MITRE D3FEND (Defensive Techniques)
D3-APCA

Application Protocol Command Analysis

Description

Analyzing application protocol level remote commands to detect unauthorized activity.

Mapped SPARTA techniques

17 techniques

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records DE-0009.04 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • EX-0014SpoofingST0004
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • EX-0014.01Time SpoofST0004
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014.01 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • EX-0014.02Bus Traffic SpoofingST0004
    mitigates
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014.02 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • EX-0014.03Sensor DataST0004
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014.03 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0006 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • EXF-0006.01Software Defined RadioST0008
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0006.01 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • EXF-0006.02TransponderST0008
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0006.02 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1199 Trusted Relationship; SafeMode's curated mapping records IA-0003 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • IA-0006Compromise Hosted PayloadST0003
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1199 Trusted Relationship; SafeMode's curated mapping records IA-0006 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • IA-0007Compromise Ground SystemST0003
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1190 Exploit Public-Facing Application; SafeMode's curated mapping records IA-0007 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • IA-0013Compromise Host SpacecraftST0003
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1199 Trusted Relationship; SafeMode's curated mapping records IA-0013 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • LM-0001Hosted PayloadST0007
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1210 Exploitation of Remote Services; SafeMode's curated mapping records LM-0001 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1210 Exploitation of Remote Services; SafeMode's curated mapping records LM-0002 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0003 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0004 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Counters 72 in MITRE ATT&CK Enterprise

Cite as SafeMode Space, d3fend D3-APCA.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.