Data Transfer Size Limits T1030
Tactic: Exfiltration
An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.
Events covered
16 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 27 rules share fields, values, and exclusions.
Fields filtered most (56 distinct)
These fields appear most often in rule filters.
Top indicator values (175 distinct)
These values appear most often in rule predicates.
Exclusions (70 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 2 rules
Elastic 2 rules
- GenAI Process Performing Encoding/Chunking Prior to Network Activity
- Potential Data Splitting Detected
Splunk 7 rules
- Linux Auditd Data Transfer Size Limits Via Split
- Linux Auditd Data Transfer Size Limits Via Split Syscall
- MacOS Data Chunking
- Rclone Execution
- Rclone Execution (PowerShell)
- Rclone Execution (Sysmon)
- Rclone Execution (Windows Event Log)
Kusto 16 rules
- Anomaly found in Network Session Traffic (ASIM Network Session schema)
- Cisco SEG - DLP policy violation
- Cisco SEG - Multiple large emails sent to external recipient
- CloudNGFW By Palo Alto Networks - Threat signatures from Unusual IP addresses
- Corelight - Multiple files sent over HTTP with abnormal requests
- Detect unauthorized data transfers using timeseries anomaly (ASIM Web Session)
- Mimecast Data Leak Prevention - Hold
- Mimecast Data Leak Prevention - Hold
- Mimecast Data Leak Prevention - Notifications
- Mimecast Data Leak Prevention - Notifications
- Palo Alto Threat signatures from Unusual IP addresses
- SharePointFileOperation via devices with previously unseen user agents
- SharePointFileOperation via previously unseen IPs
- Threat Essentials - Time series anomaly for data size transferred to public internet
- Time series anomaly detection for total volume of traffic
- Time series anomaly for data size transferred to public internet