At a high level it's possible to alarm on data egress, but at the same time it depends on the type and degree of compromise we're discussing and how the attacker exfiltrates the data.
If an intruder isn't detected, they could slowly egress the data to borrowed residential IPs, rather than a giant multi TB transfer that might set off more obvious alarms. For a large enough organization with substantial outbound traffic to start, it can become incredibly hard to distinguish from legitimate activity.
reply