ATT&CK · T1030
Data Transfer Size Limits
Tactics: exfiltration
About
An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.
Platforms: Linux, macOS, Windows, ESXiMITRE ATT&CK ↗
Used by actors
5 known groups
Software
14 malware/tools implement this
CarbanakPOSHSPYCobalt StrikeHelminthOopsIEKesselRDATAppleSeedObliqueRATMythicKevinRcloneLunarWebStealBit
Corpus indicators tagged with this technique
1 indicators in the corpus carry T1030.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| 138.226.246.94 | ip | supply_chain | 70 | 5 |