All techniques
EXF-0001
ST0008Exfiltration

Replay

Description

The adversary re-sends previously valid commands or procedures to cause the spacecraft to transmit data again, then captures the resulting downlink. Typical targets are recorder playbacks, payload product dumps, housekeeping snapshots, or file directory listings. By aligning replays with geometry (e.g., when the satellite is in view of actor-controlled apertures) and with acceptance conditions (counters, timetags, mode), the attacker induces legitimate transmissions that appear routine to operators. Variants include selectively replaying index ranges to fetch only high-value intervals, reissuing subscription/telemetry-rate changes to increase data volume, or queueing playbacks that fire during later passes when interception is feasible.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    direct

    Replay-resistant authentication (counter freshness, nonces, timestamp windows) is the precise authentication property (2)(d) requires the product's access-management mechanisms to provide.

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Counters, timetags, and acceptance conditions ARE the integrity controls (2)(f) requires; replay defeats them when the protections are absent or weak.

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    85(1)'s cryptographic concept must include anti-replay handling (counters, timetags, freshness windows) — the core protection against replay.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Replay exfiltration (primary: Art. 85(1)/(3)) cascades to 85(2) — counter discipline within key lifecycle limits the operational window for replay.

  • eu-space-actArt. 85(3)
    addresses
    high
    direct

    85(3)(a)/(b)'s end-to-end authentication and telecommand encryption — paired with anti-replay counters that 85(3) presumes — are the cryptographic discipline that defeats replay.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Repeated playback patterns, off-cadence recorder dumps, and subscription/rate-change reissues that align with non-mission ground geometry are detectable behavioural anomalies; Art. 21(2)(b)'s incident-handling capability must surface them.

  • nis2Art. 21(2)(h)
    addresses
    high
    direct

    Art. 21(2)(h) requires cryptography policies and procedures covering anti-replay; it addresses replay-to-exfiltrate by mandating those measures, while the deployed anti-replay state and MAC-bound counters, not the policy obligation, are what prevent re-sent commands from inducing a repeat downlink of previously dumped data.

  • nis2-implAnnex 11.6.1
    addresses
    moderate
    inferred

    Authentication based on access control is domain relevant but does not interdict replay; anti-replay freshness (monotonic counters, nonces, timestamp validation) is the control that rejects re-sent valid commands.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface duplicate or unauthorized-source command sequences that solicit recorder playbacks or bulk dumps, which is the observable signature of replay-driven exfiltration.

ENISA controls

  • Cryptography and key management governs the cryptographic foundation relevant to replay defense, but the generic rules excerpt does not itself provide the active anti-replay mechanism.

  • Bidirectional cryptographic command authentication forces replayed commands to fail validation regardless of how authentic the framing appears.

  • Replay-resistant authentication on commands directly defeats re-issuance of previously valid commands to induce repeated downlinks.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EXF-0001 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.