- Nationwide Digital Forensic & Cyber Investigation Services
Endpoint evidence shows what ran. Network evidence shows what left. In exfiltration disputes, extortion claims, and notification decisions, flow records and proxy logs are frequently the only sources that can quantify what actually crossed the perimeter.
Updated August 2026 · Reviewed by Elite Digital Forensics examiners · Nationwide breach response
| Question | One line answer |
|---|---|
| Can you see what was inside encrypted traffic? | Generally no, without interception at a proxy. Metadata and volume still carry substantial weight. |
| What proves command and control? | Regular periodic connections of consistent size to an unfamiliar destination, corroborated by endpoint process data. |
| How is exfiltration volume measured? | Outbound byte counts per host and destination from flow, firewall, or proxy records, compared with a baseline. |
| How long is packet capture kept? | Usually days, because full capture consumes terabytes daily. |
| Do internal firewalls matter? | Yes. East to west records are often the only proof of lateral movement between servers. |
| What if nothing was logged? | The correct finding is that the record neither confirms nor excludes transfer, and that should be stated plainly. |
| Term | What it means |
|---|---|
| Flow record | A summary of a network conversation including source, destination, ports, byte counts, and duration, without packet contents. |
| Full packet capture | A complete copy of network traffic including payload, limited in practice by storage cost. |
| Zeek | An open source network monitoring platform that produces structured connection, name resolution, and certificate logs. |
| Beaconing | Repeated outbound connections at regular intervals, characteristic of malware checking in with its operator. |
| Client fingerprinting | Techniques that identify the software initiating an encrypted session from handshake characteristics rather than content. |
| Egress baseline | A normal outbound volume profile for a host or user, against which anomalous transfers are measured. |
Very few organizations have full packet capture. Almost all have some combination of the following, and a competent examiner works with what exists rather than lamenting what does not.
| Source | What it proves | Typical retention |
|---|---|---|
| Flow records from routers and switches | Which hosts talked to which destinations, when, and how many bytes moved | 30 to 90 days when collected |
| Firewall logs | Allowed and denied sessions at the perimeter and between internal zones | 30 to 90 days on device, longer if forwarded |
| Web proxy or secure gateway logs | Destination hostnames, categories, user attribution, and transfer sizes | 30 to 180 days by product tier |
| Name resolution logs | Domains resolved by each internal host, which surfaces command and control and tunneling | 30 to 90 days when enabled |
| Virtual private network concentrator logs | Remote access sessions, source addresses, and durations | 30 to 90 days |
| Cloud provider flow logs | Traffic to and from cloud workloads, including exfiltration from a cloud environment | As configured, often 30 to 90 days |
| Network monitoring platform logs | Structured connection, certificate, and protocol metadata suitable for deep analysis | As configured |
Nearly all outbound traffic is now encrypted, and newer protocol features conceal even the destination hostname during the handshake. This is often described as the end of network forensics. It is not.
Where an organization performs inspection at a gateway, content may be available and should be handled with care for privacy and legal restrictions. Where it does not, the analysis is metadata driven and the report should say so.
Extortion claims and notification decisions both hinge on volume. We analyze the traffic evidence and give you a defensible answer.
When a criminal group claims to hold hundreds of gigabytes of company data, the business, its counsel, and its carrier all need to know whether that claim is plausible. Network records are the primary test.
Establish normal outbound volume for the host, the user, and the destination category over a comparable prior period.
Identify outbound sessions during the intrusion window that deviate materially in volume, destination, or timing.
Tie each anomalous session to a process on the endpoint and an authenticated user where proxy logs allow.
Compare measured volume against staging archive sizes found on disk and against the volume claimed by the extortion group.
Where retention or coverage prevents measurement, report that the evidence neither confirms nor excludes transfer.
That last step matters more than any other. Regulators, carriers, and courts respond well to an examiner who distinguishes proven transfer from unproven possibility, and poorly to one who treats absence of evidence as proof either way.
Perimeter logging is common. Internal visibility is rare, and that is exactly where intrusions expand.
Broad internal file share access from a single host is a strong indicator of discovery and staging activity.
Unusual use of remote procedure call and management protocols between workstations frequently marks the pivot path.
Replication style traffic originating from a non domain controller indicates credential replication abuse.
Where internal firewalls exist, denied session records can also demonstrate that segmentation limited the blast radius, which is useful to carriers and regulators.
