All techniques
DE-0011
ST0006Defense Evasion

Credentialed Evasion

Description

Threat actors may leverage valid credentials to conduct unauthorized actions against a spacecraft or related system in a way that conceals their presence and evades detection. By using trusted authentication mechanisms attackers can blend in with legitimate operations and avoid triggering access control alarms or anomaly detection systems. This technique enables evasion by appearing authorized, allowing adversaries to issue commands, access sensitive subsystems, or move laterally within spacecraft or constellation architectures without exploiting software vulnerabilities. When credential use is poorly segmented or monitored, this form of access can be used to maintain stealthy persistence or facilitate other tactics under the guise of legitimate activity.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    direct

    Credentialed evasion is the canonical case (2)(d)'s 'report on possible unauthorised access' clause is meant to surface — appropriate-control-mechanisms must include detection of legitimate-but-anomalous credential use.

  • craAnnex I, Part I, (2)(l)
    addresses
    high
    direct

    Detecting credentialed evasion requires recording and monitoring access to data, services, and functions — the (2)(l) obligation directly.

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    Credentialed evasion is the canonical case 81(1)'s identity-and-access-management protocols defend against — appropriate-control-mechanisms must surface anomalous use of legitimate credentials.

  • eu-space-actArt. 81(4)
    addresses
    high
    direct

    81(4)'s audit clause on access rights surfaces credentialed-evasion patterns — periodic recertification and behavioral audit limit the value of compromised credentials.

  • eu-space-actArt. 81(5)
    addresses
    moderate
    direct

    Credentialed evasion (primary: Art. 81(1) + Art. 81(4)) cascades to 81(5) — auto-revocation discipline ensures stale credentials cannot continue providing evasion cover.

  • eu-space-actArt. 83(1)
    addresses
    moderate
    direct

    83(1)'s continuous monitoring detects anomalous patterns of legitimate-credential use that signal evasion behavior.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    inferred

    DE-0011 leverages valid credentials to act undetected where credential use is poorly segmented or monitored; NIS2 21(2)(i) access control policies and asset management govern this risk.

  • nis2Art. 21(2)(j)
    mitigates
    high
    direct

    Multi-factor authentication or continuous authentication under Art. 21(2)(j) limits the value of valid-but-stolen credentials and forces session-binding signals that distinguish legitimate from credentialed-evasive use.

  • nis2-implAnnex 11.5.1
    addresses
    high
    derived

    Identity life-cycle management bounds the population of valid credentials and ensures stale or compromised identities are revoked promptly, narrowing the surface for credentialed evasion.

  • nis2-implAnnex 11.7.1
    addresses
    high
    derived

    Multi-factor authentication ensures that even valid credentials require an additional factor; passive credential reuse for evasion is broken by MFA enforcement on commanding paths.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface anomalous-but-credentialed activity (off-hours operator actions, geographic anomalies, command-pattern deviations) that signal evasion via valid credentials.

  • nis2-implAnnex 3.3.1
    addresses
    moderate
    derived

    Credentialed-evasion-class behaviour (off-hours activity by valid users, geographic anomalies, command-pattern deviations) is most reliably surfaced by colleagues noticing irregularities; Annex 3.3.1 mechanism is the upstream feeder for the Annex 3.2.1 monitoring this technique's primary mapping invokes.

ENISA controls

  • Authentication-information management governs the credentials whose appropriate handling, rotation, and revocation reduces credentialed-evasion lifetime.

  • Access-rights provisioning, review, and removal limits the scope of any harvested credential used for evasion.

  • MFA defeats the credential-only path that defines credentialed evasion.

  • Anomaly detection with established baselines surfaces credential-use patterns that deviate from documented network operations even when each individual command is authenticated.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0011 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.