• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Large HTTP POST Exfiltration - Multipart or Chunked Upload Over 5MB

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ankit Mehta@Secvyn
    •updated Jun 30, 2026•0•0•1

    Detects large HTTP POST requests (over 5MB) directed at external hosts that utilize multipart or chunked encoding, which are commonly used to obfuscate or stream large volumes of data during an exfiltration event.

    Suricata

    Tags

    T1071.001 - Web ProtocolsT1048.003 - Exfiltration Over Unencrypted Non-C2 ProtocolTA0011 - Command and ControlTA0010 - ExfiltrationNetwork Data TransferHTTP RequestData ExfiltrationIDS IPS AlertNetwork GenericSuricata IDSSnort IDSHTTPTrojan Activity

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?