ESA SPACE-SHIELD
T2054.001
enhancement

Stored Data Manipulation

Parent: T2054

Description

An attacker can alter or corrupt stored data within a system, such as mission control databases, payload data storage, or onboard systems. Manipulating stored data can lead to incorrect decision-making, confusion, or operational errors, especially if the data is used for mission-critical analysis or operations. Preventive measures include employing encryption, access control, and integrity-checking mechanisms to ensure the authenticity and reliability of the stored data.

Mapped SPARTA techniques

23 techniques

  • T2054.001 'Stored Data Manipulation' explicitly covers altering stored data including 'mission control databases' and 'onboard systems' — direct match to DE-0003's manipulation of housekeeping/control values (counters, mode flags, crypto-mode indicators) that operators trust.

  • T2054.001 covers stored-data manipulation — addresses DE-0003.01's zeroing/freezing/forging of the Vehicle Command Counter telemetry field.

  • DE-0003.02Rejected Command CounterST0006
    addresses
    moderate

    T2054.001 covers stored-data manipulation — addresses DE-0003.02's suppression/clearing of the Rejected Command Counter and reason-code tampering.

  • T2054.001 covers stored-data manipulation — addresses DE-0003.03's toggling of receiver enable states and stored configuration that governs command-receiver activation.

  • T2054.001 covers stored-data manipulation — addresses DE-0003.04's targeting of receiver AGC/RSS configuration values to suppress command processing.

  • T2054.001 covers stored-data manipulation — addresses DE-0003.05's freezing/clearing of receiver lock flags and counters and threshold tampering.

  • DE-0003.06Telemetry Downlink ModesST0006
    addresses
    moderate

    T2054.001 covers stored-data manipulation — addresses DE-0003.06's editing of telemetry mode parameters (rates, filters, virtual-channel selections, playback queues).

  • DE-0003.07Cryptographic ModesST0006
    addresses
    moderate

    T2054.001 covers stored-data manipulation — addresses DE-0003.07's biasing of mode indicators and status words so ground displays show expected settings while the link operates under attacker-chosen parameters.

  • T2054.001 covers stored-data manipulation — addresses DE-0003.11's modification of WDT parameters (timeout durations, windowed-WDT bounds, reset actions) to shape what evidence survives.

  • T2054.001 covers stored-data corruption — addresses DE-0003.12's poisoning of training corpora used by onboard anomaly-detection ML models (data-poisoning is data alteration). SPACE-SHIELD has no AI/ML-specific evasion technique.

  • EX-0010.01RansomwareST0004
    addresses
    moderate

    T2054.001 'Stored Data Manipulation' covers altering/corrupting stored data such as mission control databases and payload data storage — addresses ransomware's encryption-as-corruption of mass-memory file stores, configuration tables, and event logs in EX-0010.01.

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate

    T2054.001 covers stored-data corruption — addresses wiper malware's destructive overwrites of mass-memory volumes, executable images, checksums, and undo logs in EX-0010.02.

  • EX-0012.01RegistersST0004
    addresses
    moderate

    T2054.001 covers stored-data manipulation — addresses the persistent-register subset of EX-0012.01 (configuration registers held in non-volatile storage).

  • EX-0012.02Internal Routing TablesST0004
    addresses
    moderate

    T2054.001 'Stored Data Manipulation' covers altering stored configuration data — addresses EX-0012.02's rewriting of internal routing tables, message-ID-to-subscriber maps, and bridge address translations.

  • EX-0012.03Memory Write/LoadsST0004
    addresses
    moderate

    T2054.001 covers stored-data alteration — addresses EX-0012.03's use of legitimate memory write/load services to place chosen bytes at chosen addresses in RAM and non-volatile stores.

  • EX-0012.04App/Subscriber TablesST0004
    addresses
    moderate

    T2054.001 covers altering stored configuration tables — addresses EX-0012.04's editing of pub/sub application/subscriber tables and 1553 RT/subaddress configurations.

  • T2054.001 'Stored Data Manipulation' explicitly names 'payload data storage' as a target — direct match to EX-0012.06's alteration of raw detector frames, Level-0 streams, file catalogs, and ancillary metadata.

  • EX-0012.07Propulsion SubsystemST0004
    addresses
    moderate

    T2054.001 covers altering stored configuration — addresses EX-0012.07's modification of thruster calibration, valve timing, delta-V tables, and pressure thresholds.

  • T2054.001 covers stored-data alteration — addresses EX-0012.08's editing of star-tracker masks, sensor alignments, gyro bias terms, controller gains, and estimator covariances.

  • T2054.001 covers stored-data alteration — addresses EX-0012.09's editing of bus voltage/current limits, MPPT setpoints, battery thresholds, and load-shed priorities.

  • T2054.001 covers stored-data alteration — addresses EX-0012.10's editing of opcode-to-handler maps, queue depths, message ID routing, and pub/sub bindings in C&DH.

  • EX-0012.11Watchdog Timer (WDT)ST0004
    addresses
    moderate

    T2054.001 covers stored-data alteration — addresses EX-0012.11's modification of WDT timeout durations, windowed-WDT bounds, reset actions, and supervisor parameters.

  • T2054.001 covers stored-data corruption — addresses EX-0012.13's poisoning of training corpora, fine-tuning sets, calibration products, and ground-truth datasets used by onboard ML models. SPACE-SHIELD has no AI/ML-specific technique.

Cite as SafeMode Space, space-shield T2054.001.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.