UC-L3-011
Large Outbound Data Transfer
Firewall logs / Network flow data
Use case development / Prevent Data Exfiltration / Detect Large Data Transfers
sigma
Detection rule
title: Large Outbound Data Transfer
status: experimental
description: Detects unusually large outbound network transfers
logsource:
product: firewall
detection:
selection:
action: allow
direction: outbound
condition: selection | sum(bytes_out) by src_ip > 1073741824
timeframe: 1h
falsepositives:
- Cloud backups
- Software updates
level: medium
tags:
- attack.exfiltration
- attack.t1041Test cases
- Transfer 1GB+ of data outbound in 1 hour
False positive guidance
Baseline normal transfer volumes per endpoint.