All techniques
EXF-0003.02
ST0008Exfiltration
sub-technique

Downlink Exfiltration

Parent: EXF-0003

Description

The attacker records spacecraft-to-ground traffic, real-time telemetry, recorder playbacks, payload products, and mirrored command sessions, to obtain mission data and health/state information. With sufficient signal quality and protocol knowledge, frames and packets are demodulated and extracted for offline use; where protection exists only on uplink or is inconsistently applied, downlink content may still be in clear. Downlinked command echoes, event logs, and file catalogs can expose internal activities and aid follow-on targeting while the primary objective remains data capture at scale.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    inferred

    Art. (2)(d) is access-control relevant (authenticated frame structure limits reuse/replay of captured material) but does not interdict the eavesdropping vector itself; the operative control against interception of downlink content is confidentiality/encryption (2)(e).

  • craAnnex I, Part I, (2)(e)
    addresses
    high
    direct

    Downlink interception captures real-time telemetry, recorder playbacks, and payload products; (2)(e)'s state-of-the-art encryption-in-transit obligation directly addresses confidentiality of downlinked content, including the case where uplink is protected but downlink is not.

  • eu-space-actArt. 80(3)
    addresses
    moderate
    inferred

    Art. 80(3)'s information categorization is domain-relevant to downlink exfiltration (it drives crypto policy), but categorization itself does not interdict the exfiltration.

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    Downlink interception captures real-time telemetry, recorder playbacks, and payload products; 85(1)'s cryptographic concept must cover downlink confidentiality where operator risk assessment requires it.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Downlink exfiltration (primary: Art. 85(1)) is mitigated by 85(2)'s key rotation — limiting how much intercepted downlink content remains decryptable per key.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Art. 21(2)(h) obliges cryptography and encryption policies covering the downlink; it addresses downlink exfiltration by requiring those measures, while the deployed downlink confidentiality, not the policy article, is what reduces an interception campaign to traffic-analysis surface only.

  • nis2-implAnnex 12.1.1
    addresses
    moderate
    derived

    Real-time telemetry, recorder playbacks and payload products are mission-critical information assets; the asset-classification obligation drives the encryption and link-protection decisions that determine whether downlink intercept yields decodable content.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations cover protection of downlink traffic on space-link and ground-side networks; link-layer encryption, integrity verification and signal-protection measures are the network-security measures that resist offline reconstruction of recorded downlinks.

ENISA controls

  • Communications security maintains downlink confidentiality during preparation for transmission and reception, defeating the recording-and-decode workflow EXF-0003.02 relies on.

  • Cryptography and key management mandates uplink/downlink encryption to prevent eavesdropping; unprotected downlink content is the precise EXF-0003.02 target.

  • Data encryption per availability/integrity/confidentiality requirements covers payload products, telemetry, and recorder playbacks captured by downlink interception.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EXF-0003.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.