Large HTTP POST Possible Data Exfiltration Over 10MB
This rule detects large HTTP POST requests (greater than 10MB) originating from the internal network to external destinations, which may indicate bulk data exfiltration.
Suricata

This rule detects large HTTP POST requests (greater than 10MB) originating from the internal network to external destinations, which may indicate bulk data exfiltration.

Already have an account?