Detect and Investigate Data Theft
Build a safe investigation workflow for suspected infostealer exfiltration and distinguish containment from eradication.
In this lesson, you will learn to:
- Outline a proportionate detection and response workflow for suspected infostealer data theft.
Detect and Investigate Data Theft
This lesson turns exfiltration knowledge into response practice. You will define investigation questions, preserve evidence, isolate the host, assess credential exposure, and communicate uncertainty while the investigation develops.
Contain First, Then Establish Scope
When exfiltration is suspected, the first decisions protect people and evidence. Use the approved process to isolate the device, preserve volatile and relevant endpoint evidence, and prevent further session reuse. Do not assume that deleting the suspicious file removes the exposure; stolen cookies, passwords, and tokens may remain valid elsewhere.
Establish scope with focused questions: which account used the device, which browsers and applications were present, what data locations were accessed, when did collection begin, where did network connections go, and which credentials or sessions must be revoked? Record facts separately from hypotheses. A confirmed file read is different from an assumption that the file was transmitted.
Communicate an interim assessment with confidence and next steps. Tell the account owner and response lead what is known, what is not known, which controls are already active, and what evidence is still required. This prevents the investigation from becoming either false reassurance or uncontrolled panic.