51x Over Baseline: Catching the Exfiltration Every Control Approved

Avatar photo
Austin Zide August 25, 2026

Each download and upload looked like an authorized user doing authorized things. Measured against the account’s own history, it was three years of financial records leaving in one sitting.

At a large IT Services company, a customer-support employee’s account downloaded 63 confidential financial archives from corporate Google Workspace and, within minutes, uploaded them to a personal Discord account. The endpoint’s data-loss controls processed every file and allowed each one. Artemis flagged the download burst, then reconstructed the download-to-Discord chain and measured it against the account’s own baseline: first-ever Discord activity, a volume far beyond anything the account had done before, and a coherent three-year record set. That context is what turned “files moved” into “exfiltration.”

What happened

On an otherwise ordinary morning, a customer-support employee’s account pulled 63 archives out of corporate Google Workspace in about six minutes. Every one was labeled confidential, and together they held three consecutive years of monthly invoice records. All of it landed on the employee’s own managed device, on the corporate network.

Within a few minutes the same account started uploading, this time to a personal Discord account. Over roughly fifty minutes, all 63 archives went out. The endpoint’s data-loss controls saw every download and every upload and allowed each one.

Time (UTC)What happenedATT&CK
11:12 to 11:1863 confidential financial archives downloaded from corporate Google Workspace to a managed device; each allowed by the controlsT1530
11:15 to 11:1841 files pulled in a 12-minute window from a sensitive SaaS (the detection point)T1530
~11:20 to 11:24All 63 archives uploaded to a personal Discord account; each allowed by the controls

Why nothing looked wrong

Nothing in this sequence is individually suspicious. An authorized user, on a managed device, downloaded files they had access to, then uploaded files to a web destination over ordinary traffic. No malware, no failed login, no external address to block. Data-loss prevention that only logs isn’t preventing anything, but the deeper problem is that a per-file verdict cannot see the thing that made this a theft. The signal only exists in the sequence, and only when you know what this account normally does.

How Artemis caught it

Artemis analyzes the endpoint, browser, and SaaS audit telemetry directly. Its detector for bulk downloads from a sensitive SaaS fired on the burst, 41 files in twelve minutes, independent of the verdict the controls had assigned to each file.

That was the entry point. From there Artemis asked the questions a per-file verdict cannot answer:

  • Had this account ever used this destination? It had not. Against a 30-day baseline of zero, this was the account’s first Discord upload of any kind.
  • Was this volume consistent with the account’s history? It was not. The upload exceeded the account’s prior single-day maximum for external transfers many times over, a change in the nature of the activity rather than in its intensity.
  • Did the exfiltrated data form a coherent set? It did. Three consecutive years of confidential monthly billing records is a deliberately assembled collection, not the byproduct of routine access.
  • Were the download and the upload the same event? They were. The 63 archives that left Workspace were the 63 archives that reached Discord, from the same account, minutes apart.

Each answer in isolation is a data point. Taken together and measured against the account’s established behavior, they describe an account collecting years of financial records and moving them off-network. The controls evaluated each file and found nothing objectionable. Artemis evaluated the sequence against the account’s history and identified an exfiltration.

For defenders

  1. Treat a DLP “allowed” verdict as telemetry, not assurance. A DLP that logs and permits gives you a complete record of an exfiltration and stops none of it. Do not read “allowed” as “fine.” Alert on bulk downloads of sensitive or confidential-labeled files followed by uploads to personal or messaging destinations, especially the ones the DLP waved through.
  2. Rank on the user’s own baseline, not a fixed threshold. The signal here was not the raw file count. It was first-ever use of a personal exfiltration channel and a jump many times over this account’s prior maximum. A per-user baseline catches the employee who has never once touched Discord moving dozens of files to it in one sitting, where a static rule would either miss it or drown in noise.
  3. Watch the full sequence. A bulk download from a corporate SaaS is routine. The same account uploading the same volume to a personal Discord account or personal cloud minutes later is the exfiltration. Correlate the two into one sequence and score the sequence.

Detection as a prompt

Role: Triage browser, SaaS, and data-access telemetry across the org's own logs.
Trigger: A burst of file downloads of sensitive or confidential-labeled documents from a corporate SaaS by a single account within a short window.

Investigate, in order:
1. Characterize what was downloaded: sensitivity labels, volume, and whether it forms a coherent high-value set (consecutive financial records, a full contract set, a source-code tree) versus scattered access.
2. Look for uploads of comparable volume from the same account to an external or personal destination (Discord, personal cloud, webmail) in the minutes after the download.
3. Measure both against the account's own baseline: has it ever used this destination, and how does the volume compare to its prior maximum.
4. Check the DLP or browser control verdicts, and remember that an "allowed" verdict on every file is consistent with a permissive tool that logs but does not block.
5. Check the account's authentication around the same window for account-takeover signals that would distinguish a compromised session from a deliberate insider.

Do not treat a DLP "allowed" verdict, a managed device, or an authorized user as exoneration. The access can be legitimate and the data movement still a theft.
Code language: HTTP (http)

Details are drawn from real findings in a customer environment. Details are anonymized and indicators sanitized.

Table of contents
    Get a personalized demo

    Ready to See Everything and Stop Anything?

    Book a personalized demo and see what Artemis is building differently and how it can anticipate anything in your environment.

    Book A Demo
    2
    B+
    events processed every hour
    15,000
    + TB
    data processed daily
    2,000
    +
    insights generated daily