wireshark_detect_exfiltration
Detect data exfiltration by analyzing large outbound transfers, DNS length anomalies, and non-standard ports in pcap files.
Instructions
[Anomaly] Detect data exfiltration (large outbound transfers, DNS length anomalies, non-standard ports).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| pcap_file | Yes |