Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1030 — Data Transfer Size Limits
T1030

Data Transfer Size Limits

Exfiltration
TLP:CLEAR

Description

An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.

MITRE ATT&CK Detection Strategies
1

DET0213 Detection Strategy for Data Transfer Size Limits and Chunked Exfiltration
AN0596 Windows

Adversary uses a process to establish outbound connections that transmit uniform packet sizes at a consistent interval, avoiding threshold-based network alerts.

WinEventLog:Sysmon NSM:Flow
AN0597 Linux

Outbound connections from non-network-facing processes repeatedly send similarly sized payloads within uniform time intervals.

auditd:SYSCALL NSM:Flow
AN0598 macOS

Processes on macOS initiate external connections that consistently transmit data in fixed sizes using LaunchAgents or unexpected users.

macos:unifiedlog macos:endpointsecurity

Details

Platforms
Linux
Macos
Windows
Esxi
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.