All techniques
DE-0002
ST0006Defense Evasion

Disrupt or Deceive Downlink

Description

Threat actors may target ground-side telemetry reception, processing, or display to disrupt the operator’s visibility into spacecraft health and activity. This may involve denial-based attacks that prevent the spacecraft from transmitting telemetry to the ground (e.g., disabling telemetry links or crashing telemetry software), or more subtle deception-based attacks that manipulate telemetry content to conceal unauthorized actions. Since telemetry is the primary method ground controllers rely on to monitor spacecraft status, any disruption or manipulation can delay or prevent detection of malicious activity, suppress automated or manual mitigations, or degrade trust in telemetry-based decision support systems.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Deception-based downlink attacks manipulate transmitted telemetry content — the canonical case (2)(f) integrity-of-transmitted-data covers, including its corruption-reporting requirement.

  • craAnnex I, Part I, (2)(h)
    addresses
    high
    direct

    Denial-based downlink attacks (disabling telemetry links, crashing telemetry software) target the availability of essential monitoring functions, which (2)(h) requires resilience and DoS-mitigation measures for.

  • eu-space-actArt. 83(1)
    addresses
    high
    direct

    Telemetry IS the operator's primary monitoring channel; 83(1)'s continuous-monitoring obligation contemplates protections that detect telemetry disruption or content tampering.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Downlink disruption/deception attacks the integrity and availability of the network-and-information-system telemetry channel — within 84(2)'s Annex VII point 5.1 scope.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Telemetry loss or falsification destroys the primary monitoring surface; Art. 21(2)(b)'s incident-handling capability must surface telemetry gaps and content anomalies via heartbeat baselines and cross-source corroboration.

  • nis2Art. 21(2)(c)
    addresses
    moderate
    direct

    Telemetry continuity — alternate downlink stations, deferred playback recovery, and crisis-management procedures during loss-of-monitoring — falls under business continuity, backup management, and crisis management at Art. 21(2)(c).

  • nis2Art. 21(2)(h)
    addresses
    high
    inferred

    An authenticated telemetry MAC interdicts in-pipeline value substitution on the reporting path, but it does not cover the dominant scope of visibility denial, induced crashes and display tampering, where the operative control is integrity-monitoring and redundancy rather than cryptography. Under the strict bar the cryptographic control covers one vector but not the defining scope, so at NIS2 Art. 21(2)(h) the relationship is addresses.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface telemetry gaps and abnormal display-pipeline behaviour, which are the observable signatures of downlink disruption or deception.

  • nis2-implAnnex 3.3.1
    addresses
    moderate
    derived

    Downlink-disruption is operator-visible (telemetry pipelines empty, displays freeze, alerts queue); Annex 3.3.1 mechanism captures rapid operator reports that complement automated link-margin alerts.

  • nis2-implAnnex 4.1.1
    addresses
    moderate
    derived

    Business-continuity-and-disaster-recovery obligations cover the loss of operator visibility into spacecraft health; recovery plans for telemetry-pipeline outage are part of the entity's continuity discipline.

  • nis2-implAnnex 4.1.4
    addresses
    moderate
    derived

    Primary mapping to Annex 4.1.1 (BCDR plan for downlink-disruption recovery) implies the Annex 4.1.4 test-cadence obligation: continuity plans for telemetry-pipeline outage must be tested at planned intervals.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations cover the ground-side telemetry pipeline (reception, processing, display); the protections that resist downlink disruption ride on those network-security measures.

ENISA controls

  • Event-detection communication ensures detected anomalies are propagated even when telemetry pipelines are partially impaired.

  • Critical-telemetry-points monitoring synchronised with ground-based defensive cyber operations is the named control for surfacing telemetry disruption and deception.

  • System redundancy across ground stations and processing chains preserves operator visibility when one downlink path is disrupted.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0002 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.