All techniques
EXF-0003.01
ST0008Exfiltration
sub-technique

Uplink Exfiltration

Parent: EXF-0003

Description

Here the target is command traffic from ground to space. By receiving or tapping the uplink path, the adversary collects telecommand frames, ranging/acquisition exchanges, and any file or table uploads. If confidentiality is weak or absent, opcode/argument content, dictionaries, and procedures become directly readable; even when encrypted, session structure, counters, and acceptance timing inform future command-link intrusion or replay. Captured material can reveal maintenance windows, contingency dictionaries, and authentication schemes that enable subsequent exploitation.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    inferred

    Authentication with replay protection (2)(d) addresses EXF-0003.01 by reducing reuse of captured uplink material, but interception of the command path is interdicted by confidentiality/encryption (2)(e); recorded here as addresses.

  • craAnnex I, Part I, (2)(e)
    addresses
    high
    direct

    Uplink interception captures telecommand frames and table uploads; (2)(e)'s state-of-the-art encryption-in-transit obligation directly addresses confidentiality of command-link content.

  • eu-space-actArt. 85(1)
    mitigates
    moderate
    direct

    85(1)'s cryptographic concept governs uplink-side authentication and encryption design — limiting both content disclosure and the value of session-structure leaks.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Uplink interception (primary: Art. 85(1)/(3)) is mitigated by 85(2)'s key lifecycle — counter and key rotation discipline limits replay/clone potential of captured material.

  • eu-space-actArt. 85(3)
    addresses
    high
    direct

    85(3)(b)'s ensure-encryption-of-telecommands obligation is the precise countermeasure against uplink interception — encrypted command traffic limits what intercepted material reveals.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Art. 21(2)(h) requires cryptography and encryption policies covering the uplink; it addresses uplink exfiltration by mandating those measures, while the deployed uplink confidentiality and integrity, not the policy obligation, are what keep telecommand content from an unauthorised receiver.

  • nis2-implAnnex 12.1.1
    addresses
    moderate
    derived

    Uplink content (commands, table uploads, file transfers) is classified information assets; classification level drives the confidentiality controls that resist uplink interception.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations cover the protection of uplink command traffic; link-encryption and integrity protection are the network-security measures that resist uplink-side interception of telecommand frames and file uploads.

ENISA controls

  • Communications security on uplinks (including encryption to prevent eavesdropping of telecommands) directly defeats uplink-exfiltration content recovery.

  • Cryptography and key management on uplink command sessions with anti-replay counters renders intercepted uplink content non-readable and time-stale.

  • Cryptographic bidirectional command authentication governs the uplink and limits reuse of captured authentication exchanges, but authentication does not provide the confidentiality that would counter passive collection of uplink command content, so addresses rather than mitigates.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EXF-0003.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.