All techniques
DE-0003.11
ST0006Defense Evasion
sub-technique

Watchdog Timer (WDT) for Evasion

Parent: DE-0003

Description

By modifying watchdog parameters or who “pets” them, an adversary shapes what evidence survives. Extending or disabling timeouts allows long-running processes to operate without forced resets that would expose abnormal CPU or power usage; conversely, shortening windows or relocating the petting source to a low-level ISR can induce frequent resets that wipe volatile traces, break correlation in logs, and explain anomalies as “spurious reboots.” In both directions, the watchdog becomes a timing tool for hiding activity rather than a guardrail against it.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Modifying watchdog parameters or relocating the petting source is unauthorized modification of configuration within (2)(f)'s scope.

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    direct

    WDT-induced resets that wipe volatile traces and break log correlation defeat the monitoring obligation (2)(l) places on the product.

  • eu-space-actArt. 81(3)
    addresses
    moderate
    direct

    WDT registers and supervisor commands are critical-function controls; 81(3)(b) restricts which entities can edit them.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    direct

    Watchdog parameter manipulation rewrites network-and-information-system supervision configuration — 84(2)'s Annex VII point 5.1 integrity scope.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Disabled or redirected watchdog supervision, suspiciously long task runs, or rhythmic resets aligned with operational events are detectable patterns Art. 21(2)(b)'s incident-handling capability must surface.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Watchdog parameters (timeout durations, windowed bounds, prescalers, reset-action ladders, petting-source registers) are access-controlled assets; Art. 21(2)(i)'s access-control + asset-management obligation governs which paths can edit them.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring-and-logging procedures should capture WDT-configuration changes, reset-policy modifications and unusual reset cadences that signal evidence shaping.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    WDT parameter modification (timeouts, pet-task assignment) is change-managed configuration; documented procedures govern such modifications because their evidence-shaping effects are significant.

ENISA controls

  • Configuration management of watchdog-timer parameters establishes the baseline whose modification DE-0003.11 attempts to mask process activity.

  • Integrity checking on watchdog configuration values detects unauthorised tampering used to extend or disable timeouts.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0003.11 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.