FORENSIA

ATT&CK · T1030

Data Transfer Size Limits

Tactics: exfiltration

About

An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.

Platforms: Linux, macOS, Windows, ESXiMITRE ATT&CK ↗

Used by actors

5 known groups

Software

14 malware/tools implement this

CarbanakPOSHSPYCobalt StrikeHelminthOopsIEKesselRDATAppleSeedObliqueRATMythicKevinRcloneLunarWebStealBit

Corpus indicators tagged with this technique

1 indicators in the corpus carry T1030.

IndicatorTypeFamilySevSrc
138.226.246.94ipsupply_chain705