MITRE D3FEND (Defensive Techniques)
D3-RPA

Relay Pattern Analysis

Description

The detection of an internal host relaying traffic between the internal network and the external network.

Mapped SPARTA techniques

1 techniques

  • EXF-0008Compromised Developer SiteST0008
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Relay Pattern Analysis counters T1567 Exfiltration Over Web Service; SafeMode's curated mapping records EXF-0008 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Cite as SafeMode Space, d3fend D3-RPA.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.