HomeBlog › Threat Lab
True story from the field

How to Tell If Your Security Software Is Phoning Home: A Forensic Field Lesson

Updated 2026-07-16 · 7 min read · by Mihai Bătrîneanu
How to Tell If Your Security Software Is Phoning Home: A Forensic Field Lesson

The fastest way to tell whether a trusted application is quietly sending your data somewhere it shouldn't: watch the direction of its traffic. Software updates flow into your machine — the vendor pushes new code down to you. Data exfiltration flows out — large, regular transfers leaving your network toward servers you never chose. When a program sends far more than it receives, on a steady schedule, to destinations that don't match its stated purpose, “it's just updates” is a red flag, not an answer. Updates don't pull your files out.

ContentsA quiet finding, years before the headlines
The principle: read the direction, not the label
How to check your own network — a practical playbook
Why jurisdiction is part of the threat model
What good looks like: continuous, autonomous egress monitoring
Frequently asked questions

A quiet finding, years before the headlines

Some years ago I was asked to look into a security product deployed across a large organization. Nothing was obviously wrong — the software ran, the endpoints looked protected. The network told a different story.

Following the traffic forensically, I traced large, regular outbound transfers leaving the organization and terminating at a chain of proxy servers abroad. The volume was substantial and the cadence was regular — this was not a person browsing the web. So we did the responsible thing: we wrote to the vendor, attached what we had, and asked a simple question — what are these large, regular transfers?

The answer, delivered informally through a local representative, was: “updates.”

That answer does not survive first contact with how software actually works. When a vendor updates its product, it pushes data to you — new signatures, new binaries, new rules travel down the wire, into the endpoint. A steady stream of data leaving your network is the opposite shape. Updates come in. This was going out.

Let me be precise, because precision is the whole point of this profession. I no longer hold the packet captures from that engagement, and it was years ago; I will not name the client, and I will not accuse a specific vendor of wrongdoing I can no longer place in evidence. What I can give you is the lesson — the one that has held up in every engagement since, and that you can verify on your own network today.

The principle: read the direction, not the label

Every application has a traffic “shape.” A browser pulls pages in and sends small requests out. An update service pulls large files in on a schedule and sends almost nothing out. A backup client sends large volumes out — but to a destination you configured. Trouble looks like this:

No single signal proves malice. Together they define anomalous egress — and anomalous egress is where data leaves. Endpoint antivirus and most EDR agents are built to inspect what runs on the host; they are not built to sit on the wire and ask why a trusted process is shipping gigabytes to a proxy in another jurisdiction.

How to check your own network — a practical playbook

You can do a first pass with tools you already have:

The uncomfortable truth: the more trusted the software, the less anyone watches what it sends home.

Why jurisdiction is part of the threat model

Where your security vendor is based — and where its servers and updates actually route — is not a political footnote. Software installed with high privilege can, in principle, see and move a great deal, so trust in that software is inseparable from the legal and geopolitical jurisdiction that can compel it.

This is not a fringe view; it is public record. Multiple governments have restricted specific foreign security vendors from state and critical-infrastructure use on national-security grounds — the United States, European Union institutions, and Romania among them. Whatever one concludes about any single vendor, the pattern is documented and worth internalizing: vendor trust and vendor jurisdiction are the same decision.

My own view — formed on the wire, long before those official decisions — is simple: assume nothing about a privileged application until you have watched what it sends out.

What good looks like: continuous, autonomous egress monitoring

The answer is not paranoia; it is visibility. You want a system that continuously baselines normal traffic for every asset and raises a hand the instant egress deviates — new destination, wrong direction, off-schedule volume. Not once a year in an audit, but every minute, automatically.

This is precisely the gap between an endpoint antivirus with a default firewall and a real Security Operations Center. Endpoint tools ask “is this file bad?” A SOC — especially an autonomous, AI-driven one sitting inline on the network — asks the question that actually surfaced the transfers above: “is this trusted thing behaving the way it should?” That is the work we build CYBER3.AI to do: sovereign threat intelligence and autonomous detection and response, watching the traffic, not only the files.

Updates come in. Data goes out. If you remember one line from a career spent on the wire, make it that one — then go and look at your own egress.

See what your network is really sending out.
CYBER3.AI's autonomous Cloud SOC baselines your traffic and flags anomalous egress in real time — the exfiltration that endpoint antivirus never sees.
Explore CYBER3.AI Cloud SOC →
🛡️ Try CYBER3.AI free
AI security copilot + Global Scan of your own network. 700 free credits on sign-up — no card, no strings.
Start free →
About the author: Mihai Bătrîneanu
Founder of CYBER3.AI and a 30-year veteran of internet infrastructure. In 1994 he founded PC-NET, the first Internet Service Provider in Eastern Europe, and built Romania's first e-mail, ADSL broadband and VoIP services. He now builds CYBER3.AI — a sovereign Security LLM and autonomous Security Operations Center.

Frequently asked questions

How can I tell if my security software is sending my data out?

Watch the direction and shape of its network traffic. Legitimate updates are inbound — the vendor pushes code down to you. Data exfiltration is sustained, regular outbound volume to destinations you did not choose. Baseline bytes-out vs bytes-in per process for a week; high, scheduled outbound to unexpected IPs or proxies is the warning sign.

Isn't large outbound traffic just software updates?

No. Updates flow into your machine — you download new signatures and binaries, in bursts around release times, not as steady all-day outbound. If a product explains large, regular OUTBOUND transfers as updates, the explanation contradicts how updates actually work.

What is egress monitoring?

Egress monitoring means watching the traffic leaving your network — by process, volume, schedule and destination — to detect data that should not be leaving. It is how you catch a trusted application exfiltrating data, which endpoint antivirus typically does not see.

Does antivirus or EDR detect data exfiltration?

Endpoint antivirus and most EDR focus on what runs on the device — files, processes and host behavior. They are generally not designed to sit on the network and judge whether a trusted process's outbound traffic is anomalous. Network-level, SOC-style egress monitoring covers that gap.

Why does my security vendor's country matter?

High-privilege software can see and move a lot of data, and the vendor's home jurisdiction can, in principle, compel access. That is why several governments have restricted certain foreign security vendors from state and critical-infrastructure use. In practice, vendor trust and vendor jurisdiction are the same decision.

Protejează-ți telefonul — CYBER3, gratuit pe Google Play
Instalează