ESA SPACE-SHIELD
T2009.002
enhancement

Forge Digital Certificates

Parent: T2009

Description

If an attacker gains control of the credential-management system and issues credentials, he can access the system and maintain a persistent control on it. There is a need to invalidate existing credentials and reissue all credentials. CCSDS recommends two forms of credentials: X.509 certificates and protected simple authentication. The authenticity of an X.509 certificate is dependent upon the digital signature of the CA attesting to the credential. If the digital signature algorithm used by the CA is of insufficient cryptographic strength, a credential may be spoofed. (Citation: MITRE ATT&CK) Standard/references: (Citation: SRC014)

Mapped SPARTA techniques

1 techniques

  • T2009.002 'Forge Digital Certificates' captures EX-0003's credential-management process compromise scope (gaining control of the credential-management system to issue forged credentials).

Cite as SafeMode Space, space-shield T2009.002.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.