Large Outbound HTTP POST Exceeding 10MB Content-Length — Data Exfiltration

Detects outbound HTTP POST requests where the Content-Length header indicates a transfer size exceeding 10MB to external (non-HOME_NET) addresses. This pattern is indicative of potential data exfiltration via HTTP.