Gather Victim Org Information
Description
Adversaries may gather information about the victim's organization that can be used during targeting. Information about an organization may include a variety of details, including the names of divisions/departments, specifics of business operations, as well as the roles and responsibilities of key employees. (Citation: MITRE ATT&CK) Relevant standards: (Citation: SRC038)(Citation: ESA Security Framework)
Mapped SPARTA techniques
6 techniques
T1591 'Gather Victim Org Information' partially covers REC-0002 because spacecraft descriptors include operator and country of registry — organizational facets that fall under T1591's scope.
T1591 'Gather Victim Org Information' is the canonical SPACE-SHIELD reconnaissance technique for organizational mapping (divisions, employees, business operations), an exact topical match to REC-0002.02 Organization.
Ops handovers, staffing patterns, and decision chains overlap T1591's organizational scope (roles/responsibilities of key employees, business operations).
Enumerating dev-team tooling, repository ownership, and access models leverages organizational information that T1591 explicitly covers (employee roles, business operations).
Enumerating manufacturers, integrators, and contractors is gathering victim-organization information of the kind T1591 covers (divisions/departments, business operations).
Mapping prime/sub/MSP/contractor relationships, org charts, and trust bridges is the exact scope of T1591 'Gather Victim Org Information'. T2033 'Trust Relationships Discovery' was excluded because it is a post-access discovery technique, not pre-access reconnaissance.
Cite as SafeMode Space, space-shield T1591.