All techniques
DE-0003.01
ST0006Defense Evasion
sub-technique

Vehicle Command Counter (VCC)

Parent: DE-0003

Description

The VCC tracks how many commands the spacecraft has accepted. An adversary masks activity by zeroing, freezing, or selectively decrementing the VCC, or by steering actions through paths that do not increment it (maintenance dictionaries, alternate receivers, hidden handlers). They may also overwrite the telemetry field that reports the VCC so ground displays show a lower or steady count while high volumes of commands are processed. This breaks simple “command volume” heuristics and makes bursty activity look normal.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Zeroing, freezing, or steering the Vehicle Command Counter is unauthorized manipulation of stored counter data and the telemetry field that reports it — the integrity property (2)(f) covers, including the corruption-reporting requirement.

  • craAnnex I, Part I, (2)(l)
    addresses
    high
    direct

    The VCC is a primary recording channel for command-acceptance activity; (2)(l)'s record-and-monitor requirement is precisely defeated when the counter is biased or hidden.

  • eu-space-actArt. 83(1)
    addresses
    high
    direct

    VCC is a primary detection input under 83(1) — monitoring command-acceptance volume is precisely the discipline VCC manipulation defeats.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Vehicle Command Counter is core network-and-information-system state under 84(2)'s Annex VII point 5.1 — manipulation of the counter or the field that reports it is integrity tampering.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    VCC anomalies (zeroed counts, frozen values, divergence between accepted-command behaviour and reported VCC) are detectable through cross-validation; Art. 21(2)(b)'s incident-handling capability must surface those signals from multi-source command auditing.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Signed verified-command-count reports defeat ground-side rewriting of the reported counter, but they do not stop onboard counter and field tampering by an adversary with write access, since cryptography cannot prevent direct register edits at the source. Under the strict bar the cryptographic control covers the reporting path but not the defining onboard vector, so at NIS2 Art. 21(2)(h) the relationship is addresses.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring procedures must capture VCC values, increment cadence and divergences from per-pass expected counts; this is the principal observable signature of VCC tampering.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    VCC value alterations and command-path bypasses are change-management events governed by the implementing regulation's change-control procedures.

ENISA controls

  • Integrity checking validates baselined mission software, programmable logic, and firmware and is relevant to the integrity domain, but the Vehicle Command Counter is a live runtime telemetry value outside the signed baseline, so the excerpt does not show active detection of runtime VCC manipulation.

  • Critical-telemetry-points monitoring of command counters (the literal subject) flags VCC freezing or selective decrement.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0003.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.