# Data Exfiltration
**Source:** https://glossary.keenfunnel.com/terms/data-exfiltration
**Language:** German

---

## Technische Erklärung

Exfiltration may occur through network channels, cloud services, removable media, compromised accounts, malicious insiders, covert protocols, or authorised tools used outside policy. It can be rapid or deliberately low-volume to evade detection. Controls include data classification, least privilege, egress filtering, data loss prevention, behavioural monitoring, encryption, and incident response.

## Geschäftliche Relevanz

Exfiltration can expose personal data, intellectual property, credentials, regulated information, and commercial strategy, leading to operational disruption, notification duties, financial loss, and reputational damage.

## Implementierungsbeispiel

An attacker compromises a SaaS administrator account and exports customer records to external storage. Identity telemetry, unusual-download alerts, and egress controls detect and contain the activity.

## Einschränkungen und häufige Missverständnisse

Data exfiltration is an outcome, not a single attack technique. Legitimate transfers can look similar, encrypted traffic reduces content visibility, and prevention controls can disrupt normal work if classification and policies are poorly designed.

## Themen

Cybersicherheit KI-Governance Data Engineering

## Quellen

MITRE ATT&CK — Exfiltration — NIST Cybersecurity Framework — https://www.nist.gov/cyberframework

## Besprechen Sie Ihre Systeme

Benötigen Sie Hilfe bei der Implementierung oder Bewertung dieses Konzepts? Keenfunnel entwirft vernetzte KI-, Automatisierungs- und Datensysteme.

Discovery-Session buchen