Free kit

Free AI Tabletop Exercise Kit for SMBs

Sign up for the Cyber Defense & AI Brief and get it free.

Get the free kit

UC-L3-011

Large Outbound Data Transfer

Firewall logs / Network flow data

Use case development / Prevent Data Exfiltration / Detect Large Data Transfers

sigma

Detection rule

title: Large Outbound Data Transfer
status: experimental
description: Detects unusually large outbound network transfers
logsource:
  product: firewall
detection:
  selection:
    action: allow
    direction: outbound
  condition: selection | sum(bytes_out) by src_ip > 1073741824
  timeframe: 1h
falsepositives:
  - Cloud backups
  - Software updates
level: medium
tags:
  - attack.exfiltration
  - attack.t1041

Test cases

  • Transfer 1GB+ of data outbound in 1 hour

False positive guidance

Baseline normal transfer volumes per endpoint.

ATT&CK

Detection course