Relay Pattern Analysis
Description
The detection of an internal host relaying traffic between the internal network and the external network.
Mapped SPARTA techniques
1 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Relay Pattern Analysis counters T1567 Exfiltration Over Web Service; SafeMode's curated mapping records EXF-0008 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 31 in MITRE ATT&CK Enterprise
- T1001Data Obfuscation
- T1008Fallback Channels
- T1048.001Exfiltration Over Symmetric Encrypted Non-C2 Protocol
- T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1048.003Exfiltration Over Unencrypted Non-C2 Protocol
- T1071Application Layer Protocol
- T1071.001Web Protocols
- T1071.002File Transfer Protocols
- T1071.003Mail Protocols
- T1071.004DNS
- T1090.002External Proxy
- T1090.003Multi-hop Proxy
- T1090.004Domain Fronting
- T1095Non-Application Layer Protocol
- T1102Web Service
- T1104Multi-Stage Channels
- T1105Ingress Tool Transfer
- T1132Data Encoding
- T1189Drive-by Compromise
- T1197BITS Jobs
- T1204.001Malicious Link
- T1219Remote Access Tools
- T1567Exfiltration Over Web Service
- T1567.001Exfiltration to Code Repository
- T1567.002Exfiltration to Cloud Storage
- T1568Dynamic Resolution
- T1571Non-Standard Port
- T1572Protocol Tunneling
- T1573Encrypted Channel
- T1573.001Symmetric Cryptography
- T1573.002Asymmetric Cryptography
Cite as SafeMode Space, d3fend D3-RPA.