All techniques
DE-0002.01
ST0006Defense Evasion
sub-technique

Inhibit Ground System Functionality

Parent: DE-0002

Description

Threat actors may utilize access to the ground system to inhibit its ability to accurately process, render, or interpret spacecraft telemetry, effectively leaving ground controllers unaware of the spacecraft’s true state or activity. This may involve traditional denial-based techniques, such as disabling telemetry software, corrupting processing pipelines, or crashing display interfaces. In addition, more subtle deception-based techniques may be used to falsify telemetry data within the ground system , such as modifying command counters, acknowledgments, housekeeping data, or sensor outputs , to provide the appearance of nominal operation. These actions can suppress alerts, mask unauthorized activity, or prevent both automated and manual mitigations from being initiated based on misleading ground-side information. Because telemetry is the primary method by which ground controllers monitor the health, behavior, and safety of the spacecraft, any disruption or falsification of this data directly undermines situational awareness and operational control.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Falsifying telemetry within the ground system (modifying command counters, acknowledgments, housekeeping data) is exactly the unauthorized manipulation of processed data (2)(f) covers, including the corruption-reporting requirement.

  • craAnnex I, Part I, (2)(h)
    addresses
    high
    direct

    Disabling telemetry software, corrupting processing pipelines, or crashing display interfaces directly attacks the availability of the ground product's essential monitoring functions.

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    Inhibiting ground-system functionality requires access to operator workstations, telemetry processing, or display software — IAM under 81(1) defends these surfaces.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    Inhibiting ground-system functionality (primary: Art. 81(1) IAM) cascades to (4)'s issuance/management/revocation/audit obligations — credential audit detects compromise of operator workstations.

  • eu-space-actArt. 83(1)
    addresses
    moderate
    direct

    83(2)'s ground-station detection systems (Annex VII point 4) include cross-checks that surface inhibited-functionality patterns in mission ground.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Falsifying telemetry within ground processing pipelines attacks integrity of network-and-information-system data — 84(2)'s Annex VII point 5.1 compliance covers ground-side processing integrity.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Disabled telemetry software, corrupted processing pipelines, and falsified ground-side displays are paradigmatic incidents the entity's incident-handling capability under Art. 21(2)(b) must detect via integrity-of-monitoring and out-of-band corroboration.

  • nis2Art. 21(2)(e)
    addresses
    moderate
    direct

    Ground-software integrity, secure development of telemetry processors and dashboards, and disclosed-vulnerability handling on those services fall under Art. 21(2)(e)'s network-and-information-systems acquisition/development/maintenance obligation.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Ground processing pipelines, telemetry display interfaces, and alert-routing services are the precise asset class Art. 21(2)(i)'s access-control + asset-management obligation governs.

  • nis2-implAnnex 11.7.1
    addresses
    moderate
    derived

    Multi-factor authentication on telemetry-processing servers and operator displays prevents credential-only foothold from converting into the configuration changes that suppress ground-system telemetry rendering.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must capture telemetry-processing pipeline anomalies, gaps and unexpected configuration changes that signal ground-system inhibition.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Inhibiting ground-system functionality acts on the entity's ground-segment networks and processing chain; network-security obligations cover the protections (boundary control, gateway monitoring, integrity verification of telemetry processing) that resist this attack.

  • nis2-implAnnex 6.9.1
    addresses
    moderate
    derived

    Where ground-system inhibition rides through malicious software (telemetry-display tampering, processing-pipeline subversion), the malware-protection obligation applies as the detective and preventive layer.

ENISA controls

  • Least-privilege access control and four-eyes principle on telemetry pipelines and display interfaces denies the foothold needed to disable or falsify telemetry processing.

  • Incident response procedures including SIEM-driven alerting cover detection of compromised telemetry processing.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0002.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.