Data Exfiltration

Data leaves two ways, and both are allowed.

ARRTECH DLP, Cyberdroid AI Detection and ARRTECH SOAR

A person moves a file through a channel the company opened: an upload, an email, a USB stick. Malware moves it over a protocol the network trusts, often DNS. Neither looks like theft at the time. MITRE ATT&CK lists exfiltration as its own tactic, TA0010, with techniques for web services, cloud accounts, physical media and command-and-control channels.

Exits

The channels a person uses are the ones a company opened for work. The channel malware prefers is one that is allowed almost everywhere and, in the case of DNS, may be allowed before a device has authenticated.

Upload

Files leave through any application, not only the browser. Encryption hides the content from anything not inline with the traffic.

AI services

A prompt is an upload. Text pasted or a file attached to a generative-AI service leaves the company the same way.

Email

The commonest exit. A draft with the wrong attachment goes to the wrong recipient, from Outlook, another client or a script.

Media

A stick, a disc or a printout. Also the clipboard and a screen capture, which leave no file behind.

Network

Malware copies data out inside DNS queries or beacons to a server it controls. The traffic is small, regular and allowed.

Prevention

Inspecting the browser is not enough. Uploads leave from every application, and the same file leaves by mail, USB and print.

The ARRTECH DLP agent inspects all endpoint traffic at the kernel as an inline proxy, including HTTPS, WebSocket, FTP and SMTP and the encrypted traffic inside them, with no browser extension to disable. The same proxy inspects prompts and uploads to generative-AI services on content, not destination. The Outlook add-in inspects body, subject and attachments before the Send click and removes sensitive attachments from the draft. Kernel-level SMTP protection covers any other mail client or script, and an agentless gateway covers phones and tablets.

Device control allows or blocks USB storage, phones, cameras, printers and external drives by device, user, machine or time window, with whitelisting by serial number. Rules also cover the clipboard and screen capture.

Rules

Blocking every match stops work. Each ARRTECH DLP rule chooses its own response: block, allow and log, ask the user for a justification, or send the file to a supervisor who releases that one file. A rule can also encrypt the file with a company key, so it is readable only where the agent runs.

Every response is attributed to a user and written to the log in the management console, so an investigation starts from a record, not a guess.

Detection

No rule describes malware that has not been written yet, and DNS is allowed on every host. What gives it away is the pattern: queries on a schedule, names that look generated, a host resolving domains nothing else in the estate touches.

Cyberdroid AI Detection, part of the Cyberdroid SOC Platform, the AI layer of the ARRTECH Security Suite, baselines each host’s DNS and network behavior against its own history and detects beaconing, tunneling and algorithm-generated domains. It reads what ARRTECH SIEM, or a third-party SIEM with a supported export, already holds, read-only, near-hourly.

Every finding shows the observed value, the baseline, the score, the threshold crossed and an ordered evidence timeline.

Response

A blocked upload interrupts a person’s work. An isolated host interrupts a team’s. Both are decisions, and they belong to people.

Detection never blocks or changes anything. A score is a prioritization aid, not a verdict. ARRTECH DLP acts only on the rule your team wrote, and approvals go to a named supervisor. When a finding needs action, a person chooses it, and ARRTECH SOAR runs the playbook and keeps the history.

Evaluation

A proof of value runs beside your existing controls on labeled replay scenarios and at least one representative week of your own telemetry. Detection overlap and gaps, evidence completeness, precision and false positives, and time to a defensible disposition are scored against a scorecard agreed before it begins.

Schedule a meeting

Sources

Products

Stops sensitive data leaving through endpoints, email, web, network shares, removable media, printers, generative-AI services and unmanaged devices.

Cross-source behavioral detection on your SIEM: identity, network, DNS, process and firewall telemetry, baselined against each entity’s own history.

Available now

Runs incident playbooks through API integrations, with a human decision built into the flow.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.