Data Transfer Size Limits T1030

Tactic: Exfiltration

An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.

Events covered

16 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 27 rules share fields, values, and exclusions.

Fields filtered most (56 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine5regex_match 3, contains 2, match 1, starts_with 1(?i)\s+(((copy|move|moveto|copyto)\s+.*\S+:\S+\s+.*\S+:\S..., -b , if=, (?i)rclone, Compress-Archive
SourceIP4is_not_null 4
anomalies4gt 40
dest_ip4is_not_null 4
process_name4in 2, regex_match 2, eq 1, starts_with 1(?i)rclone, 7z, 7za, 7zr, dd
src_ip4is_not_null 4
DestinationIP3is_not_null 3
EventID3eq 31, 4103, 4104, 4688
Rank3lt 2, le 110
sourcetype3eq 3auditd, bash_history
type3eq 3syscall, execve, proctitle
Action2eq 2hold, notification
Deviation2gt 225
EventType2eq 1, in 1ProcessRollup2, connection_attempted, exec, exec_event
NetworkDirection2eq 2outgoing

Top indicator values (175 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
anomaliesgt
0
412
CommandLineregex_match
(?i)\s+(((copy|move|moveto|copyto)\s+.*\S+:\S+\s+.*\S+:\S+)|(serve\s+(dlna|ht...
22
Deviationgt
25
22
NetworkDirectioneq
outgoing
22
Operationin
filedownloaded
22
Operationin
fileuploaded
22
Ranklt
10
22
RecordTypeeq
sharepointfileoperation
22
TotalEventsgt
25
2
TotalEventslt
10
22
TotalSentBytesinMBgt
10
22
commeq
split
22
event.typeeq
start
21078
process_namein
split
23
process_nameregex_match
(?i)rclone
22
sourcetypeeq
auditd
258
typeeq
syscall
227
Actioneq
hold
1
Actioneq
notification
1
Activityeq
threat
1
AdditionalFieldscontains
esadlpverdict
1
CommandLinecontains
-b
1
CommandLinecontains
if=
1
CommandLinecontains
base64
119
CommandLinecontains
buffer.from
14
CommandLinecontains
gzip
12
CommandLinecontains
split
1
CommandLinecontains
tarfile
1
CommandLinecontains
zipfile
1
CommandLinecontains
zlib
14

Exclusions (70 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
TotalEventsgt
25
2
dest_ipcidr_match
10.0.0.0/8
2
dest_ipcidr_match
127.0.0.0/8
2
dest_ipcidr_match
169.254.0.0/16
2
dest_ipcidr_match
172.16.0.0/12
2
dest_ipcidr_match
192.168.0.0/16
2
process_nameregex_match
(?i)(cmd|powershell).exe
2
Activityeq
threat
1
DestinationIPcidr_match
10.0.0.0/8
1
DestinationIPcidr_match
127.0.0.0/8
1
DestinationIPcidr_match
169.254.0.0/16
1
DestinationIPcidr_match
172.16.0.0/12
1
DestinationIPcidr_match
192.168.0.0/16
1
DeviceEventClassIDin
file
1
DeviceEventClassIDin
flood
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 2 rules

Elastic 2 rules

Splunk 7 rules

Kusto 16 rules