← All articles

ARTICLE · DATA LEAK ACTIVE TESTING

BAS and data exfiltration testing: why specialisation matters

  • Comparison
  • 6 min read
  • Updated
A row of glowing warning triangles on a circuit board, an image of replayed attack scenariosBreadth or depth

The essentials in 30 seconds

  • A BAS covers the whole attack chain, i.e. 14 ATT&CK tactics; an exfiltration test only looks at data leaving (TA0010), but digs into it channel by channel.
  • A DLP rarely gives way all at once: it fails on a variant (encrypted archive, renamed file, split upload).
  • Already have a BAS? Count its exfiltration scenarios that use content close to yours. If you can count them on one hand, depth is missing.

“We already have a BAS, so why bother with an exfiltration test?” We often hear this in demos, and it is a fair question: the tool runs, the reports come out, the Exfiltration line is green. Our answer fits in 2 sentences. Put simply, the BAS tells you that your defences react to known techniques. It does not tell you whether your customer records, your blueprints or your payroll can get out, or which way.

BAS (Breach and Attack Simulation) automatically replays attack techniques across the whole chain, from initial access to impact. Data exfiltration testing is a specialisation of it: it works only on egress, but in depth, channel by channel and data type by data type. The two do not answer the same question.

Two questions, two tools

With a BAS, you check that your defences hold against a wide range of behaviours: phishing, execution on the endpoint, lateral movement, privilege escalation, persistence. In MITRE ATT&CK, that covers 14 tactics, from reconnaissance (TA0043) to impact (TA0040). That is the strength of BAS.

Exfiltration testing asks a narrower question: if an attacker or a trusted user tries to get your sensitive data out, does it get out? A file blocked on 1 channel tells you nothing. You need to vary formats, volumes, encodings and destinations, then compare each result with your DLP rules. The TA0010 tactic has 9 techniques, from automated transfer (T1020) to transfer to a cloud account (T1537), including alternative protocols (T1048), the command and control channel (T1041), web services (T1567), physical media (T1052) and scheduled transfers (T1029). Enforcis replays the full sequence (discovery, collection, staging, automation, exfiltration) over network and cloud channels, from at least 1 Windows or Linux agent per subnet.

Diagram · breadth versus depth

BAS breadth, exfiltration testing depthOn the left, the general-purpose BAS covers the whole attack chain, from initial access to exfiltration, with few variants per step. On the right, exfiltration testing focuses on the egress step alone and breaks it down into channels, formats, volumes and content.Generalist BASThe whole chainExfiltration testingFocus on egressFew variantsEvery variant replayedInitial accessLateral movementPrivilegesPersistenceExfiltrationExfiltrationChannelsFormatsVolumesContent

What BAS does very well

Presenting it as outdated would be dishonest. BAS did, after all, establish a simple idea in the profession: a control you do not test remains an assumed control. Used well, it:

  • covers many tactics with a single tool;
  • gives the SOC repeatable scenarios to check its detections;
  • spots regressions after an EDR, proxy or firewall update;
  • speaks the language of ATT&CK, which management understands.

If you have never validated your controls in an automated way, it is often the right first purchase.

Where breadth reaches its limits

Broad coverage comes at a price: each of the 14 tactics gets a small share of the effort. On exfiltration, depending on the vendor, you get anything from a few generic scenarios to a dedicated module. A send to an unknown domain, a transfer over an uncommon protocol, a file marked “sensitive” dropped on a web service. Your scenario passes or it does not, and the box turns green.

In practice, a DLP rarely gives way all at once. It fails silently, on a variant. Your document is blocked as a PDF, but not once it is slipped into an encrypted ZIP (T1560). Your rule recognises a 16-digit card number written with spaces, but not without. Your web traffic is inspected, but the personal Dropbox or OneDrive sync client is not. A typical case: an upload to a consumer storage service is cut off above a certain volume; split below the threshold (T1030), it gets through. These gaps are detailed in DLP false negatives: why your rules fail silently.

BAS and exfiltration testing: a point-by-point comparison

Criterion General-purpose BAS Specialised exfiltration testing
Question asked Do my defences react across the whole attack chain? Can my sensitive data get out, and which way?
Scope Broad: up to 14 tactics, from initial access to impact Narrow: 1 tactic (TA0010) and what leads up to it
Depth on exfiltration Varies by vendor, from a few scenarios to a dedicated module Many variants of channel, format, volume and content
Link with the DLP Indirect Direct: each scenario is compared with the rules and classifications
Data used The vendor’s test payloads or sample data sets Decoys that mimic your business data
Expected result Prevention and detection rate per technique Prioritised list of possible leaks and fixes

Concrete scenario: two readings of the same estate

A typical scenario, one Monday in March, at a manufacturer equipped with endpoint DLP, a proxy with TLS inspection and rules on outbound email. Its BAS shows a good score on the Exfiltration tactic: sending to an external server and transferring over an unusual protocol are both blocked.

