All techniques
EX-0005.02
ST0004Execution
sub-technique

Malicious Use of Hardware Commands

Parent: EX-0005

Description

Threat actors may issue low-level device or maintenance commands that act directly on hardware, bypassing much of the high-level command mediation. These may be memory-mapped register writes forwarded over the bus, vendor-specific instrument/control opcodes, built-in-test and calibration modes, boot-mode or fuse-programming sequences, file/sector operations to on-board non-volatile stores, or actuator primitives for wheels, thrusters, motors, heaters, and RF chains. Because these interfaces exist to configure sensors, zero momentum, switch power domains, tune gains, or adjust clocks, they can also be sequenced to produce harmful effects: over-driving mechanisms, altering persistent calibration, disabling watchdogs, or switching timing sources. Some hardware command sets are only exposed in maintenance or contingency modes, while others are always reachable through gateway processors that translate high-level telecommands into device-level operations. By crafting orders that respect expected framing and rate/size limits, the adversary can induce mechanical, electrical, or logical state changes with immediate, high-privilege impact, all while appearing to exercise legitimate device capabilities.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Manufacturer obligation to provide protection from unauthorized access via authentication and access-management applies to low-level/maintenance command interfaces; products must constrain JTAG, scan-chain and memory-mapped-register access.

  • craAnnex I, Part I, (2)(j)
    addresses
    high
    derived

    Limited attack surfaces include hardware test/maintenance modes; manufacturers must design products to disable, lock or destroy these surfaces post-deployment.

  • eu-space-actArt. 81(3)
    addresses
    high
    direct

    81(3)(b)'s restrict-access-to-critical-functions clause directly governs who can issue low-level hardware commands (memory-mapped writes, fuse-programming, actuator primitives) that bypass high-level mediation.

  • eu-space-actArt. 84(3)
    addresses
    moderate
    direct

    84(3)'s only-authorized-devices rule governs which sources can issue raw hardware commands — preventing maintenance/test interfaces from accepting unsanctioned actor traffic.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Hardware-command sequences producing physical or electrical anomalies (over-driven mechanisms, altered calibration, disabled watchdogs) are detectable as incidents the entity's incident-handling capability under Art. 21(2)(b) must surface via subsystem telemetry.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Maintenance/contingency-mode hardware command sets, register-write opcodes, fuse-programming sequences, and built-in-test commands are access-controlled functions; Art. 21(2)(i)'s access-control + asset-management obligation governs which roles/sessions can issue them.

  • nis2-implAnnex 11.3.1
    addresses
    moderate
    derived

    Hardware-level commands (memory-mapped register writes, JTAG/test-mode commands) are privileged-account actions; the privileged-account policy bounds who can issue them and under what review.

  • nis2-implAnnex 11.4.1
    addresses
    moderate
    direct

    Administration-systems control restricts and monitors the use of system-administration tools; low-level hardware commands are exactly the administration class this Annex item governs.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    Change-management procedures govern when and how hardware-level commands are issued in production; out-of-procedure issuance is exactly what an attacker exploits.

ENISA controls

  • Configuration management with least-functionality baseline removes maintenance and contingency-mode hardware commands not required in nominal operations.

  • Backdoor-command analysis explicitly identifies and restricts critical hardware commands that could adversely affect mission success — exactly the EX-0005.02 surface.

  • Least-privilege access control on hardware-command interfaces denies the broad device-level reach EX-0005.02 needs.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0005.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.