ESA SPACE-SHIELD
T2009

Valid Credentials

Description

Adversaries may obtain and abuse credentials to gain Initial Access or Persistence in a space resource. Compromised credentials may be used to bypass access controls placed on systems within the network and to decrypt communication, to send authenticate messages and to take control of the spacecraft. Gained credentials may even be used for persistent access to the resource. Adversaries may obtain and abuse master or session keys, or target the digital certificates used for the authentication. Standards: (Citation: SRC014) (Citation: SRC039)

Mapped SPARTA techniques

4 techniques

  • DE-0011Credentialed EvasionST0006
    addresses
    high

    T2009 'Valid Credentials' is the direct cross-framework counterpart of DE-0011 — both describe leveraging valid credentials to bypass access controls and blend with legitimate operations.

  • T2009 'Valid Credentials' is the direct cross-framework counterpart of LM-0007 — both describe reusing legitimate credentials to bypass access controls and traverse trust boundaries within the network.

  • T2009 'Valid Credentials' explicitly covers obtaining and abusing credentials for Initial Access OR Persistence — direct match to PER-0005 Credentialed Persistence (using legitimate credentials to maintain long-lived access).

  • REC-0003.04Valid CredentialsST0001
    addresses
    high

    T2009 'Valid Credentials' is the direct cross-framework counterpart of REC-0003.04 — both describe acquiring legitimate credentials (cryptographic keys, station accounts) usable to authenticate or decrypt.

Cite as SafeMode Space, space-shield T2009.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.