Exfiltrated File - Did What

This topic provides details to help you understand how to define alert rule conditions using the options available in the Exfiltrated File group category in the Did what? section of the Create Alert Rule page. (For more about the Did what? section, see Defining the "Did What?" Conditions.)

This option is available for alert type rules on Windows and Mac-based operating systems.

An alert can be configured when a file is exfiltrated to the following destinations:

  • To any destination: An alert is triggered when a file is exfiltrated to any destination, such as any website, cloud sync folder, webmail, social media sites and file sharing sites.

  • To website/web-application (Upload): An alert is triggered when a file is uploaded to any website or web-application, including webmail, social media sites and file sharing sites. Uploads can be detected on any file, whether tracked or non-tracked. An uploaded file is not subsequently tracked by ObserveIT.

  • To cloud storage sync folder: An alert is triggered when a tracked file is moved or copied to a local cloud storage sync folder, such as Box.

  • To USB device: An alert is triggered when a tracked file is copied or downloaded to a USB device.

  • By attaching it to an email client: An alert is triggered when a tracked file is attached to an email client.

  • By sending it via email: An alert is triggered when a tracked file is sent via email.

To create an alert when a file is exfiltrated to any destination

Select What file origin? and choose from the dropdown list:

  • Any origin (default)
  • Downloaded Exported from web
  • Saved from an email client
  • Taken from cloud storage sync folder

Select From Which Website/Web-Application? and choose from the dropdown list:

This option is available only when you select What file originDownloaded exported from web.

  • Any website/web-application (default)
  • Website name
  • Website URL
  • Website Window Title
  • Website Category

Select Which file? and choose from the dropdown list:

  • Any file (default)
  • Exfiltrated File Name
  • Exfiltrated File Path
  • Original File Name
  • File size (in KBs)

Select MIP Label of the file and choose from the dropdown list:

  • Any label of no label (default)
  • Original file label
  • Exfiltrated file label

To any website/web application (Upload) 

File is exfiltrated and uploaded to a website or web application including social media.

Select To which Website/Web-Application? and choose from the dropdown list:

  • Any website/web-application (default)
  • Website name
  • Website URL
  • Website Window Title
  • Website Category

Select What file origin? and choose from the dropdown list:

  • Any origin (default)
  • Downloaded/Exported from web
  • Saved from an email client
  • Taken from cloud storage sync folder

Select From Which Website/Web-Application? and chose from the dropdown list:

This option is available only when you select What file originDownloaded exported from web.

  • Any website/web-application (default)
  • Website name
  • Website URL
  • Website Category

Select Which file and choose from the dropdown list:

  • Any file (default)
  • Exfiltrated File Name
  • Exfiltrated File Path
  • Original File Name
  • File size (in KBs)

Select MIP Label of the file and choose from the dropdown list:

  • Any label of no label (default)
  • Original file label
  • Exfiltrated file label

To cloud storage sync folder

File is exfiltrated to a cloud storage sync folder.

Select To which cloud storage sync folder? and choose from the dropdown list:

  • Any sync folder (default)
  • Vendor name

    In version 7.10, this option is available for Microsoft Box only.

Select What file origin? and choose from the dropdown list:

  • Any origin (default)
  • Downloaded Exported from web
  • Saved from an email client
  • Taken from cloud storage sync folder

Select From Which Website/Web-Application? and choose from the dropdown list:

This option is available only when you select What file originDownloaded exported from web.

  • Any website/web-application (default)
  • Website name
  • Website URL
  • Website Category

Select Which file and choose from the dropdown list:

  • Any file (default)
  • Exfiltrated File Name
  • Exfiltrated File Path
  • Original File Name
  • File size (in KBs)

Select MIP Label of the file and choose from the dropdown list:

  • Any label of no label (default)
  • Original file label
  • Exfiltrated file label

To USB device

File is exfiltrated to a USB device.

Select By: and choose from the dropdown list:

  • Any method (default)
  • Copy/Move to USB
  • Downloading directly to USB

Select To: and and choose from the dropdown list:

  • Any USB (default)
  • Unlisted USB
  • White listed USB
  • USB whose vendor
  • USB whose model
  • USB whose label
  • USB whose S/N
  • USB whose ID

Select What file origin? and choose from the dropdown list:

  • Any origin (default)
  • Downloaded Exported from web
  • Saved from an email client

Select MIP Label of the file and choose from the dropdown list:

  • Any label of no label (default)
  • Original file label
  • Exfiltrated file label

By attaching it to an email client

File is exfiltrated by attaching it to an email client.

Selelct What file origin? and choose from the dropdown list:

  • Any origin (default)
  • Downloaded Exported from web
  • Saved from an email client
  • Taken from cloud storage sync folder

Select From Which Website/Web-Application? and choose from the dropdown list:

This option is available only when you select What file originDownloaded exported from web.

  • Any website/web-application (default)
  • Website name
  • Website URL
  • Website Category

Select Which file and choose from the dropdown list:

  • Any file (default)
  • Exfiltrated File Name
  • Exfiltrated File Path
  • Original File Name
  • File size (in KBs)

By sending it via email

File is exfiltrated by sending it via email.

Select To and choose from the dropdown list:

  • Any recipients (default)
  • All recipients are within trusted domains (Yes/No)
  • At least one recipient address
  • Number of recipients
  • BCC recipients exist

Select Sender Address and choose from the dropdown list:

  • Any address (default)
  • Sender address

Select Email Subject and choose from the dropdown list:

  • Email subject

Select What file origin? and choose from the dropdown list:

  • Any origin (default)
  • Downloaded Exported from web
  • Saved from an email client
  • Taken from cloud storage

Select From Which Website/Web-Application? and choose from the dropdown list:

This option is available only when you select What file originDownloaded exported from web.

  • Any website/web-application (default)
  • Website name
  • Website URL
  • Website Category

Select Which file and choose from the dropdown list:

  • Any file (default)
  • Exfiltrated File Name
  • File size (in KBs)

Select MIP Label of the file and choose from the dropdown list:

  • Any label of no label (default)
  • Original file label
  • Exfiltrated file label

Examples of How to Create Rules for Exfiltrated Files

These are some examples of the alert created for exfiltrated files.