All techniques
EX-0012.11
ST0004Execution
sub-technique

Watchdog Timer (WDT)

Parent: EX-0012

Description

Watchdogs supervise liveness by requiring software to “pet” within defined windows or the system resets. Threat actors manipulate WDT behavior by changing timeout durations, windowed-WDT bounds, reset actions, enable/mask bits, or the source that performs the petting (e.g., moving it into a low-level ISR so higher layers can be stalled indefinitely). Software WDTs can be disabled or starved; hardware WDTs are influenced via control registers, strap pins, or supervisor commands that alter prescalers and reset ladders. Outcomes include preventing intended resets so runaway tasks consume power and bandwidth, or forcing repeated resets at tactically chosen moments, e.g., during updates or handovers, to keep the system in a degraded or easily predictable state. The technique converts a safety mechanism into a tool for either unbounded execution or rhythmic disruption, depending on how the WDT parameters are rewritten.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection on watchdog-timer configuration ensures liveness-supervision logic cannot be silently bypassed.

  • craAnnex I, Part I, (2)(h)
    addresses
    moderate
    derived

    Availability obligation extends to watchdog mechanisms whose disabling allows hung software to persist undetected.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Watchdog Timer configuration (timeout durations, reset actions, enable bits) is mission-system integrity covered by 84(2)'s Annex VII point 5.1 requirements.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Runaway tasks, repeated resets at tactically chosen moments, and disabled watchdogs are detectable patterns; Art. 21(2)(b)'s incident-handling capability must surface those WDT-state anomalies.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Watchdog control registers, prescaler settings, and reset-ladder configuration are access-controlled assets; Art. 21(2)(i)'s access-control + asset-management obligation governs which paths can disable, mask, or alter the WDT supervision regime.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must capture WDT-configuration changes and reset-policy modifications, which are subtle observable signatures of liveness-supervision tampering.

  • nis2-implAnnex 6.4.1
    addresses
    high
    derived

    Watchdog-timer parameters (timeouts, reset actions, windowed bounds) are change-managed configuration; alterations must follow documented procedures because their mission-safety impact is significant.

ENISA controls

  • Watchdog-timer values are configuration items whose baseline must be documented and monitored under configuration management.

  • Integrity-checking surfaces unauthorised modifications to watchdog timer values that EX-0012.11 issues.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0012.11 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.