Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
33 techniques
Configuration management with documented baselines covers the parameter and limit tables, command interlocks, and inhibit masks DE-0001 modifies.
Configuration management of telemetry mode, packet filters, and reporting rates surfaces unauthorised modifications that suppress on-board telemetry generation.
Configuration management of mode indicators, downlink modes, and crypto-mode selectors detects unauthorised obfuscation of on-board values.
Configuration management of command-receiver enable/disable states is the discipline that surfaces deliberate quiet-window manipulation.
Configuration management of AGC parameters surfaces unauthorised modifications used to suppress specific signals.
Configuration management of receiver lock-mode settings detects unauthorised modifications that bias acquisition states.
Telemetry downlink modes (real-time channels, recorder playback, beacon/summary, event-driven) are configuration items whose baseline must be monitored under configuration management.
Configuration management of crypto-profile selectors and key-ID rotation surfaces unauthorised mode flips.
Configuration management of clock disciplining sources and time-service settings detects unauthorised slewing for evasion.
Configuration management of watchdog-timer parameters establishes the baseline whose modification DE-0003.11 attempts to mask process activity.
Configuration management of whitelist baselines surfaces additions of unauthorised entries.
Configuration management of boot configuration words, image-selection logic, and device trees detects bootkit-installed hooks that persist across resets.
Configuration management with monitoring of security configurations identifies modifications to policy tables, key identifiers, and counter initialization.
Configuration management of boot-configuration words, OTP fuses, and image-selection logic identifies unauthorized changes that EX-0004 introduces.
Configuration management with least-functionality baseline removes maintenance and contingency-mode hardware commands not required in nominal operations.
Configuration management with monitoring of security configurations detects modifications that toggle test modes or downgrade negotiated suites.
Configuration management with the principle of least functionality removes maintenance shells and management consoles from the flight build.
Configuration management of boot configuration words, fuses, and image-selection logic detects modifications a bootkit makes to redirect early-boot trust.
Configuration management with documented, monitored, and reviewed configurations is the discipline that detects unauthorised modifications to control data EX-0012 makes.
Configuration-management baselines for security configurations cover device and control registers — the values EX-0012.01 modifies.
Routing/subscriber tables are configuration items whose baseline must be established, documented, monitored, and reviewed under configuration management.
Application/subscriber tables are configuration items under configuration management; modifications outside the baseline are flagged.
Schedules and timeline configurations fall under documented configuration baselines whose unauthorised modification triggers review.
Configuration management of the C&DH baseline detects unauthorised modifications EX-0012.10 makes.
Watchdog-timer values are configuration items whose baseline must be documented and monitored under configuration management.
Configuration management of system-clock baselines detects unauthorised slewing or epoch changes.
Configuration management of distributed time-service settings detects unauthorised slewing toward attacker-chosen values.
Configuration management of secondary-link enable states, beacon configurations, and contingency profiles surfaces unauthorised activation of out-of-band paths.
Configuration management of radio/optical link configuration — carriers, modulation/coding profiles, virtual channels, beacon content, regenerative routing tables — directly defeats EXF-0006 unauthorised modifications.
Configuration management of SDR profiles (DSP chains, filters, mixers, FEC, framing) surfaces unauthorised modifications introducing covert subcarriers or modified preambles.
Configuration management of transponder input-output paths, translation frequencies, polarization, gain, and routing tables surfaces unauthorised re-routing for covert downlinks.
Configuration management of init scripts, table loaders, and event hooks detects modifications used to reinstate unauthorized logic on boot.
Configuration management of key identifiers, selectors, and algorithm profiles detects unauthorised changes to crypto material configuration.