Skip to content

Latest commit

 

History

History
42 lines (35 loc) · 1.73 KB

MATCH-S00457.md

File metadata and controls

42 lines (35 loc) · 1.73 KB

Rules: Large File Upload

Description

Observes for file uploads above 50MB in size. It is recommended to tune this rule to desired file size threshold for your organization as well as to exclude users/systems typically sending large outbound files.

Additional Details

Detail Value
Type Templated Match
Category Exfiltration
Apply Risk to Entities srcDevice_hostname, srcDevice_ip, user_username
Signal Name Large File Upload
Summary Expression File of size: {{bytesOut}} uploaded from IP: {{srcDevice_ip}}
Score/Severity Static: 1
Enabled by Default False
Prototype False
Tags _mitreAttackTactic:TA0010, _mitreAttackTechnique:T1567, _mitreAttackTechnique:T1567.001, _mitreAttackTechnique:T1567.002

Vendors and Products

Fields Used

Origin Field
Normalized Schema bytesOut
Normalized Schema dstDevice_ip_isInternal
Normalized Schema listMatches
Normalized Schema objectType
Normalized Schema srcDevice_hostname
Normalized Schema srcDevice_ip
Normalized Schema user_username