Become a Beta Tester

DocsAttack Types

Data Exfiltration & Suspicious Transfers

Unusual outbound transfers for this VM.

A VM sends unusually large amounts of data out, which can mean stolen data leaving a compromised machine. Backups and legitimate uploads look similar, so by default Frabs alerts your team rather than acting.

Detectors (6)

DetectorMeasuresWarningIncidentCritical
DNS ExfiltrationTunnelling indicators (0-100) (score)50 in 10 min70 in 30 min90 in 1 h
Large Outbound TransferBytes sent to external destinations (bytes)1,000,000,000 in 1 h10,000,000,000 in 1 h50,000,000,000 in 1 h
High-Volume External UploadBytes sent to external destinations (bytes)1,000,000,000 in 1 h10,000,000,000 in 1 h50,000,000,000 in 1 h
Suspicious External DestinationContacts with addresses on threat-intelligence lists (contacts)1 in 10 min10 in 1 h100 in 1 h
Known Exfiltration DestinationContacts with addresses on threat-intelligence lists (contacts)1 in 10 min10 in 1 h100 in 1 h
Encrypted Tunnel ActivityTunnelling indicators (0-100) (score)50 in 10 min70 in 30 min90 in 1 h

Change the thresholds

Use Custom Protection to change any of these, or set them for one VM. See Detectors and Thresholds.