T1030 Data Transfer Size Limits — ATT&CK Technique
An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.
Detection coverage (5)
- Split A File Into Pieces - Linux low
- Split A File Into Pieces low
- Linux Auditd Data Transfer Size Limits Via Split Syscall
- Linux Auditd Data Transfer Size Limits Via Split
- MacOS Data Chunking
Malware using this technique
- OopsIE
- POSHSPY
- RDAT
- Kessel
- Kevin
- ObliqueRAT
- StealBit
- AppleSeed
- Cobalt Strike
- Mythic
- Rclone
- LunarWeb
- Carbanak
- Helminth