Data exfiltration (which can also be referred to as data extrusion or data theft) is an unauthorized data transfer from a computer. This can either be done by having physical access to the devices in the network or by remotely using automated scripts.
Advanced Persistent Threats (APTs) usually have data exfiltration as the main goal. The goal of an APT is to gain access to a network but remain undetected as it stealthily seeks out the most valuable data.
There may be cases in which the client wants to check both exploitation as well as data exfiltration. This makes the activity even more interesting as exfiltration of data without detection can sometimes be tricky.
In this chapter, we will cover the following topics:
- Exfiltration basics
- CloakifyFactory
- Data exfiltration via DNS
- Data exfiltration via Empire