Incident Response & Data Exfiltration

Containing file exfiltration through an unblocked social platform

After a user was found moving files through a social platform outside the organization’s blocklist, I helped drive the response: scoping five years of activity, reviewing affected systems and documents, automating evidence collection and routing, coordinating remediation, and briefing executive leadership.

Capabilities
Incident Response Python Endpoint Telemetry File Analysis Data Classification Executive Reporting
Incident response workflow from file discovery through classification, deletion requests, and executive briefing

Impact & Outcomes

15,000+ Documents Reviewed

Files from the platform’s historical upload activity were collected, organized, and reviewed for sensitivity and business ownership.

5 years Activity Examined

Historical uploads were investigated alongside relevant endpoint and file telemetry to establish the full scope of the event.

4 Sustained Claims

The investigation produced documented findings for Employee Relations and leadership review.

6 Teams Managed

Investigation, evidence review, and remediation coordinated across Legal, HR, SOC, IR, Privacy, and DLP.

The Challenge

An Unmonitored Egress Path

A user had uploaded company files through a social-media platform that existing controls did not block. What began as a single discovery quickly became an incident requiring containment, historical reconstruction, endpoint review, document classification, and coordinated remediation.

Five Years of Historical Scope

The response team needed to examine the platform’s upload history across a five-year lookback, connect activity to the relevant users and machines, determine which documents were sensitive, and identify the correct business owners without losing evidentiary context.

Incident Response & Automation

01. Scope, Collection & Endpoint Review

Reconstructed historical upload activity, examined relevant endpoints for associated file movement, and retrieved controlled copies of the identified documents so investigators could review a consistent body of evidence.

02. Python Evidence Pipeline

Wrote Python scripts to parse and pull the available data, organize documents by user, preserve source context, and produce repeatable review queues instead of relying on manual file handling across thousands of records.

Coordination & Remediation

Business Classification & Deletion Requests

Automated document routing to the appropriate lines of business for classification, coordinated communications with Employee Relations and data-classification teams, and submitted deletion requests for files confirmed to require removal.

Executive Incident Communication

Provided senior leaders and executives with ongoing, non-technical updates that explained what happened, how broadly it extended, which response actions were complete, and which decisions still required leadership attention.