Skip to content
safemode.space
All tactics
ST0009

Impact

A SPARTA tactic: the objective an adversary is pursuing. SPARTA files 14 techniques under this one. See every tactic at once on the tactic matrix, or all techniques in the technique index.

Description

The Impact tactic captures adversary activity that directly produces or sustains an effect against the affected system. An impact may affect the spacecraft as a whole. It may instead affect a payload, subsystem, software service, communication path, mission function, or connected asset. Impact does not require permanent physical damage. Effects may be temporary or persistent. They may also be reversible, irreversible, destructive, or non-destructive. A spacecraft may remain powered and responsive while behaving in a way that benefits the adversary. It may mislead defenders, expose protected information, provide access to another system, or lose an essential mission function. Impact is not necessarily the final stage of an attack. Adversaries may revisit the Impact tactic several times during one operation. Impact activity may also create conditions for further reconnaissance, initial access, lateral movement, defense evasion, or other tactics. SPARTA does not imply a clean or linear attack chain. The revised Impact structure replaces broad outcome-based techniques with repeatable technical mechanisms. Terms such as denial, degradation, disruption, deception, and destruction describe possible effects or objectives. They do not explain how the adversary produced the effect. SPARTA characterizes Impact using two related concepts:
  • Impact Techniques describe how the adversary produces the effect. Each Impact technique represents a technical mechanism that can apply across different spacecraft functions and architectures.
  • Impact Vectors describe the conditional objective that the adversary may pursue through that mechanism. They provide context for why technically similar actions may be used for different purposes.
Impact Vectors do not assert that SPARTA knows the adversary’s actual intent. They describe conditional possibilities: if the adversary’s objective is a given vector, how could the selected Impact Technique support it? A single action may involve more than one Impact Technique. A technique may also support more than one Impact Vector. The technique should be selected based on the technical lever the adversary used. The vector should be selected based on the objective. Neither concept is mutually exclusive. Impact Technique pages also link to relevant SPARTA Techniques and Sub-Techniques from other tactics. Those mappings identify the technical behaviors that may enable or realize the mechanism. Users can follow the linked technique pages to their existing Countermeasures and Indicators of Behavior. Impact Vectors Impact Vectors describe why an adversary may produce an effect against a spacecraft or space-system element. The technique page provides one concise Illustrative Application for each applicable vector. These examples demonstrate the relationship between the mechanism and the conditional objective. They are not exhaustive results, canonical outcomes, or formal mappings to a specific spacecraft target. For example:
  • Changing a measured temperature is Data Manipulation. Changing the threshold used to evaluate that temperature is Configuration Manipulation. Changing the programmed response to the threshold crossing is Software, Firmware, or Programmable Logic Manipulation.
  • Issuing a legitimate command to place a spacecraft into safe mode may involve both Native Functionality Abuse and State or Mode Manipulation.
  • A spacecraft may satisfy the Disable vector even when it remains powered and communicative, provided it can no longer conduct its intended mission or an essential mission function.
The following vectors may be associated with each Impact technique:
VectorDefinition
CollectThe objective is to obtain information or knowledge the adversary is not authorized to acquire, whether for reconnaissance, intelligence, technical exploitation, competitive advantage, capability replication, or preparation for future actions.
PivotThe objective is to use a compromised spacecraft or space-system element as an intermediary to access, route activity toward, or conduct operations against another payload, spacecraft, mission system, network segment, trust domain, or connected asset. The compromised element becomes an intermediary in the attack path, and the broader adversary campaign may continue beyond the affected spacecraft or space-system element.
SubvertThe objective is to undermine, distort, degrade, disrupt, deceive, divert, or otherwise compromise intended mission operations, system behavior, outputs, trustworthiness, or defender understanding without necessarily seizing control or eliminating essential mission capability. Subvert includes effects intended to undermine mission performance, output trustworthiness, operational understanding, or defender decision-making.
SeizeThe objective is to obtain sufficient unauthorized control or use of a spacecraft, payload, service, function, or mission capability to direct, repurpose, exploit, ransom, or reserve that capability for adversary purposes. Seize requires adversary-directed control or utility; merely preventing the rightful operator from using the capability is Disable.
DisableThe objective is to prevent the spacecraft from conducting its intended mission or prevent an essential mission function from operating, whether temporarily or permanently and whether through destructive or non-destructive means. Disable applies when the essential function is unavailable, rather than merely degraded, misleading, or operating below expected performance. Disable does not require the adversary to obtain control or utility from the affected capability.

Reproduced verbatim from SPARTA v4.0, including its own citation markers, spelling and formatting. Nothing in the text above is SafeMode Space's wording, and nothing has been corrected.

Techniques

Cite as SafeMode Space, ST0009 (SPARTA v4.0), https://safemode.space/reference/tactics/st0009, accessed YYYY-MM-DD. Replace YYYY-MM-DD with the date you read the page; the corpus is curated continuously, so mappings can change between readings. Sources and licence: sources and attribution. A mapping on this page is interpretive analysis of how a technique and a provision relate, not a statement of law and not compliance guidance. Read the disclaimer.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.