The data egress hunt

Runbooks for hunting data leaving the environment through unusual channels or volumes, including DNS tunnelling, cloud storage abuse, and anomalous outbound traffic patterns.