Data exfiltration is the unauthorized removal of data from an environment, often the ultimate goal of an attack, and detection evasion is the effort to move that data without triggering alarms. Studying these concepts from the defender's perspective is what matters: understanding how exfiltration appears on a network is exactly what lets an organization detect and prevent it. This lesson focuses on that defensive view, how data theft manifests, why it is a cat-and-mouse with detection, and the controls that stop it.
Analogy🏏Cricket
🏏 Think of it like cricket: Active recon is the captain walking out to inspect the pitch on match morning, pressing the surface, checking the grass, watching how the ball behaves in the nets. Unlike studying old footage from afar, this inspection happens on the ground itself and is visible to everyone. Just as that inspection reveals conditions no video could, active scanning reveals live services no public record shows, and just as it happens with the ground's permission, scanning happens only within authorized scope.