A theft you can name in one sentence is the theft your tools already catch. One file, one big upload, one unfamiliar destination. That move trips every wire you own. So the data does not leave that way.
It leaves slower. Someone reads a database export. Then a file share. Then an internal API. The pulls land in one directory, get zipped into an archive, and sit. Hours pass. Then the archive goes out through a cloud bucket your team approved last quarter. The exit is the part everyone watches. The gathering happened first, and almost nothing watched it.
The gathering has a name. Staging. It is the earliest point where exfiltration stops being a guess and turns into a pattern you can read.
The exit is the latest place to look, not the first
Watch only the door and you watch a transfer that is already underway. The destination is reached. The connection is open. You can block a partial transfer or write the disclosure letter, and neither one gets the data back.
The door is rarely even suspicious. It is an approved cloud bucket, a sanctioned SaaS sync, an FTP endpoint that moves real files every day. The move out is permitted. Every tool you own lets it through, correctly, because nothing about that one move is wrong.
Your most valuable data leaves on access you granted on purpose. No single move breaks a rule. The breach is the shape across moves, and staging is where that shape first becomes legible.
What staging actually looks like
Staging is a sequence, and the sequence carries the signal.
It opens with collection. One identity reads from sources it does not normally touch together: a database export, a bulk read of a file share, a pull from an internal API. Each read is allowed on its own. Read side by side, they are a consolidation that does not fit the user or the job.
Concentration follows. The data lands in one place, a temp directory or a scratch volume or a single host now holding far more than it usually does. It gets compressed into an archive, which shrinks the eventual transfer and changes its signature. Sometimes it gets encrypted. Encryption hides content from anything that reads content. It hides nothing from anything that reads movement.
Then it waits. The staged archive sits queued, often off-hours, sometimes until the operator confirms the path out is clear.
No step here trips a permission check. The reads were allowed. Writing to a temp directory is allowed. Zipping a folder is allowed. The signal is the whole: this identity, pulling from these sources, into this one place, at this volume, in this window. A pattern is a case, not an alert.
Why most tools never see the gathering
The stack is built around the door, not the room behind it.
DLP watches egress and the application layer: what gets uploaded, emailed, synced out. Endpoint detection watches process behavior and known attack techniques on the host. Posture tools check whether configurations and permissions are correct. Each does its own job well. None of them is built to take a string of individually permitted reads, correlate them into one location across time, and resolve the whole thing to the identity behind it.
That correlation is the entire game during staging. The reads cross different sources, sometimes different hosts. The concentration happens locally, inside a boundary, where an egress tool is not looking, because nothing has crossed out yet. By the rules every other system enforces, nothing has happened.
So staging passes in silence. The rest of the stack speaks up when the archive starts leaving, which is the one moment when speaking up changes the least.
Reading the pattern at runtime
Staging only forms in one place: at runtime, on the movement itself. Not before, where predictive tools guess and miss the permitted move. Not after, where forensics narrates what already left. During.
Hilt watches data movement at the kernel, metadata only by default, off the path. It reads no content to do this, and it does not have to read your data to tell that a consolidation does not fit. Each move resolves to a probabilistic, source-dependent identity: which user, which job, which source, which destination, and whether any of it matches what that identity normally does.
During staging, the deviation surfaces on several layers at once. Collection reads from sources this identity does not usually combine. Concentration writes an unusual volume into one location. Compression rewrites the footprint without changing the fact that an identity is gathering far more than its work requires. Any one of these is noise. In sequence, attributed to one identity, they are the staging pattern, and the pattern is readable before the first byte leaves the building.
That is the point of seeing it here. Trigger on staging instead of egress and there is still time to act. Hilt responds with host-level network isolation, quarantine, from the control plane. It never sits inline. It never blocks, drops, or alters traffic. It isolates the host where the staged archive sits, at the network, so the queued transfer has nowhere to go. The response lands on the gathering, not the escape.
Encryption deserves the last word, because it is the move operators reach for to beat content inspection. Encrypt the archive and you blind anything reading content. You change nothing for a system reading movement. The identity still pulled from unusual sources, still concentrated an unusual volume, still produced a sequence that breaks its own history. Metadata reads the staging pattern whether or not the bytes are.
What this buys you
Exfiltration is a process, not a moment. The moment everyone instruments, the door, is the last step in that process and usually a permitted one. Everything before it, gather, concentrate, compress, queue, is where intent first hardens into a pattern, and a pattern is something you act on while acting still matters.
Instrument only the boundary and you catch exfiltration at the one point where catching it saves you almost nothing. Read the staging pattern instead, resolved to the identity and the job, scored against how that identity's data normally moves, and a disclosure letter becomes a quarantined host.
If that is the gap you are working to close, the quickest way to know whether it fits your environment is a 30-minute technical call, engineer to engineer, to walk through where the collector sits and what the staging pattern looks like on your own data movement.