Mechanisms for detecting phishing exfiltration data transmissions are provided. The mechanisms receive electronic input data transmission from a data network and process the electronic data transmission to extract a structure token representing the content structure of electronic input data transmission. The structure token is entered into a machine learning (ML) model that is trained,to identify grammars of phishing exfiltration data transfers and relationships between grammars of phishing exfiltration data transfers in structure tokens. The ML model processes the structure token to generate a vector output that specifies calculated values for processing by a classification logic. Classification logic processes the vector output from the ML model to classify the electronic input data transmission as either a phishing exfiltration data transmission or a non-phishing exfiltration data transmission, and outputs a corresponding classification output.
展开▼