Monitors traffic volume or bandwidth usage on the payload communication link to detect spikes that exceed normal operational thresholds, which may indicate malicious activity.
STIX Pattern
[network-traffic:src_ref.value = 'payload_channel' AND network-traffic:traffic_volume > 'baseline_threshold']