Use of Unexpected Protocol on Out-of-Band Link

Monitors for protocol deviations on the out-of-band link, which could indicate exploitation attempts.

STIX Pattern

[network-traffic:protocols != 'expected_protocol' AND network-traffic:src_ref.channel = 'out_of_band']

SPARTA TTPs

ID Name Description
EXF-0004 Out-of-Band Communications Link Threat actors may attempt to exfiltrate data via the out-of-band communication channels. While performing eavesdropping on the primary/second uplinks and downlinks is a method for exfiltration, some space vehicles leverage out-of-band communication links to perform actions on the space vehicle (i.e., re-keying). These out-of-band links would occur on completely different channels/frequencies and often operate on separate hardware on the space vehicle. Typically these out-of-band links have limited built-for-purpose functionality and likely do not present an initial access vector but they do provide ample exfiltration opportunity.