Gather Victim Mission Information
Description
An attacker tries to gather information about a specific mission to target it. An attacker can find information about firmware, software, hardware, frequencies, protocols, cryptographic algorithms, spacecraft descriptors used in a mission, and other knowledge like the spacecraft design, architecture, position and trajectory. The application of this technique in the supply chain can lead to a software/tools/datasheets or a design leak. If COTS or open-source components are used, information can be easily gathered online or from the producing company. Relevant standards: (Citation: SRC038)(Citation: ESA Security Framework)
Mapped SPARTA techniques
25 techniques
T2002 'Gather Victim Mission Information' is SPACE-SHIELD's reconnaissance technique covering pre-attack collection of design information (firmware, software, hardware, frequencies, protocols, cryptographic algorithms, spacecraft descriptors) and is the cross-framework equivalent of the SPARTA REC-0001 generic 'gather spacecraft design information' technique.
Software design reconnaissance is explicitly enumerated in T2002's listed targets ('firmware, software, ...'); SPACE-SHIELD has no narrower 'software design' sub-technique under T2002, so the parent is the most specific applicable level.
Firmware reconnaissance is explicitly named in T2002's listed targets; SPACE-SHIELD has no firmware-specific reconnaissance sub-technique, so T2002 is the most specific applicable level.
Cryptographic algorithm reconnaissance is explicitly named in T2002 ('cryptographic algorithms') and SPACE-SHIELD has no narrower pre-attack crypto-recon technique; T2032 (Key Management Policy Discovery) is post-access tactic 'discovery' and was excluded.
Data bus reconnaissance falls within T2002's hardware/protocol target scope; SPACE-SHIELD has no bus-specific reconnaissance technique.
Thermal control system reconnaissance is gathering hardware/architecture information about the spacecraft, covered by T2002's broad scope ('spacecraft design, architecture').
Maneuver and control (GNC) reconnaissance is gathering spacecraft design and architecture information, covered by T2002's broad scope including 'position and trajectory'.
Payload reconnaissance is gathering hardware/software/protocol information about a mission element, squarely within T2002's pre-attack mission information scope.
Power system reconnaissance falls within T2002's hardware/architecture target scope.
Fault management (FDIR/safing) reconnaissance is gathering software/architecture information, covered by T2002.
T2002 explicitly enumerates 'spacecraft descriptors used in a mission' as a reconnaissance target, directly aligning with REC-0002's identifier/operator/orbit dossier.
Identifier enumeration (NORAD, COSPAR, call signs, slot tags) is exactly the 'spacecraft descriptors' scope listed in T2002.
Operational descriptors (CONOPS, pass schedules, calibration timelines) are mission information of the type T2002 collects to time follow-on actions.
T2002 explicitly enumerates 'frequencies, protocols' as reconnaissance targets, directly aligning with REC-0003's RF/networking-posture collection.
Communications equipment reconnaissance is gathering hardware information, covered by T2002's hardware/protocol scope.
Studying telecommand framing, authentication, and command dictionaries is gathering protocol/cryptographic information — squarely within T2002's pre-attack scope.
Launch information collection (windows, vehicle, range, ascent comms, LEOP procedures) is mission information of the kind T2002 enumerates; SPACE-SHIELD has no launch-specific reconnaissance technique.
Flight termination intelligence (architecture, authority chains, crypto protections) is mission/architecture information; T2002 is the broadest applicable SPACE-SHIELD reconnaissance technique because no FTS-specific entry exists.
FSW development information (architecture, SBOMs, toolchains, CI/CD, autonomy logic) is software/firmware information of the kind T2002 enumerates; SPACE-SHIELD has no FSW-development-specific reconnaissance technique.
Development environment reconnaissance (IDEs, compilers, repos, CI orchestrators) overlaps T2002's software-toolchain scope but is more org-internal than the typical T2002 mission-info target.
Knowledge of security testing tools (analyzers, fuzzers, HIL setups) is software/process information of the type T2002 covers; no SPACE-SHIELD entry specifically targets test-tool reconnaissance.
Supply chain reconnaissance (manufacturers, lots, BOMs, tooling) collects hardware/software/firmware information of the kind T2002 lists, though SPACE-SHIELD does not have a supply-chain-specific reconnaissance technique.
Hardware reconnaissance (component sources, screening levels, FPGA bitstream provenance) is hardware information of the type T2002 explicitly enumerates as a target.
Software factory reconnaissance (repos, CI/CD, registries, signing services) collects software information explicitly named as a T2002 target.
T2002 'Gather Victim Mission Information' is the direct title-and-scope counterpart of REC-0009 Gather Mission Information — both describe collecting CONOPS-level mission information to time and target follow-on actions.
Cite as SafeMode Space, space-shield T2002.