Data exfiltration
Moving data out of a system to somewhere its owner did not intend.
For an agent, exfiltration rarely looks like a break-in. A tool is asked, by a sentence the model read somewhere, to put a file's contents in an argument, or to send a message to an address that is not the user's. The data leaves through a channel the agent was allowed to use.
That is why the pattern set on this site flags a tool description that names a destination, and why the rubric asks every listing to declare which hosts it contacts.
An agent with a mail tool, a file tool and a model that can be steered has everything needed to leak data without a single bug in any of them.
Looking for exfiltration as a network anomaly. It usually travels through a legitimate tool, to a legitimate service, in a legitimate-looking call.
Related terms
See Data exfiltration on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue