All techniques
DE-0002.03
ST0006Defense Evasion
sub-technique

Inhibit Spacecraft Functionality

Parent: DE-0002

Description

In this variant, telemetry is suppressed at the source by manipulating on-board generation or transmission. Methods include disabling or pausing telemetry publishers, altering packet filters and rates, muting event/report channels, reconfiguring recorder playback, retuning/muting transmitters, or switching to modes that emit only minimal beacons. The spacecraft continues operating, but the downlink no longer reflects true activity or arrives too sparsely to support monitoring. By constraining what is produced or transmitted, the adversary reduces opportunities for detection while other actions proceed.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Disabling on-board telemetry publishers and altering packet filters/rates is the unauthorized modification of programs and configuration (2)(f) addresses; the corruption-reporting requirement is directly defeated by the technique.

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    direct

    (2)(l) requires recording and monitoring of internal activity, including modification of services or functions — the telemetry-publisher reconfiguration that (2)(l) is meant to surface as security-related information.

  • eu-space-actArt. 81(3)
    addresses
    moderate
    direct

    81(3)(b)'s restrict-access-to-critical-functions clause limits which entities can disable telemetry publishers or alter packet filters.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    On-board telemetry-publisher manipulation alters network-and-information-system integrity — 84(2)'s Annex VII point 5.1 covers the configuration of these publishers.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    On-board telemetry suppression — paused publishers, throttled rates, retuned transmitters, beacon-only modes — is detectable via heartbeat baselines and ground cross-source corroboration; Art. 21(2)(b)'s incident-handling capability must surface those signals despite the spacecraft 'continuing to operate'.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Telemetry publishers, packet filters, rate controls, event/report channels, and recorder-playback configuration are access-controlled assets; Art. 21(2)(i) governs which roles can disable, mute, or reroute on-board telemetry generation.

  • nis2-implAnnex 11.3.1
    addresses
    high
    derived

    Authority to disable telemetry channels, mute event reports or alter packet filter rates is privileged-account authority; the privileged-account policy bounds the population that can issue such modifications.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface telemetry-source quieting, packet-rate drops and event-channel muting, which are the observable signatures of source-side telemetry suppression.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    On-board telemetry-publisher state, packet filters, rates and channel mute settings are change-managed configuration; documented procedures govern modification of these settings whether commanded or implanted.

ENISA controls

  • Configuration management of telemetry mode, packet filters, and reporting rates surfaces unauthorised modifications that suppress on-board telemetry generation.

  • Event-detection communication ensures suppression of telemetry generation surfaces as a separately tracked event.

  • Critical-telemetry-points monitoring detects suppression at the source by tracking expected telemetry rates against ground reception.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0002.03 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.