All techniques
EXF-0006.01
ST0008Exfiltration
sub-technique

Software Defined Radio

Parent: EXF-0006

Description

Programmable SDRs let an attacker introduce new waveforms or piggyback payloads into existing ones. By modifying DSP chains (filters, mixers, FEC, framing), the actor can: add a low-rate subcarrier under the main modulation, alter preamble/pilot sequences to encode bits, vary puncturing/interleaver patterns as a covert channel, or schedule brief “maintenance” bursts that actually carry exfiltrated data. Changes may be packaged as legitimate updates or configuration profiles so the SDR transmits toward attacker-visible geometry using standard equipment, while mission tooling interprets the emission as routine.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(c)
    addresses
    moderate
    inferred

    Art. (2)(c) is patching-domain relevant (the SDR's update path is the delivery vector abused) but does not interdict the covert-channel injection itself; the control that authenticates and rejects fraudulent waveform/DSP profiles is integrity protection (2)(f) and secure update distribution (Part II 7).

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    direct

    SDR profile/configuration changes should require authenticated commands; (2)(d)'s authentication obligation applies to all privileged configuration interfaces.

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Modifying SDR DSP chains (filters, mixers, FEC, framing) is unauthorized modification of programs and configuration; (2)(f)'s integrity-of-programs scope and corruption-reporting requirement directly address this.

  • craAnnex I, Part II, (8)
    addresses
    moderate
    direct

    SDR-modification exfiltration (primary mapping: Part I, (2)(c) security updates) cascades to (8) — when the attack rides 'legitimate updates', the manufacturer's update channel must include the timely-dissemination discipline that legitimate fixes require.

  • eu-space-actArt. 81(3)
    addresses
    moderate
    direct

    SDR profile/configuration changes are critical-function actions; 81(3)(b)'s access restriction governs which entities can write to SDR control planes.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    direct

    SDR DSP chain modifications (filters, mixers, FEC, framing) attack network-and-information-system program/config integrity — 84(2)'s Annex VII point 5.1 scope.

  • eu-space-actArt. 92(1)
    addresses
    moderate
    direct

    Malicious DSP changes packaged as legitimate updates ride supplier toolchains; 92(1)'s contractual information-security obligation governs SDR vendor relationships and update governance.

  • nis2Art. 21(2)(e)
    addresses
    moderate
    direct

    SDR DSP-chain modifications shipped as legitimate update profiles are a maintenance-pipeline attack; secure acquisition/development/maintenance and vulnerability handling under Art. 21(2)(e) cover the channel through which the change reaches the radio.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Art. 21(2)(h) crypto policy does not interdict SDR covert subcarrier, pilot or puncturing channels; the operative control is emission monitoring and signal-configuration control. Addresses (domain relevance).

  • nis2-implAnnex 5.1.1
    addresses
    moderate
    derived

    SDR vendors and waveform suppliers are direct suppliers under the supply-chain policy; the policy frames the integrity expectations on vendor-supplied DSP chains and configuration profiles that, if subverted, deliver covert downlinks.

  • nis2-implAnnex 6.2.1
    addresses
    moderate
    derived

    SDR DSP chains, framing logic and waveform configuration are produced inside the secure-development life cycle; rules for that lifecycle govern integrity protection on bitstreams and waveform packages so attacker-introduced subcarriers and covert framing are blocked at source.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    SDR firmware and waveform-profile changes are change-management events; documented procedures govern release, modification and emergency edits to these reconfigurable radios.

ENISA controls

  • Configuration management of SDR profiles (DSP chains, filters, mixers, FEC, framing) surfaces unauthorised modifications introducing covert subcarriers or modified preambles.

  • Change Management governs the configuration change-control process for SDR profiles and waveforms that EXF-0006.01 disguises as legitimate updates, establishing process control rather than actively detecting the covert modification.

  • Regularly performed, regression-tested software updates govern the SDR software baseline and are relevant to its integrity, but regression testing validates function rather than detecting the covert DSP-chain or FEC modifications EXF-0006.01 uses.

  • Integrity checking on programmable logic devices including SDR bitstreams and DSP modules detects covert-channel injections that EXF-0006.01 packages as legitimate updates.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EXF-0006.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.