DATA EXFILTRATION DETECTION

Exfiltration is a pattern, not a single egress event.

Vedric correlates archive/replication process metadata, removable-media writes, temporal drift, sensitive-extension inventory changes and host-level network aggregates. These signals can justify review; they do not prove which content moved.

Request Early AccessView PlatformWindows endpoints today.

THE PROBLEM

By the time the egress alert fires, the data has left.

Network-egress alerts show that bytes moved, but not necessarily why. Process and command drift, unusual archive-tool use, removable-media writes and after-hours context can make that signal more useful. Vedric correlates those metadata surfaces while leaving content classification and per-file read evidence to DLP or EDR products that actually collect them.

WHY CURRENT APPROACHES FALL SHORT

Why egress-only detection is too late.

DLP RULES

Match on file content and patterns. Miss when the staging files do not contain a regex-recognizable secret, when the format has been changed, or when the data moves in chunks that fall under the rule threshold.

NETFLOW ANALYSIS

Sees the bytes leave. Excellent for forensics, weak for prevention. By the time NetFlow shows the spike, the actor is already past the egress decision.

EDR FILE TELEMETRY

Sees compression and copy events but does not connect them to scope drift, temporal drift, or privilege drift on the same identity. The pattern is invisible to per-event detection.

CASB

Watches sanctioned cloud surfaces. Misses on-premise staging, USB transfer, encrypted transport, or use of cloud surfaces that are sanctioned-but-unusual for this user.

HOW VEDRIC HELPS

A storyline that catches the staging, not just the egress.

Vedric correlates supported metadata shapes: temporal drift, archive/replication tool use, removable-media write counts and bytes, sensitive-extension inventory changes, and host-level outbound-byte/new-destination-count anomalies. Analysts still determine intent and content sensitivity.

01 /PRECURSORS

Detection on the staging pattern

First-time archive or replication utilities, command-line drift, removable-media writes, and a sensitive-extension inventory change can add staging context. Vedric does not observe bulk reads or repository-level file access.

02 /CORRELATED

Drift across multiple axes, same identity

Command-scope drift in week one, temporal drift in week two, and host-level outbound-byte/new-destination-count drift in week three can be correlated on the same endpoint and identity where attribution evidence exists.

03 /CONFIDENCE

Egress is the confirmation, not the trigger

When host-level outbound-byte or new-destination-count drift correlates with supported precursor metadata, confidence can rise. The evidence remains labeled by collector so an analyst can see what was and was not observed.

EXAMPLE SCENARIO · TIMELINE

A senior researcher staging six months of work.

The actor is a senior researcher leaving the company in two weeks. They have legitimate access to everything they want to take. None of the individual events would trigger DLP.

  1. T+01
    T+01 - endpoint process, network and removable-media baselines are stable.
  2. T+02
    T+04 - the watched sensitive-extension inventory changes. Context logged; no file open or read is inferred.
  3. T+03
    T+07 - 7zip executed for the first time on this endpoint in the user history. Compression-utility deviation logged.
  4. T+04
    T+09 - a removable drive appears and write counts/bytes rise above this endpoint recent pattern. Second axis.
  5. T+05
    T+10 - multiple correlated drifts on the same identity. Storyline materializes; egress not yet observed.
  6. T+06
    T+12 - host-level outbound bytes and new-destination counts rise above baseline. Network drift correlates with the existing storyline and raises urgency.
OUTCOME

The correlated metadata justified investigation before offboarding. It did not establish which files moved; the analyst would combine it with authorized DLP, storage, or forensic evidence before making that claim.

WHAT VEDRIC SURFACES

Read the staging. Then confirm with the egress.

VEDRIC SURFACES
  • Per-endpoint removable-media write counts/bytes and sensitive-extension inventory changes
  • Compression and staging utility execution against historical user pattern
  • Scope drift, privilege drift, and temporal drift correlated as one storyline
  • Host-level outbound-byte, connection, DNS, and new-destination-count baselines
  • Tenant-isolated AI triage that ties all four axes into a single verdict
VEDRIC DOES NOT DO
  • Read file contents to "decide" if data is sensitive
  • Rely on a static block list of compression tools or destinations
  • Capture screenshots, keystrokes, audio, or network payloads
  • Make response decisions without admin approval and a stated reason
  • Operate cross-tenant - every storyline is scoped to a single tenant
PRIVACY-FIRST BY DEFAULT

No keystrokes. No screenshots. No file contents.

Vedric minimizes content by design. The collector enforces the refusal list and the documented bounded PowerShell exception in agent code.

Read the full privacy stance →
  • No keystrokes
  • No screenshots
  • No webcam
  • No microphone
  • No file contents
  • No private messages
FREQUENTLY ASKED

Questions buyers ask first.

Catch the staging. Confirm with the egress.

Early access is for security teams who treat exfiltration as a pattern to be watched well before the data has left.

Request Early AccessTalk to security teamResponse within one business day.