Skip to the content.

back

Find sigma rule :x:

Attack: Data Transfer Size Limits

An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.

MITRE

Tactic

technique

Test : Data Transfer Size Limits

OS

Description:

Take a file/directory, split it into 5Mb chunks

Executor

sh

Sigma Rule

back