Stored Data Manipulation
Parent: T1565
Description
Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data.(Citation: FireEye APT38 Oct 2018)(Citation: DOJ Lazarus Sony 2018) By manipulating stored data, adversaries may attempt to affect a business process, organizational understanding, and decision making. Stored data could include a variety of file formats, such as Office files, databases, stored emails, and custom file formats. The type of modification and the impact it will have depends on the type of data as well as the goals and objectives of the adversary. For complex systems, an adversary would likely need special expertise and possibly access to specialized software related to the system that would typically be gained through a prolonged information gathering campaign in order to have the desired impact.
Mapped SPARTA techniques
13 techniques
Training data is stored data used to train models; T1565.001 'Stored Data Manipulation' covers manipulation of the training corpus itself (the underlying data-modification activity). Cross-tactic moderate (impact vs defense-evasion).
Corrupting SDA-system stored data (track files, catalog entries, ephemeris archives) is T1565.001 'Stored Data Manipulation' applied to the SDA database layer. Cross-tactic moderate (impact vs defense-evasion).
Internal routing tables (CCSDS APID routing, bus address translation, virtual-channel maps) are stored configuration data; T1565.001 'Stored Data Manipulation' covers tampering with such stored configuration. Cross-tactic moderate.
Memory writes that target stored configuration regions (lookup tables, calibration data, persistent counters) also fit T1565.001 'Stored Data Manipulation'; the two sub-techniques together cover both in-flight and at-rest aspects of memory modification.
App/subscriber tables (cFS publisher-subscriber routing, message bus subscription lists) are stored configuration; tampering with them is T1565.001 'Stored Data Manipulation' applied to the FSW middleware layer.
Scheduling-algorithm parameters (task priorities, time-slice budgets, queue depths) are stored RTOS configuration; modifying them maps to T1565.001 'Stored Data Manipulation' at the scheduler-config level.
Science/payload data products are stored on spacecraft mass memory before downlink; manipulating them maps to T1565.001 'Stored Data Manipulation' applied to the payload data store. Cross-tactic moderate.
Propulsion subsystem parameters (delta-V budgets, valve duty cycles, burn timing tables) are stored configuration tables; modifying them is T1565.001 'Stored Data Manipulation' applied to subsystem control data.
ADCS parameters (control-loop gains, deadbands, mode-transition tables, sensor-fusion weights) are stored configuration; manipulating them maps to T1565.001 'Stored Data Manipulation' at the attitude-control-config level.
Electrical Power Subsystem parameters (load-shed thresholds, battery-protect setpoints, MPPT calibration) are stored EPS configuration; modifying them maps to T1565.001 'Stored Data Manipulation'.
C&DH parameters (command dispatch tables, telemetry packetisation rules, virtual-channel mappings) are stored configuration; manipulating them maps to T1565.001 'Stored Data Manipulation'.
Watchdog Timer (WDT) parameters (timeout values, reset-action rules, kick patterns) are stored configuration; modifying them to extend or disable the watchdog is T1565.001 'Stored Data Manipulation' applied to a defensive subsystem's config.
AI/ML training data is stored data used to train onboard inference models; poisoning it maps to T1565.001 'Stored Data Manipulation' applied to the ML pipeline's training corpus.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Countered by 11 in MITRE D3FEND (Defensive Techniques)
Cite as SafeMode Space, mitre-attack-enterprise T1565.001.