ArcanaIncident-response documentationBrowse the feedTemplates
Back to feed
Playbook
PB-005

Data Exfiltration

1. Purpose & Scope

  • Purpose:

    This playbook outlines the end-to-end response process for suspected or confirmed data exfiltration incidents involving unauthorised access, collection, staging, transfer, theft, or exposure of organisational data. It is designed to identify impacted data, determine exposure scope, contain active exfiltration activity, preserve evidence, and coordinate legal, regulatory, and business response activities.

  • Scope:

    Applies to all suspected or confirmed data exfiltration incidents across the organisation, including insider threats, external compromises, cloud and SaaS abuse, unauthorised file transfers, sensitive data exposure, and threat actor collection activities.

2. Incident Identification & Criteria

Incident Type: Data Exfiltration

Trigger Conditions:

  • DLP alert generated
  • Large outbound transfer detected
  • Unusual cloud upload activity identified
  • Suspicious archive creation activity detected
  • Sensitive file access anomalies observed
  • Unauthorised SaaS sharing identified
  • Insider threat indicators observed
  • Threat actor collection behaviour identified
  • Third-party notification of exposed data received

Severity Levels:

SeverityDescription
Sev 3Suspicious transfer activity with no confirmed exposure
Sev 2Confirmed exfiltration of limited data
Sev 1Confirmed exfiltration of sensitive, confidential, or regulated data
Sev 0Large-scale data theft, public exposure, or critical business impact

3. Roles & Responsibilities

  • Incident Commander: Coordinates and leads the incident response effort, approves containment actions, and manages escalation decisions.

  • Incident Responder / Forensic Analyst: Performs forensic investigation, determines exfiltration scope, preserves evidence, reconstructs the attack timeline, and identifies root cause.

  • Communications Lead: Coordinates internal and external communications, executive updates, and stakeholder notifications.

  • Other Roles:

    • Identity & Access (IAM) Team: Locks down compromised accounts, revokes sessions/tokens, and rotates credentials.
    • Cloud Security Team: Investigates and remediates exfiltration via cloud storage, SaaS, and cloud workloads.
    • Data Owners: Assess data sensitivity, regulatory classification, and business impact.
    • Legal & Compliance: Assesses regulatory and breach notification obligations; owns external notification decisions.
    • HR / People Team: Engaged where insider activity is suspected or out-of-band user contact is required.

4. Initial Actions

  • Immediate Steps:

    • Triage the originating alert or report to validate it represents real exfiltration activity
    • Determine whether exfiltration is currently active (e.g. traffic to known C2 / suspicious domain, uploads to personal cloud storage)
    • Determine what type and volume of data is being exfiltrated (sensitive file names/paths, large size, high file count)
    • Identify the account(s) and host(s) being used to perform the exfiltration

    Decision Point:

    • Active exfiltration identified โ†’ Proceed immediately to Containment actions
    • Historical exfiltration only โ†’ Continue Investigation & Analysis

5. Investigation & Analysis

6. Containment, Eradication & Recovery

7. Communication & Escalation

8. Post-Incident Activities

  • Lessons Learned:

    • Schedule and conduct a Post-Incident Review (PIR)
    • Document timeline and root cause
    • Identify detection and response gaps
    • Assess effectiveness of containment actions
    • Review data governance controls
  • Documentation Updates:

    • Update this playbook as required
    • Update associated runbooks
    • Update detection content and monitoring logic
    • Update data handling and governance procedures

9. References & Linked Resources

10. Appendices

Contributor

Vishal Thakur
GitHub: https://github.com/malienist

Jayden Vo
GitHub: https://github.com/jayden-vo

Contributed to the Arcana Incident Response Documentation Framework.