Large Outbound HTTP POST Exfiltration with Archive MIME Type Exceeds 10MB

Detects outbound HTTP POST requests where the Content-Length is at least 10MB and the Content-Type header indicates the transfer of archived data (zip or x-tar). This pattern is often associated with the staging and exfiltration of compressed sensitive data from an internal host to an external network destination.