HTTP POST Large Body Data Exfiltration Content-Length Exceeds 10MB
This rule detects HTTP POST requests containing a Content-Length header value indicating a body size exceeding 10MB. Large POST requests may indicate data exfiltration, large file uploads, or misuse of HTTP channels for data transfer to external destinations.
Suricata

