ESA SPACE-SHIELD
T1070.001
enhancement

Clear Log/Command History

Parent: T1070

Description

If a log is available, an attacker can delete logging onboard the spacecraft to hide illegitimate operations (a TC log service is usually not implemented). (Citation: MITRE ATT&CK)

Mapped SPARTA techniques

3 techniques

  • DE-0003.08Received CommandsST0006
    addresses
    high

    T1070.001 'Clear Log/Command History' explicitly covers deleting onboard logging to hide illegitimate operations — direct match to DE-0003.08's editing/pruning of command-history buffers, logs, and event records.

  • DE-0007Evasion via RootkitST0006
    addresses
    moderate

    T1070.001 'Clear Log/Command History' covers the log-clearing subset of rootkit evasion (filtering telemetry packets, rewriting recorder catalogs, biasing housekeeping).

  • DE-0010Overflow Audit LogST0006
    addresses
    high

    T1070.001 'Clear Log/Command History' is the direct cross-framework counterpart for log overflow — both describe overwriting onboard logging to hide illegitimate operations (DE-0010 achieves this via buffer exhaustion rather than direct deletion).

Cite as SafeMode Space, space-shield T1070.001.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.