Home › Use Cases › Covert exfiltration

The data left around your proxy.

The data left. It did not go through your proxy, so it is not in the egress record you review, and the connection that carried it was opened by a process an AI session wrote days earlier. SalienceCyber.ai ties that flow back to the process, the process back to the session, and stops the connection at the host.

A binary written inside an AI session is recorded at the moment it is created, bound to the interaction that produced it. Days later it runs, and reaches for a destination directly — the kind of connection that never touches the proxy and so never appears in the egress record anyone reviews. Because the artifact was already tied to its session, Salience Cyber neutralizes that connection at the system plane, through a userspace host sensor rather than a kernel agent. The flow never leaves.
See

Flow, process, parent, binary

Host to parent to process to destination, sized by volume — with connections that routed around the proxy surfaced rather than absent, because they never reached the log you were watching.

Comprehend

Tied to the session that wrote it

Artifacts created in an AI session are recorded at birth, so a binary that executes days later is already bound to the interaction that produced it — provenance, not inference.

Neutralize

Off-proxy egress, stopped

The connection neutralized at the system plane by a userspace host sensor — not a kernel agent — at the moment the process reaches for a destination it was never meant to have.

Fig. 1
In the console
Network Sensor table of process-attributed egress flows with counters for total flows, attributed flows, AI flows and evaded flows, and one row flagged as evaded.

Flow-to-Process Attribution

Every outbound connection tied to the local process that opened it — and the ones that bypassed the proxy counted out on their own.

See the full product tour