Use of Unexpected Protocol on Out-of-Band Link

Monitors for protocol deviations on the out-of-band link, which could indicate exploitation attempts.

STIX Pattern

[network-traffic:protocols != 'expected_protocol' AND network-traffic:src_ref.channel = 'out_of_band']

SPARTA TTPs

ID Name Description
EXF-0004 Out-of-Band Communications Link Some missions field secondary links, separate frequencies and hardware, for limited, purpose-built functions (e.g., rekeying, emergency commanding, beacons, custodial crosslinks). Adversaries co-opt these channels as covert data paths: embedding content in maintenance messages, beacon fields, or low-rate housekeeping; initiating vendor/service modes that carry file fragments; or switching to contingency profiles that bypass normal routing and monitoring. Because these paths are distinct from the main TT&C and may be sparsely supervised, they provide discreet avenues to move data off the spacecraft or to external relays without altering the primary link’s traffic patterns.