Exfiltration Over C2 Channel
Description
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
Mapped SPARTA techniques
2 techniques
T1041 'Exfiltration Over C2 Channel' is the ATT&CK exfiltration-tactic technique for siphoning data over the legitimate command-and-control channel; SPARTA EXF-0007 covers compromised-ground-system exfiltration where the GS's legitimate data-distribution paths (telemetry forwarders, archive databases, cross-site links) are the C2-equivalent channel. Tactic and activity align directly.
MITRE Enterprise has no impact-tactic data-theft technique; the theft outcome is captured through the exfiltration mechanism (T1041 Exfiltration Over C2 Channel and related). T1041 covers data theft via the legitimate C2 channel — the primary mechanism for SPARTA IMP-0006 'Theft' (steal mission-critical data via spacecraft downlink). Cross-tactic moderate (exfiltration vs impact) honors MITRE's separation of exfil-mechanism from impact-outcome where SPARTA combines them.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Countered by 21 in MITRE D3FEND (Defensive Techniques)
- D3-APCAApplication Protocol Command Analysis
- D3-CACertificate Analysis
- D3-CFContent Filtering
- D3-CMContent Modification
- D3-CQContent Quarantine
- D3-CSPPClient-server Payload Profiling
- D3-DFDecoy File
- D3-FAFile Analysis
- D3-FEFile Encryption
- D3-FEVFile Eviction
- D3-FIMFile Integrity Monitoring
- D3-LFPLocal File Permissions
- D3-NTCDNetwork Traffic Community Deviation
- D3-NTFNetwork Traffic Filtering
- D3-NTSANetwork Traffic Signature Analysis
- D3-PHDURAPer Host Download-Upload Ratio Analysis
- D3-PMADProtocol Metadata Anomaly Detection
- D3-RFRestore File
- D3-RFAMRemote File Access Mediation
- D3-RTSDRemote Terminal Session Detection
- D3-UGLPAUser Geolocation Logon Pattern Analysis
Cite as SafeMode Space, mitre-attack-enterprise T1041.