• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Large HTTP POST Possible Data Exfiltration Over 10MB

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ankit Mehta@Secvyn
    •updated Jun 30, 2026•0•0•2

    This rule detects large HTTP POST requests (greater than 10MB) originating from the internal network to external destinations, which may indicate bulk data exfiltration.

    Suricata

    Tags

    T1567 - Exfiltration Over Web ServiceTA0010 - ExfiltrationNetwork Data TransferHTTP RequestData ExfiltrationIDS IPS AlertNetwork GenericSuricata IDSSnort IDSGeneric Network LogHTTPPolicy Violation

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?