Content Quarantine
Description
Transfer content that does not comply with policy to a quarantine zone.
Mapped SPARTA techniques
2 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Content Quarantine counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records EXF-0007 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Content Quarantine counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 109 in MITRE ATT&CK Enterprise
- T1003.007Proc Filesystem
- T1003.008/etc/passwd and /etc/shadow
- T1005Data from Local System
- T1014Rootkit
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1027.001Binary Padding
- T1027.002Software Packing
- T1027.004Compile After Delivery
- T1033System Owner/User Discovery
- T1036.001Invalid Code Signature
- T1036.003Rename Legitimate Utilities
- T1036.005Match Legitimate Resource Name or Location
- T1036.006Space after Filename
- T1037.001Logon Script (Windows)
- T1037.002Login Hook
- T1037.003Network Logon Script
- T1037.004RC Scripts
- T1041Exfiltration Over C2 Channel
- T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1055.001Dynamic-link Library Injection
- T1055.002Portable Executable Injection
- T1055.003Thread Execution Hijacking
- T1055.009Proc Memory
- T1055.014VDSO Hijacking
- T1059Command and Scripting Interpreter
- T1070.002Clear Linux or Mac System Logs
- T1070.004File Deletion
- T1071Application Layer Protocol
- T1071.001Web Protocols
- T1072Software Deployment Tools
- T1074.001Local Data Staging
- T1083File and Directory Discovery
- T1114.001Local Email Collection
- T1119Automated Collection
- T1127.001MSBuild
- T1137.001Office Template Macros
- T1137.002Office Test
- T1137.003Outlook Forms
- T1140Deobfuscate/Decode Files or Information
- T1187Forced Authentication
- T1204.002Malicious File
- T1218.002Control Panel
- T1218.005Mshta
- T1218.011Rundll32
- T1220XSL Script Processing
- T1486Data Encrypted for Impact
- T1505.003Web Shell
- T1518.001Security Software Discovery
- T1534Internal Spearphishing
- T1543.001Launch Agent
- T1543.002Systemd Service
- T1543.004Launch Daemon
- T1546.001Change Default File Association
- T1546.002Screensaver
- T1546.004Unix Shell Configuration Modification
- T1546.005Trap
- T1546.006LC_LOAD_DYLIB Addition
- T1546.007Netsh Helper DLL
- T1546.008Accessibility Features
- T1546.009AppCert DLLs
- T1546.010AppInit DLLs
- T1546.013PowerShell Profile
- T1546.014Emond
- T1546.015Component Object Model Hijacking
- T1547.001Registry Run Keys / Startup Folder
- T1547.002Authentication Package
- T1547.003Time Providers
- T1547.004Winlogon Helper DLL
- T1547.005Security Support Provider
- T1547.006Kernel Modules and Extensions
- T1547.007Re-opened Applications
- T1547.008LSASS Driver
- T1547.009Shortcut Modification
- T1547.010Port Monitors
- T1548.002Bypass User Account Control
- T1548.003Sudo and Sudo Caching
- T1552.001Credentials In Files
- T1552.003Shell History
- T1553.003SIP and Trust Provider Hijacking
- T1555Credentials from Password Stores
- T1555.003Credentials from Web Browsers
- T1556.002Password Filter DLL
- T1556.003Pluggable Authentication Modules
- T1560Archive Collected Data
- T1560.001Archive via Utility
- T1560.002Archive via Library
- T1560.003Archive via Custom Method
- T1562.003Impair Command History Logging
- T1562.009Safe Mode Boot
- T1564.002Hidden Users
- T1564.003Hidden Window
- T1564.006Run Virtual Instance
- T1564.007VBA Stomping
- T1565.001Stored Data Manipulation
- T1565.003Runtime Data Manipulation
- T1566.001Spearphishing Attachment
- T1566.002Spearphishing Link
- T1566.003Spearphishing via Service
- T1573.002Asymmetric Cryptography
- T1574.001DLL
- T1574.004Dylib Hijacking
- T1574.006Dynamic Linker Hijacking
- T1574.007Path Interception by PATH Environment Variable
- T1574.008Path Interception by Search Order Hijacking
- T1574.009Path Interception by Unquoted Path
- T1574.011Services Registry Permissions Weakness
- T1574.012COR_PROFILER
- T1649Steal or Forge Authentication Certificates
Cite as SafeMode Space, d3fend D3-CQ.