All ENISA publications
ENISA-STL-2025-03-sD.29-i02

Publication: enisa-stl-2025-03 Space Threat Landscape

Full text

The control text is third-party content; see the official source for the full wording.

Mapped SPARTA techniques

17 techniques

  • DE-0007Evasion via RootkitST0006
    mitigates
    high

    On-board IDS/IPS surfaces rootkit activity (hooked command handlers, falsified events) that masks malicious actions.

  • Establishing and documenting normal network activity for ground SDA mission applications is relevant to later anomaly detection, but the excerpt describes baselining rather than active detection or prevention of the ingestion saturation and track injection DE-0009.05 performs.

  • EX-0010Malicious CodeST0004
    addresses
    high

    On-board IDS/IPS with response/log capability and integration with fault management surfaces malicious-code execution and supports countermeasure selection.

  • EX-0010.03RootkitST0004
    mitigates
    high

    On-board IDS/IPS monitoring mission-critical components surfaces rootkit telemetry-filtering and command-handler-hooking activity even when system reports look healthy.

  • EX-0013FloodingST0004
    addresses
    high

    Intrusion detection and prevention with response capability detects flooding patterns and selects safe countermeasures (rate limiting, isolation).

  • EX-0013.01Valid CommandsST0004
    addresses
    high

    On-board IDS/IPS surfaces excessive cadence of valid commands and selects safe countermeasures.

  • EX-0013.02Erroneous InputST0004
    addresses
    moderate

    IDS/IPS detects malformed-traffic patterns and provides countermeasures within fault-management constraints.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    moderate

    Intrusion detection and prevention with documented baselines surfaces bulk extraction patterns and abnormal staging activity in ground systems.

  • IA-0004.01Ground StationST0003
    addresses
    high

    Intrusion detection and prevention covering backup ground systems surfaces the establishment of presence on standby chains before they activate.

  • Intrusion detection and prevention with documented network baselines surfaces the deep reconnaissance and command preparation that defines IA-0007.

  • IA-0009Trusted RelationshipST0003
    mitigates
    moderate

    Intrusion detection and prevention on connections from partner enclaves identifies anomalies even when traffic originates from a trusted route.

  • IA-0009.03User SegmentST0003
    mitigates
    moderate

    Intrusion detection at the user-segment-to-mission boundary identifies malformed tasking requests propagating into payload scheduling.

  • Intrusion detection and prevention with documented baseline activities surfaces the late firmware loads, key/counter initialisation, and full-system rehearsals IA-0012 abuses.

  • Intrusion detection and prevention with documented baselines surfaces the durable reconnaissance and continuous staging that defines PER-0003 ground presence.

  • Intrusion detection and prevention on mission-critical components surfaces the compromise activity central to RD-0002.

  • Intrusion detection and prevention with traffic baselines for mission-operated ground systems detects the compromise activity that defines this sub-technique.

  • Intrusion detection and prevention on mission-critical components detects payload-delivery attempts at the boundary or on the spacecraft itself.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.