enforces the refusal list and the documented bounded PowerShell exception in agent code.
Read the full privacy stance →Early access is for security teams who treat exfiltration as a pattern to be watched well before the data has left.