Opening Forensia workspaceacquiring
Loading the current evidence view. Navigation and account controls remain available.
Loading recent evidenceacquiring
ATT&CK knowledge
Loading the current evidence view. Navigation and account controls remain available.
Tactics: exfiltration
5
known groups
14
software
1
corpus matches
about
An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.
used by actors
5 known groups
software
14 malware & tools implement this
corpus indicators tagged T1030
1 carry this technique
A shared-technique signal for hunting: each row resolves to its own verdict. Not attribution to any one group.