Received Commands
Parent: DE-0003
Description
Spacecraft typically maintain histories of accepted, rejected, and executed commands, buffers, logs, or file records that can be downlinked on demand or periodically. An adversary conceals activity by editing or pruning these artifacts: removing entries, altering opcodes or arguments, rewriting timestamps and source identifiers, rolling logs early, or repopulating with benign-looking commands to balance counters. Related acknowledgments and event records may be suppressed or reclassified so cross-checks appear consistent. After manipulation, the official command history shows a plausible narrative that omits or mischaracterizes the adversary’s actions.
Mappings
EU regulation articles
Editing or pruning command-history buffers, logs, and file records is unauthorized modification of stored data (2)(f) covers, including the corruption-reporting requirement that the technique tries to suppress.
Command histories and event logs ARE the (2)(l) recording channel; rewriting opcodes, timestamps, and source IDs is the canonical attack (2)(l) requires the product to resist.
Command histories and event logs ARE the recording channel 83(1)'s continuous-monitoring obligation depends on; tamper-resistance is part of monitoring discipline.
Editing or pruning command-history buffers tampers with stored network-and-information-system records — within 84(2)'s integrity scope per Annex VII point 5.1.
Log-integrity controls and cross-validation between on-board and ground-side command records are part of incident-handling readiness under Art. 21(2)(b); discrepancies should surface even when the on-board narrative looks plausible.
Append-only signed command-history makes pruning and rewriting detectable, but it does not prevent onboard log pruning by an adversary with write access, where the operative control is audit-record integrity and protection rather than a cryptography-use policy. Under the strict bar the cryptographic control makes tampering detectable but does not interdict the defining onboard vector, so at NIS2 Art. 21(2)(h) the relationship is addresses.
The obligation to maintain and document logs is the procedural lever that governs how command-history buffers are kept and reviewed; without that discipline, edited or pruned histories go unnoticed.
Regular log review for unusual or unwanted trends is the detective procedure that surfaces command-history tampering patterns.
The implementing regulation requires logs to be maintained, backed up for a predefined period, and protected from unauthorized access and modification — exactly the integrity protection that resists tampering with command-history records.
ENISA controls
Integrity checking covering proper management of information and records detects modification of executed-command histories and file records.
Anomaly detection mandates that audit/log records are documented, implemented, and reviewed in accordance with policies — defending the records DE-0003.08 attempts to edit or prune.
Cross-reference controls
- csf-2-0DE.CM-09Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse eventsaddressesmoderate
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records DE-0003.08 against SI-7 Software, Firmware, and Information Integrity, and CSF 2.0's own crosswalk names that control as an informative reference for DE.CM-09. Through SPARTA: SPARTA's catalog maps DE-0003.08 to countermeasure CM0032 On-board Intrusion Detection & Prevention; CM0034 Monitor Critical Telemetry Points; CM0042 Robust Fault Management, and that countermeasure's own CSF references include DE.CM-09. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15. DE.CM-09 is one of CSF's broader outcomes, so this edge locates the technique within CSF's structure rather than naming a specific defence.
Derived by composition, not from a source that names this pair. D3FEND publishes that Configuration Inventory counters T1562.003 Impair Command History Logging; SafeMode's curated mapping records DE-0003.08 as addressing that same adversary behaviour in the space domain. A configuration baseline covers flight tables, parameter sets, and mode definitions as well as ground system configuration. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Executable Allowlisting counters T1562.003 Impair Command History Logging; SafeMode's curated mapping records DE-0003.08 as addressing that same adversary behaviour in the space domain. Authenticating a file by digital signature before it is opened is the same mechanism as verifying a signed software or table upload before the spacecraft loads it. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1562.003 Impair Command History Logging; SafeMode's curated mapping records DE-0003.08 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Integrity Monitoring counters T1562.003 Impair Command History Logging; SafeMode's curated mapping records DE-0003.08 as addressing that same adversary behaviour in the space domain. Detecting unexpected changes to stored files is the on-board table, parameter, and image integrity check, and is one of the few D3FEND controls that transfers to the spacecraft without reinterpretation. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Restore Configuration counters T1562.003 Impair Command History Logging; SafeMode's curated mapping records DE-0003.08 as addressing that same adversary behaviour in the space domain. Restoring a known-good configuration covers reloading flight tables and parameter sets from a golden copy. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Restore File counters T1562.003 Impair Command History Logging; SafeMode's curated mapping records DE-0003.08 as addressing that same adversary behaviour in the space domain. Restoring a file from a known-good copy covers reloading an on-board table, image, or stored product. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
T1562.003 'Impair Command History Logging' addresses adversary impairment of command-history audit trails (originally enterprise-shell-history); SPARTA DE-0003.08 covers spacecraft received-command history with conceptually equivalent activity. Cross-domain moderate (enterprise shell history ↔ spacecraft command log).
Manipulating received-command history (deleting entries, altering timestamps) is exactly T0872 'Indicator Removal on Host' applied to the spacecraft's command-log audit trail. Tactic and activity align.
Editing or pruning the accepted, rejected, and executed command histories removes the record an investigator would use. An on-board detection function raises the alert at the time of the action rather than depending on the log that the technique edits afterwards.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
AC-3 mitigates DE-0003.08 by enforcing access authorization on command-history records.
AU-12 addresses audit-record generation on accepted/rejected/executed command histories.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SI-7 mitigates DE-0003.08 by detecting unauthorized changes to command-history buffers and logs.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
T1070 'Indicator Removal on Host' is the direct cross-framework counterpart of DE-0003.08 — both describe deleting/modifying artifacts (received-command histories, logs, file records) to remove evidence of attacker activity.
T1070.001 'Clear Log/Command History' explicitly covers deleting onboard logging to hide illegitimate operations — direct match to DE-0003.08's editing/pruning of command-history buffers, logs, and event records.
SPARTA countermeasures
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Cite as SafeMode Space, DE-0003.08 (SPARTA v3.2).