Protocol Metadata Anomaly Detection
Description
Collecting network communication protocol metadata and identifying statistical outliers.
Mapped SPARTA techniques
23 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records DE-0009.04 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014.01 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014.02 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1565.002 Transmitted Data Manipulation; SafeMode's curated mapping records EX-0014.03 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0004 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0006 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0006.01 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0006.02 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records EXF-0007 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1567 Exfiltration Over Web Service; SafeMode's curated mapping records EXF-0008 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1048 Exfiltration Over Alternative Protocol; SafeMode's curated mapping records EXF-0009 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0010 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1199 Trusted Relationship; SafeMode's curated mapping records IA-0003 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1199 Trusted Relationship; SafeMode's curated mapping records IA-0006 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1190 Exploit Public-Facing Application; SafeMode's curated mapping records IA-0007 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1199 Trusted Relationship; SafeMode's curated mapping records IA-0013 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1210 Exploitation of Remote Services; SafeMode's curated mapping records LM-0001 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1210 Exploitation of Remote Services; SafeMode's curated mapping records LM-0002 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1021 Remote Services; SafeMode's curated mapping records LM-0003 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1021 Remote Services; SafeMode's curated mapping records LM-0004 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 72 in MITRE ATT&CK Enterprise
- T1001Data Obfuscation
- T1003.006DCSync
- T1008Fallback Channels
- T1011Exfiltration Over Other Network Medium
- T1018Remote System Discovery
- T1020Automated Exfiltration
- T1021Remote Services
- T1021.001Remote Desktop Protocol
- T1021.004SSH
- T1029Scheduled Transfer
- T1030Data Transfer Size Limits
- T1041Exfiltration Over C2 Channel
- T1047Windows Management Instrumentation
- T1048Exfiltration Over Alternative Protocol
- T1048.001Exfiltration Over Symmetric Encrypted Non-C2 Protocol
- T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1048.003Exfiltration Over Unencrypted Non-C2 Protocol
- T1071Application Layer Protocol
- T1071.001Web Protocols
- T1071.002File Transfer Protocols
- T1071.003Mail Protocols
- T1071.004DNS
- T1090.001Internal Proxy
- T1090.002External Proxy
- T1090.003Multi-hop Proxy
- T1090.004Domain Fronting
- T1095Non-Application Layer Protocol
- T1098.001Additional Cloud Credentials
- T1102Web Service
- T1104Multi-Stage Channels
- T1105Ingress Tool Transfer
- T1110.003Password Spraying
- T1110.004Credential Stuffing
- T1132Data Encoding
- T1185Browser Session Hijacking
- T1189Drive-by Compromise
- T1190Exploit Public-Facing Application
- T1197BITS Jobs
- T1199Trusted Relationship
- T1204.001Malicious Link
- T1205Traffic Signaling
- T1205.001Port Knocking
- T1207Rogue Domain Controller
- T1210Exploitation of Remote Services
- T1218.003CMSTP
- T1219Remote Access Tools
- T1498.001Direct Network Flood
- T1498.002Reflection Amplification
- T1499.002Service Exhaustion Flood
- T1542.005TFTP Boot
- T1546.003Windows Management Instrumentation Event Subscription
- T1546.008Accessibility Features
- T1550.001Application Access Token
- T1550.004Web Session Cookie
- T1557Adversary-in-the-Middle
- T1557.001LLMNR/NBT-NS Poisoning and SMB Relay
- T1557.003DHCP Spoofing
- T1558.003Kerberoasting
- T1563Remote Service Session Hijacking
- T1565.002Transmitted Data Manipulation
- T1566.001Spearphishing Attachment
- T1566.002Spearphishing Link
- T1567Exfiltration Over Web Service
- T1567.001Exfiltration to Code Repository
- T1567.002Exfiltration to Cloud Storage
- T1568Dynamic Resolution
- T1570Lateral Tool Transfer
- T1571Non-Standard Port
- T1572Protocol Tunneling
- T1573Encrypted Channel
- T1573.001Symmetric Cryptography
- T1573.002Asymmetric Cryptography
Cite as SafeMode Space, d3fend D3-PMAD.