Exfiltration Over Other Network Medium
Description
Adversaries may attempt to exfiltrate data over a different network medium than the command and control channel. If the command and control network is a wired Internet connection, the exfiltration may occur, for example, over a WiFi connection, modem, cellular data connection, Bluetooth, or another radio frequency (RF) channel. Adversaries may choose to do this if they have sufficient access or proximity, and the connection might not be secured or defended as well as the primary Internet-connected channel because it is not routed through the same enterprise network.
Mapped SPARTA techniques
6 techniques
T1011 'Exfiltration Over Other Network Medium' is the exact-concept ATT&CK exfiltration-tactic technique for using a non-primary network medium to exfiltrate data; SPARTA EXF-0004 'Out-of-Band Communications Link' is the spacecraft instance (use secondary/maintenance/beacon channels for covert data movement). Tactic and activity align directly.
Proximity operations exfiltration uses a co-orbital/proximate vehicle as a TEMPEST/EMSEC sensor capturing emanations and weak crosslink leakage — this is exfiltration via a non-primary network medium (the proximity-RF channel). T1011 'Exfiltration Over Other Network Medium' covers the conceptual pattern; cross-domain moderate honors that MITRE's typical example is Bluetooth-style enterprise alternate links.
Modifying communications configuration to create covert downlink/crosslink paths is creating an alternate-medium exfil channel — direct match for T1011 'Exfiltration Over Other Network Medium'. The reconfigured carrier/subcarrier/virtual-channel becomes the non-primary medium. Tactic-aligned.
SDR reconfiguration (adding subcarriers, changing modulation, scheduling maintenance bursts) creates an alternate exfil medium piggybacking on the standard waveform — exact instance of T1011 applied to programmable-radio reconfiguration.
Transponder reconfiguration (remapping inputs/outputs, shifting translation, enabling auxiliary ports) routes mission data to non-mission receivers — exact instance of T1011 applied to bent-pipe/regenerative transponder configuration.
Payload communication channels (direct-to-user terminals, customer VPN-tunneled feeds, experimenter relay paths) are non-primary network media distinct from the TT&C channel — SPARTA EXF-0010 covers using these for exfil, exact match for T1011 'Exfiltration Over Other Network Medium'. Tactic-aligned.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Countered by 9 in MITRE D3FEND (Defensive Techniques)
- D3-APCAApplication Protocol Command Analysis
- D3-CSPPClient-server Payload Profiling
- D3-NTCDNetwork Traffic Community Deviation
- D3-NTFNetwork Traffic Filtering
- D3-NTSANetwork Traffic Signature Analysis
- D3-PHDURAPer Host Download-Upload Ratio Analysis
- D3-PMADProtocol Metadata Anomaly Detection
- D3-RTSDRemote Terminal Session Detection
- D3-UGLPAUser Geolocation Logon Pattern Analysis
Cite as SafeMode Space, mitre-attack-enterprise T1011.