The team then replays variants with synthetic files that mimic blueprints and customer records. Here is what such a test can reveal:

  • AutoCAD drawings renamed to .txt are no longer recognised;
  • an extract of a customer record pasted into ChatGPT or Copilot gets through without an alert;
  • a password-protected archive leaves Outlook for a Gmail address;
  • uploads to a Box account tolerated “for suppliers” are not inspected.

Both readings are true. The BAS says the classic techniques are covered. The test says your business data has 4 exit doors. It is this second piece of information that feeds your remediation plan.

Next step

How many exit doors does your BAS not see?

A 30-minute demo: a full campaign across the 8 channels we test, on our demo environment. The POC shows, on site, how the solution behaves in your environment, on one simple scenario in a synthetic environment. What actually leaves through your channels is what the pilot shows you.

Why specialisation changes the deliverable

Depth is only worth something if it leads to decisions. A failure on a payroll file does not carry the same weight as a failure on an internal memo. With Enforcis, each scenario replayed ends in one of 3 states (Blocked; Detected, not blocked; Not detected), with dated, traceable results within the scope actually tested. You can then rank your findings along 3 axes:

  1. the sensitivity of the data that leaked (personal data, trade secrets, financial data);
  2. the exposure of the channel (open to all machines, or to a few profiles);
  3. the cost of the fix (adjusting a rule, or launching a classification project).

It is this prioritisation that turns a pile of findings into an action plan. Upcoming versions will bring contextualised, prioritised recommendations, validated by retest; someone on your side will still decide what to fix first.

Do you have to choose?

No, in most cases. The two approaches complement each other. 4 pointers to decide the order:

  • No automated validation in place: a BAS gives you a first map of your weaknesses.
  • You need evidence of how your DLP actually behaves (audit, management committee, Article 21 of NIS2 or DORA): exfiltration testing answers that directly.
  • You already have a BAS: count its data exit scenarios and check whether they use content close to yours. “Few” and “no”? You are missing depth.
  • You are a mid-sized company without a SOC: choose the tool whose deliverable a small team can act on.

For a comparison with human-led approaches, see our article continuous validation, pentest or red team. If your DLP is Microsoft Purview™, also see how to validate your Purview policies. To decide between several vendors, use our criteria for choosing a DLP testing tool.

Checklist: does your tool go far enough on exfiltration?

  • Do the scenarios cover your 4 channel families (endpoint, network, cloud, SaaS)?
  • Does the tested content look like your sensitive data, without being real?
  • Are format, encoding and volume variants replayed?
  • Is each result linked to the DLP rule that should have reacted?
  • Can campaigns be replayed at a regular interval, or after a change?
  • Is the deliverable a list of ranked actions, or a report to interpret?

FAQ

Is exfiltration testing a form of BAS?

You can see it as a branch of BAS: the same principle of automated replay of attack techniques, but limited to data egress and taken much further on that step. Upcoming versions will bring multi-level reporting (leadership, CISO, operations), with MITRE ATT&CK mappings and, where the correspondence is established, MITRE D3FEND, as well as SIEM integrations.

Is a BAS enough to validate a DLP?

It gives a first signal. To know whether your rules block your business data on all channels, you need more scenarios, closer to your content. The method is described in How to test your DLP and find out whether it really blocks.

Can you run a BAS and an exfiltration test on the same estate?

Yes. Just let the SOC know both schedules, so that alerts are qualified as tests. SIEM integrations will come in upcoming versions; in the meantime, compare the dated results of our campaigns with the BAS results.

Why can a DLP that is “green” in the BAS still leak?

Because a BAS runs a few generic scenarios per technique, and a DLP rarely gives way all at once. It fails on a variant. A document blocked as a PDF gets through once slipped into an encrypted ZIP (T1560); a 16-digit card number is recognised with spaces and ignored without. To see these gaps, we replay format, encoding and volume variants on content close to yours.

What deliverable should you expect from an exfiltration test, compared with a BAS?

A BAS returns a prevention and detection rate per ATT&CK technique. An exfiltration test returns a prioritised list of possible leaks and fixes. With Enforcis, each scenario ends in one of 3 states (Blocked; Detected, not blocked; Not detected); you can then rank each finding along 3 axes: data sensitivity, channel exposure, cost of the fix. As a result, a payroll file that got out comes before an internal memo. Upcoming versions will bring contextualised, prioritised recommendations, validated by retest; you still decide.

How your egress controls actually behave, observed scenario by scenario.

With synthetic payloads, we run controlled campaigns on the configured paths and observe how your controls actually behave, scenario by scenario.