All techniques
DE-0003.02
ST0006Defense Evasion
sub-technique

Rejected Command Counter

Parent: DE-0003

Description

This counter records commands that failed checks or were refused. To hide probing and trial-and-error, the adversary suppresses increments, periodically clears the value, or forges the downlinked field so rejection rates appear benign. Variants also tamper with associated reason codes or event entries, replacing them with innocuous outcomes. Analysts reviewing telemetry see no evidence of failed attempts even as the system is being exercised aggressively.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Suppressing, clearing, or forging the Rejected Command Counter — and tampering with associated reason codes — is unauthorized manipulation of stored data (2)(f) addresses with its corruption-reporting requirement.

  • craAnnex I, Part I, (2)(l)
    addresses
    high
    direct

    Rejection counts and reason codes are core security-monitoring telemetry — exactly the recording fields (2)(l) requires for surfacing failed-authentication and probe activity.

  • eu-space-actArt. 83(1)
    addresses
    high
    direct

    Rejection counters and reason codes are core security-monitoring telemetry — 83(1)'s monitoring obligation is what surfaces probe activity that DE-0003.02 conceals.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Rejected Command Counter manipulation tampers with stored network-and-information-system state under 84(2)'s integrity scope.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Suspiciously flat or cleared rejection-counter telemetry alongside otherwise-active command sessions is a detectable cross-validation anomaly Art. 21(2)(b)'s incident-handling capability must surface.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring procedures must capture rejected-command-counter drops, sudden zeroing and disagreement with command-history audit trails as observable signatures of evasion.

  • nis2-implAnnex 6.4.1
    addresses
    high
    derived

    Modifications to the rejected-command counter or its downlink representation are change-management events that must follow documented procedures.

ENISA controls

  • Critical-telemetry-points monitoring explicitly covers rejected-command counters; suppression or forging of this counter is the named target.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0003.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.