All techniques
EX-0001.01
ST0004Execution
sub-technique

Command Packets

Parent: EX-0001

Description

Threat actors may resend authentic-looking telecommands that were previously accepted by the spacecraft. Captures may include whole command PDUs with framing, CRC/MAC, counters, and timetags intact, or they may be reconstructed from operator tooling and procedure logs. When timing, counters, and mode preconditions align, the replayed packet can cause the same effect: toggling relays, initiating safing or recovery scripts, adjusting tables, commanding momentum dumps, or scheduling delta-v events. Even when outright execution fails, repeated “near-miss” injections can map acceptance windows, rate/size limits, and interlocks by observing the spacecraft’s acknowledgments and state changes. At scale, streams of valid-but-stale commands can congest command queues, delay legitimate activity, or trigger nuisance FDIR responses.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    mitigates
    high
    derived

    Telecommand authentication with monotonic counters and MAC binding makes whole-PDU replay unsuccessful; this is the manufacturer-side defense against captured-and-replayed commands.

  • craAnnex I, Part I, (2)(f)
    addresses
    moderate
    derived

    Integrity protection on commands ensures replayed PDUs (lacking fresh integrity context) are rejected by the receiver.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    85(2)'s key lifecycle policy includes counter management and key rotation — limiting the operational window in which captured commands can be replayed against extant keys.

  • eu-space-actArt. 85(3)
    addresses
    high
    direct

    Replay of authenticated telecommands is defeated by 85(3)(a)'s end-to-end authentication and 85(3)(b)'s telecommand-encryption with anti-replay counters.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Streams of valid-but-stale commands congesting queues or triggering nuisance FDIR are detectable as incidents the entity's incident-handling capability under Art. 21(2)(b) must address.

  • nis2Art. 21(2)(h)
    addresses
    high
    direct

    Art. 21(2)(h) mandates cryptography policies and procedures covering anti-replay; it addresses command-packet replay by requiring those measures, while the deployed anti-replay windows and fresh counters, not the policy obligation, are what defeat re-transmission of captured PDUs whose framing and MAC are intact.

  • nis2-implAnnex 11.6.1
    addresses
    high
    inferred

    Authentication based on access control is domain relevant but does not interdict whole-PDU replay; anti-replay freshness (monotonic counters and timestamp windows enforced at acceptance) is the control that defeats re-sent stale telecommands.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Command-side monitoring must detect duplicate frames and counter regressions, which are the observable signatures of command-packet replay.

ENISA controls

  • Cryptography and key management — anti-replay counters and key rotation — turns previously-captured commands into stale, unaccepted traffic.

  • Cryptographic command authentication with bidirectional auth and counters causes replayed command PDUs to fail validation.

  • Replay-resistant authentication on telecommands directly defeats command-packet replay, the core EX-0001.01 vector.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0001.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.