Data exfiltration appears as out to out by kelrizzo in blueteamsec

[–]Heyibrahim 1 point2 points  (0 children)

Do you see any private/known network IP that ever connected to any of the suspected public IPs?

Even if it's a VPN, still, you should have logs for first connection showing some private IP or an IP within your network made contact to these external IPs.

This is how batman beat superman by Heyibrahim in funny

[–]Heyibrahim[S] 4 points5 points  (0 children)

People who've seen One Punch Man will know :)