An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.
Adversary uses a process to establish outbound connections that transmit uniform packet sizes at a consistent interval, avoiding threshold-based network alerts.
Outbound connections from non-network-facing processes repeatedly send similarly sized payloads within uniform time intervals.
Processes on macOS initiate external connections that consistently transmit data in fixed sizes using LaunchAgents or unexpected users.