Content is hidden, but destination, timing, volume, and client fingerprint remain, and those are usually sufficient to characterize the activity.
Full capture at a busy egress point is typically retained for days. The incident window is usually already gone by the time anyone looks.
Small, slow, sustained transfers evade volume thresholds, and some intrusions never involve exfiltration at all.
Internal firewall and flow records are often the only evidence that an intruder moved between servers.
| Source | Content visibility | Volume accuracy | User attribution | Typical retention |
|---|---|---|---|---|
| Full packet capture | Full, subject to encryption | Exact | Indirect | Days |
| Flow records | None | Byte counts per session | By address only | 30 to 90 days |
| Proxy or secure gateway | Hostnames, sometimes content | Good | Yes, by account | 30 to 180 days |
| Firewall logs | None | Varies by product | By address only | 30 to 90 days |
| Name resolution logs | Queried domains | None | By host | 30 to 90 days |
We analyze the traffic evidence that exists, quantify what can be measured, and give counsel and carriers a clear statement of what the network record supports. Where visibility is absent, we identify which alternate sources can close the gap.
Rapid export of flow, firewall, proxy, and resolution logs before short retention windows close.
Beacon analysis and infrastructure identification, mapped to affected hosts and processes.
Baseline comparison and egress measurement to support or refute claims about data taken.
Reconstruction of internal pivot paths and identification of every host that requires examination.
Technical assessment of whether a criminal group possession claim is consistent with the evidence.
Clear explanation of traffic evidence and its limits for judges, juries, arbitrators, and regulators.
Consultations are confidential. We work directly with affected businesses, with outside counsel, and with cyber insurance carriers and brokers nationwide.
Elite Digital Forensics is an independent digital forensics firm serving businesses, attorneys, and insurers nationwide. Our examiners include former law enforcement forensic examiners who have testified as court qualified expert witnesses in state and federal proceedings. We do not sell security software and we do not manage client networks, so our findings carry no conflict of interest when the question is whether an environment was adequately secured.
Every engagement follows documented chain of custody, defensible acquisition methods, and reporting written for attorney review, insurer submission, regulator response, or courtroom use. Work performed at the direction of counsel is generally treated as attorney work product prepared in anticipation of litigation. Call (833) 292-3733 or request a confidential consultation.
It can measure outbound bytes per host and destination during the incident window and compare that with normal behavior and with any staging archives found on disk. That produces a defensible range. Exact file level proof usually requires additional endpoint or cloud evidence.
Yes. Destination, session timing, byte volume, and client handshake fingerprints remain visible and are typically sufficient to identify command and control behavior and to quantify egress, even without content.
Commonly 30 to 90 days on device, longer where logs are forwarded to a central platform. Payment card requirements are frequently cited as a 12 month floor for in scope environments, with the most recent months immediately available.
The analysis shifts to endpoint staging artifacts, cloud provider logs, and application records. Conclusions are often still possible, but the report should state clearly that transfer volume could not be independently measured.
Where a proxy or secure web gateway authenticates users, sessions can be attributed to a named account. Flow and firewall records alone attribute to a device address, which then has to be tied to a user through authentication records.
Traffic from company networks to cloud services does. Traffic between cloud services, or from a cloud workload directly to the internet, requires provider flow logging and audit records instead, which is a separate collection.
#DigitalForensics #ComputerForensics #CellPhoneForensics #ExpertWitness #DigitalForensicExperts #EliteDigitalForensics #ForensicInvestigation #DataBreachResponse #DataBreachInvestigation #IncidentResponse #CyberForensics #NetworkForensics #TrafficAnalysis #DataExfiltration #ThreatIntelligence
This content is for educational and informational purposes only and does not constitute legal advice. Elite Digital Forensics provides independent digital forensic services and expert witness testimony; we do not provide legal representation. Every case is fact specific; outcomes depend on the evidence, jurisdiction, and counsel. Retain qualified legal counsel for advice about your matter.
Elite Digital ForensicsΒ is a Professional Digital Forensics and Cyber Consulting Company that provides services nationwide.Β
Elite Digital Forensics Assistant
By submitting this form, you consent to be contacted by email, text, or phone. Your information is kept secure and confidential. Reply Stop to opt out at anytime.Β
IMPORTANT: Please remember to check your spam or junk folder
We use cookies for site functionality and, only with your permission, analytics and advertising. See our Privacy Policy for details. California residents have the right to Do Not Sell or Share My Personal Information.