Application Protocol Command Analysis
Description
Analyzing application protocol level remote commands to detect unauthorized activity.
Mapped SPARTA techniques
17 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records DE-0009.04 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014.01 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014.02 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014.03 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0006 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0006.01 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0006.02 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1199 Trusted Relationship; SafeMode's curated mapping records IA-0003 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1199 Trusted Relationship; SafeMode's curated mapping records IA-0006 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1190 Exploit Public-Facing Application; SafeMode's curated mapping records IA-0007 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1199 Trusted Relationship; SafeMode's curated mapping records IA-0013 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1210 Exploitation of Remote Services; SafeMode's curated mapping records LM-0001 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1210 Exploitation of Remote Services; SafeMode's curated mapping records LM-0002 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0003 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0004 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 72 in MITRE ATT&CK Enterprise
- T1001Data Obfuscation
- T1003.006DCSync
- T1008Fallback Channels
- T1011Exfiltration Over Other Network Medium
- T1018Remote System Discovery
- T1020Automated Exfiltration
- T1021Remote Services
- T1021.001Remote Desktop Protocol
- T1021.004SSH
- T1029Scheduled Transfer
- T1030Data Transfer Size Limits
- T1041Exfiltration Over C2 Channel
- T1047Windows Management Instrumentation
- T1048Exfiltration Over Alternative Protocol
- T1048.001Exfiltration Over Symmetric Encrypted Non-C2 Protocol
- T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1048.003Exfiltration Over Unencrypted Non-C2 Protocol
- T1071Application Layer Protocol
- T1071.001Web Protocols
- T1071.002File Transfer Protocols
- T1071.003Mail Protocols
- T1071.004DNS
- T1090.001Internal Proxy
- T1090.002External Proxy
- T1090.003Multi-hop Proxy
- T1090.004Domain Fronting
- T1095Non-Application Layer Protocol
- T1098.001Additional Cloud Credentials
- T1102Web Service
- T1104Multi-Stage Channels
- T1105Ingress Tool Transfer
- T1110.003Password Spraying
- T1110.004Credential Stuffing
- T1132Data Encoding
- T1185Browser Session Hijacking
- T1189Drive-by Compromise
- T1190Exploit Public-Facing Application
- T1197BITS Jobs
- T1199Trusted Relationship
- T1204.001Malicious Link
- T1205Traffic Signaling
- T1205.001Port Knocking
- T1207Rogue Domain Controller
- T1210Exploitation of Remote Services
- T1218.003CMSTP
- T1219Remote Access Tools
- T1498.001Direct Network Flood
- T1498.002Reflection Amplification
- T1499.002Service Exhaustion Flood
- T1542.005TFTP Boot
- T1546.003Windows Management Instrumentation Event Subscription
- T1546.008Accessibility Features
- T1550.001Application Access Token
- T1550.004Web Session Cookie
- T1557Adversary-in-the-Middle
- T1557.001LLMNR/NBT-NS Poisoning and SMB Relay
- T1557.003DHCP Spoofing
- T1558.003Kerberoasting
- T1563Remote Service Session Hijacking
- T1565.002Transmitted Data Manipulation
- T1566.001Spearphishing Attachment
- T1566.002Spearphishing Link
- T1567Exfiltration Over Web Service
- T1567.001Exfiltration to Code Repository
- T1567.002Exfiltration to Cloud Storage
- T1568Dynamic Resolution
- T1570Lateral Tool Transfer
- T1571Non-Standard Port
- T1572Protocol Tunneling
- T1573Encrypted Channel
- T1573.001Symmetric Cryptography
- T1573.002Asymmetric Cryptography
Cite as SafeMode Space, d3fend D3-APCA.