Data Exfiltration Pattern Detector

Screen a forensic timeline for patterns potentially consistent with data movement through removable media, staging, cloud transfer, email, or print/export activity. Findings require contextual review and do not independently establish intent, attribution, or unauthorized transfer.

USB / Removable Media Staged Collection Cloud / Web Upload Email Exfiltration Print / Export

Get ranked findings, confidence labels, and short review-ready summaries.

Start a Local Scan

Choose a CSV Timeline

Screen a timeline for potentially relevant data-movement patterns.

Choose or drop a CSV timeline

CSV only, up to 25 MB. Files at or above 8 MB use large-file mode.

Ready to Analyze

Choose a CSV timeline above, then select “Scan for Exfiltration Patterns.”

Your evidence is processed locally in your browser and is not uploaded to Precision Forensics.

Ready to analyze

Technical Details

    Scan Diagnostics

    Live stage timings for local scan performance.

    Stage Status Time Details

    This is a screening tool, not a final expert opinion. Indicators may also reflect legitimate activity and require review against source artifacts and case context.

    Try a Demonstration Scenario

    Use synthetic demonstration data to see how the detector identifies potentially relevant data-movement patterns.

    Build: 6860b7b · 2026-05-06T17:55:53Z