TC/TM eavesdropping
Parent: T2018
Description
An attacker can collect and have access to data transmitted by TT&C if the communication doesn't rely on encryption. (Citation: SRC017) Standard/references: (Citation: SRC003) (Citation: SRC008) (Citation: SRC009) (Citation: SRC010)
Mapped SPARTA techniques
5 techniques
T2018.003 'TC/TM eavesdropping' covers collecting TT&C transmitted data when communication lacks encryption — addresses EXF-0003.01's exfiltration of opcode/argument content from uplink when confidentiality is weak.
T2018.003 'TC/TM eavesdropping' covers TM-channel eavesdropping when communication lacks encryption — direct match to EXF-0003.02's downlink-frame demodulation and offline extraction when downlink content is in clear.
T2018.003 'TC/TM eavesdropping' covers uplink (TC) eavesdropping when the link lacks encryption — directly aligning with REC-0005.01's content-capture aspect.
T2018.003 'TC/TM eavesdropping' covers downlink (TM) eavesdropping when the link lacks encryption.
T2018.003 'TC/TM eavesdropping' covers passive collection of telemetry that includes mode bits and event packets indicating safing — the data-content side of REC-0007.
Cite as SafeMode Space, space-shield T2018.003.