The unfortunate fact is that most organizations will be compromised -- and after being compromised attackers will successfully exfiltrate stolen data. The methods used to remove this data are usually surreptitious, and sometimes clever. For example, several years ago attackers were able to successfully exfiltrate stolen data via a hacked smart fish tank. More recently, researchers proved that smart bulbs could be used to steal data. Since the techniques used are so varied, cyber defenders should be familiar them to be able to better detect and mitigate them. In this session attendees will learn:The most common techniques used to exfiltrate stolen data; The role of compression and encryption to obfuscate data; Why data exfiltration may occur only at certain times of day; How exfiltration is conducted on an air-gapped network; How data exfiltration is performed over C&C channels; and How and why adversaries use mediums other than the C&C channel to steal data. The presenter will also share why adversaries usually exfiltrate data in fixed size chunks and limit packet sizes and tow data exfiltration is performed with protocols that are different from the main C&C protocol or channel. After this session, attendees will be better able to better detect data exfiltration attempts and, as a result, will be better prepared to defend their networks.