A security analyst is investigating a potential insider threat involving unauthorized access to sensitive customer data. Review of proxy logs shows repeated access to a cloud storage service (storage.cloudprovider.com) not approved for sensitive data, followed by large outbound transfers. The analyst also observes unusual login times for the suspect's account. Which of the following log snippets, when combined, would provide the STRONGEST evidence of data exfiltration for the incident report?
- ALog 1: `2023-10-26 10:05:12 user=jsmith src_ip=192.168.1.100 action=login status=success` Log 2: `2023-10-26 10:06:30 user=jsmith dest=storage.cloudprovider.com method=GET path=/data/report.pdf bytes_sent=0`
- BLog 1: `2023-10-26 14:20:00 user=jsmith src_ip=10.0.0.50 action=failed_login reason=bad_password` Log 2: `2023-10-26 14:21:15 user=jsmith dest=internal_share method=PUT path=/docs/project_plan.docx bytes_sent=102400`
- CLog 1: `2023-10-26 03:15:00 user=jsmith src_ip=192.168.1.100 action=login status=success` Log 2: `2023-10-26 03:16:45 user=jsmith dest=storage.cloudprovider.com method=POST path=/uploads/customer_list.csv bytes_sent=52428800`
- DLog 1: `2023-10-26 09:00:00 user=jsmith src_ip=192.168.1.100 action=email_send recipient=external@example.com subject='Meeting notes' attachment=none` Log 2: `2023-10-26 09:01:00 user=jsmith dest=internal_wiki method=GET path=/wiki/policy.html bytes_sent=0`
Show answer & explanationAnswer & explanation
Correct answer: C. Log 1: `2023-10-26 03:15:00 user=jsmith src_ip=192.168.1.100 action=login status=success` Log 2: `2023-10-26 03:16:45 user=jsmith dest=storage.cloudprovider.com method=POST path=/uploads/customer_list.csv bytes_sent=52428800`
Option B shows a successful login at an unusual time (03:15:00), immediately followed by a large POST request (50MB) to an unapproved cloud storage service, strongly indicating data exfiltration. The 'bytes_sent' value is crucial.
Why the other options are wrong
- A. Shows a GET request with 0 bytes sent, indicating data retrieval or browsing, not exfiltration.
- B. Shows a failed login and an internal transfer, not exfiltration to an external unapproved service.
- D. Shows an email send without attachment and internal wiki access, neither indicating data exfiltration.
Data Exfiltration Indicators (Logs)
Log entries that, when correlated, suggest unauthorized transfer of data from an organization's network, often characterized by unusual activity, access to unapproved destinations, and significant outbound data volumes.
- Unusual login times or locations.
- Access to unapproved cloud storage or external services.
- Large outbound data transfers (POST requests, high bytes_sent).
- Access to sensitive files followed by external transfer.
Memory trick: Exfiltration is the 'OUT' of data, often at odd 'TIMES' to 'CLOUD' storage.