All techniques
EXF-0006.02
ST0008Exfiltration
sub-technique

Transponder

Parent: EXF-0006

Description

On bent-pipe or regenerative transponders, configuration controls what is translated, amplified, and routed. An adversary can remap input–output paths, shift translation frequencies, adjust polarization or gain to favor non-mission receivers, or enable auxiliary ports so selected virtual channels or recorder playbacks are forwarded outside the planned ground segment. In regenerative systems, edited routing tables or QoS rules can mirror traffic to an attacker-controlled endpoint. The result is a sanctioned-looking carrier that quietly delivers mission data to unauthorized listeners.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    direct

    Transponder routing/QoS changes should require authenticated commands; (2)(d)'s access-management obligation governs who can edit these tables.

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Remapping transponder I/O paths, shifting translation frequencies, and editing routing tables are unauthorized modifications of authoritative configuration — the integrity-of-configuration scope (2)(f) covers.

  • eu-space-actArt. 81(3)
    addresses
    moderate
    direct

    Transponder configuration is a critical-function setting; 81(3)(b)'s restrict-access clause governs which entities can edit translation/QoS rules.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Transponder I/O remapping and routing-table edits are unauthorized modifications of network-and-information-system configuration — 84(2)'s Annex VII point 5.1 integrity scope.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Transponder routing/translation tables and gain/polarization controls are access-controlled assets; Art. 21(2)(i)'s access-control + asset-management obligation governs which roles can remap input-output paths or enable auxiliary ports that bypass mission distribution.

  • nis2-implAnnex 11.3.1
    addresses
    moderate
    derived

    Authority to remap transponder paths and adjust translation parameters is privileged; the privileged-account policy bounds the population that can issue such mirroring/forwarding configurations.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring procedures should surface transponder configuration changes and anomalous routing-table updates that signal transponder misuse for covert exfiltration.

  • nis2-implAnnex 6.4.1
    addresses
    high
    derived

    Transponder configuration changes (input–output remap, translation-frequency shifts, polarization and gain edits, regenerative routing tables) are change-management events that must follow documented procedures.

ENISA controls

  • Configuration management of transponder input-output paths, translation frequencies, polarization, gain, and routing tables surfaces unauthorised re-routing for covert downlinks.

  • Integrity checking on regenerative-payload routing tables and QoS rules detects edits that mirror traffic to unauthorised endpoints.

  • Boundary monitoring at the spacecraft's external interface flags emissions consistent with auxiliary-port enablement and out-of-plan transponder routing.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EXF-0006.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.