Large Outbound HTTP POST Data Exfiltration Over 5MB
Detects outbound HTTP POST requests where the Content-Length header indicates a data transfer of 5MB or greater. This pattern is indicative of potential unauthorized data exfiltration over the web protocol.
Suricata

