An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Network Intrusion Prevention
is blocked by Detection Strategy for Data Transfer Size Limits and Chunked Exfiltration
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Continuous Monitoring
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
Impressum Deutsch Englisch