All techniques
EX-0012.01
ST0004Execution
sub-technique

Registers

Parent: EX-0012

Description

Threat actors may target the internal registers of the victim spacecraft in order to modify specific values as the FSW is functioning or prevent certain subsystems from working. Most aspects of the spacecraft rely on internal registers to store important data and temporary values. By modifying these registers at certain points in time, threat actors can disrupt the workflow of the subsystems or onboard payload, causing them to malfunction or behave in an undesired manner.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Authentication-and-access-control obligations apply to register-level interfaces; manufacturers must constrain which actors can issue memory-mapped register writes.

  • craAnnex I, Part I, (2)(j)
    addresses
    moderate
    derived

    Limited attack surfaces apply to register-level/maintenance interfaces; manufacturers must lock or destroy them post-deployment.

  • eu-space-actArt. 81(3)
    addresses
    high
    direct

    Internal-register writes during FSW operation are critical-function actions — 81(3)(b) restricts the population that can issue register-modification commands.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Internal-register write commands are access-controlled functions; Art. 21(2)(i)'s access-control + asset-management obligation governs which sessions and roles can issue them.

  • nis2-implAnnex 11.4.1
    addresses
    moderate
    direct

    Internal-register manipulation acts directly on hardware via administrative interfaces; the administration-systems obligation requires the entity to restrict and control the use of system-administration tools that produce such effects.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    Register-level changes are change-management events; the implementing regulation requires controlled modification through documented procedures with review and authorization.

ENISA controls

  • Configuration-management baselines for security configurations cover device and control registers — the values EX-0012.01 modifies.

  • Integrity checking validates the integrity of baselined mission software, programmable logic, and firmware, which is relevant to the integrity domain EX-0012.01 attacks, but internal registers hold live runtime values outside the signed baseline, so the excerpt does not show active detection of runtime register modification.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0012.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.