Teams often look only for obvious exfiltration and miss the preparatory behaviour. In this case, process creation, anonymous pipe usage, file enumeration, and LastWriteTime collection are all early signs of malicious tasking. Detection should cover chained behaviours, not just final data transfer, because the same host may also receive download commands from the operator.
What teams miss when they wait for the exfiltration event
The common failure is treating exfiltration as the only meaningful signal. In practice, malware often has to stage the environment first, which means process creation, pipe activity, and directory enumeration can be stronger indicators than the final transfer. If you only alert on outbound volume or known upload destinations, you will miss the earlier workflow that reveals malicious tasking.
Those preparatory actions matter because they show intent, not just outcome. A process tree that launches a new executable, reads file metadata, and walks directories is already building the dataset for theft. Teams should therefore evaluate chain-of-behaviour patterns across endpoint telemetry rather than isolated events.
That is also why defenders should pay attention to repeated reads of MITRE ATT&CK Enterprise Matrix-style behaviours such as discovery and collection, even when no file leaves the host yet. The same host may also receive operator commands to fetch content, so the detection problem is bidirectional: one side stages data for removal, the other side may be staging downloads or follow-on tasks.
Why file discovery and process chaining are the real warning signs
Malware that creates processes before exfiltration is usually trying to do more than simply copy files. New process creation can indicate script launchers, living-off-the-land utilities, or helper binaries that expand capability. Anonymous pipes are often used to move output between child and parent processes without writing obvious artifacts to disk, which makes the activity look quieter than direct file export.
Directory enumeration and LastWriteTime collection are especially important because they reveal selection logic. The malware is not blindly moving data, it is discovering which files exist, where they live, and which ones are newest or most valuable. That is often the point at which defenders still have a chance to interrupt the operation before staging completes.
For broader operational controls, CIS Controls v8 reinforces the value of logging, malware defence, and account management as practical detection foundations. The relevant lesson is to capture telemetry rich enough to reconstruct process lineage, file access, and parent-child relationships, not just the network session that ultimately carries data away.
How to detect the behaviour before data leaves the host
Good detections should join endpoint, file, and process telemetry into one analytic view. A single suspicious process is rarely enough. A stronger signal is a sequence such as new process creation, pipe-based output, directory walk, repeated metadata reads, and then a network connection or archive operation. That chain is much harder for malware to hide than any one step on its own.
Teams should also look for negative space, such as file discovery without normal user interaction, or a process that enumerates many paths but has no legitimate business reason to do so. These patterns are most useful when you baseline them against the host role, because a developer workstation, file server, and build runner will not show the same normal behaviour.
When a campaign has already shown signs of credential or session abuse, a linked endpoint narrative like CircleCI Breach is useful because it shows how malware on a single machine can become a broader access event. That is the detection lesson here: local process behaviour often precedes, and is operationally more useful than, the eventual external transfer.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1005 — Data from Local System | File discovery and collection behaviour map to endpoint collection techniques. |
| Recommendation — Detect file discovery and collection chains before outbound transfer occurs. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Endpoint and file telemetry are needed to reconstruct pre-exfiltration behaviour. |
| Recommendation — Centralise telemetry for process, pipe, and file-access analysis. | ||
| NIST SP 800-53 Rev 5 | AU-12 — Audit Record Generation | Process lineage and file-access auditing are necessary to see staging behaviour. |
| Recommendation — Generate audit records that capture process, file, and network activity. | ||
Practitioner Guidance
What to prioritise: Tune detections around behavioural sequences, not single alerts. A process tree plus directory enumeration plus metadata reads is far more actionable than an outbound transfer alert after the fact.
What to verify: Confirm that your telemetry preserves parent-child process lineage, pipe activity, and file access context. If you cannot see those relationships, you will struggle to distinguish staging from ordinary administrative activity.
Common mistake: Treating exfiltration as the only trigger worth investigating. By the time data is leaving the host, the attacker has often already succeeded in discovery and collection.
Practitioner takeaway: The detection boundary should begin at staging, because the earliest reliable signal is often the malware’s preparation to exfiltrate, not the transfer itself.
Related resources from NHI Mgmt Group
- What do security teams get wrong about detecting SID History abuse in Active Directory?
- What do security teams get wrong about detecting malware that uses living-off-the-land techniques and plugin-based control?
- What do teams get wrong about detecting password reuse before account takeover happens?
- What do teams get wrong about detecting malware that uses anti-virtualization checks and decoy payloads?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org