Connection Attempt Analysis
Description
Analyzing failed connections in a network to detect unauthorized activity.
Mapped SPARTA techniques
1 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Connection Attempt Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 15 in MITRE ATT&CK Enterprise
- T1003.006DCSync
- T1021Remote Services
- T1047Windows Management Instrumentation
- T1090.001Internal Proxy
- T1098.001Additional Cloud Credentials
- T1110.003Password Spraying
- T1110.004Credential Stuffing
- T1197BITS Jobs
- T1199Trusted Relationship
- T1207Rogue Domain Controller
- T1210Exploitation of Remote Services
- T1546.003Windows Management Instrumentation Event Subscription
- T1546.008Accessibility Features
- T1557.001LLMNR/NBT-NS Poisoning and SMB Relay
- T1570Lateral Tool Transfer
Cite as SafeMode Space, d3fend D3-CAA.