All techniques
EXF-0007
ST0008Exfiltration

Compromised Ground System

Description

The adversary resides in mission ground infrastructure and uses its trusted position to siphon data at scale. With access to operator workstations, mission control servers, baseband/modem chains, telemetry processing pipelines, or archive databases, the attacker can mirror real-time streams, scrape recorder playbacks, export payload products, and harvest procedure logs and command histories. Because exfiltration rides normal paths, file staging areas, data distribution services, cloud relays, or cross-site links, it blends with routine dissemination. Compromise of scheduling tools and pass plans also lets the actor time captures to high-value downlinks and automate bulk extraction without touching the spacecraft.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    direct

    Compromise of operator workstations, mission control servers, and telemetry processing pipelines is the canonical case (2)(d)'s authentication and access-management obligation addresses for ground-segment products with digital elements.

  • craAnnex I, Part I, (2)(e)
    addresses
    high
    direct

    Archive databases, payload product stores, and procedure logs hold mission-critical data at rest; (2)(e)'s 'data at rest' encryption obligation directly applies to these ground-system products.

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    direct

    Bulk extraction blending with routine dissemination is detectable only through (2)(l)'s record-and-monitor obligation on file staging areas, distribution services, and cross-site links.

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    Compromise of operator workstations, mission control servers, scheduling, and HSMs is the canonical case 81(1)'s identity-and-access-management protocols defend against on the ground segment.

  • eu-space-actArt. 81(3)
    addresses
    high
    direct

    81(3)(a) explicitly safeguards access to the ground segment and centres for the control of the space segment — the precise infrastructure EXF-0007 attacks.

  • eu-space-actArt. 81(4)
    addresses
    high
    direct

    Compromised-ground-system exfiltration (primary: Art. 81(1)) cascades to 81(4) — credential audit and revocation discipline limits the scope of compromised credentials harvesting mission data.

  • eu-space-actArt. 83(1)
    addresses
    high
    direct

    Continuous monitoring under 83(1) is the operator's discipline for surfacing bulk-extraction patterns that ride normal data-distribution paths.

  • eu-space-actArt. 84(4)
    addresses
    moderate
    direct

    84(4)'s preventive and protective measures regarding the ground segment (Annex VII point 5.4) are the design discipline that limits ground-system intrusion success rate.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    An adversary residing in mission ground infrastructure and siphoning data at scale is a significant compromise the entity's incident-handling capability under Art. 21(2)(b) must detect via DLP, exfil-volume baselines, and unscheduled-export alerts.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Operator workstations, telemetry processing pipelines, and archive databases are access-controlled assets; Art. 21(2)(i)'s access-control + asset-management obligation governs who reaches them and the boundary between mission-data and exfiltration paths.

  • nis2Art. 21(2)(j)
    mitigates
    moderate
    direct

    Mass-scale exfiltration via mission-control servers, modem chains, and archive databases depends on attacker credentials evading detection on operator/admin accounts; multi-factor or continuous authentication under Art. 21(2)(j) directly closes that gap.

  • nis2Art. 23(1)
    triggers obligation
    high
    direct

    Confirmed mass exfiltration from a compromised ground system has cross-border impact (mission products distributed to multiple stakeholders) and meets the Art. 23(3) significance threshold; Art. 23(1) reporting (24h early warning, 72h notification) applies.

  • nis2Art. 23(2)
    addresses
    high
    derived

    Primary mapping to Art. 23(1) treats compromise of the mission ground system as a significant incident. Art. 23(2) timing (without undue delay after awareness) applies automatically.

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats MOC compromise as significant. Art. 23(3) significance is met by operational-disruption and considerable-damage criteria; cross-border impact applies to multi-mission ground systems whose telemetry and payload data flow across Member States.

  • nis2Art. 23(4)
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives the Art. 23(4) deadlines. MOC compromise typically has delayed detection, so the 24-hour early-warning clock starts at the awareness moment, not at the intrusion moment.

  • nis2-implAnnex 11.7.1
    addresses
    high
    derived

    Multi-factor authentication on operator workstations, archive databases and distribution services is the procedural defense that prevents credential-only foothold from converting into bulk-exfiltration access.

  • nis2-implAnnex 12.2.1
    addresses
    moderate
    derived

    Asset-handling policy governs how mission-data files, telemetry archives and payload products are stored, transported and disseminated, which is the procedural envelope around mass exfiltration via ground-system trusted positions.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface anomalous bulk-export activity, recorder-playback scraping and unusual cross-site link traffic, which are the observable signatures of compromised-ground-system exfiltration.

  • nis2-implAnnex 3.3.1
    addresses
    moderate
    derived

    Compromised-ground-system exfiltration produces operator-visible signals (anomalous workstation behaviour, unexpected exports). Annex 3.3.1 mechanism captures employee escalation that complements automated egress monitoring; the technique's primary mapping to Annex 3.2.1 monitoring depends on those upstream human signals to separate routine from suspicious activity.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations cover the entire ground-segment estate where compromised-ground-system exfiltration occurs (operator workstations, mission-control servers, baseband chains, archive databases); boundary protection, gateway monitoring and traffic-egress controls are the network-security measures that bound mass exfiltration.

ENISA controls

  • Data Loss Prevention solutions safeguarding information assets against unauthorised disclosure are explicitly the named control against bulk data extraction from ground systems.

  • Least-privilege access control on operator workstations, archive databases, and processing pipelines denies the broad reach EXF-0007 needs to siphon data at scale.

  • MFA on mission-control accounts limits the credential-only path to systems EXF-0007 mirrors and scrapes.

  • Intrusion detection and prevention with documented baselines surfaces bulk extraction patterns and abnormal staging activity in ground systems.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EXF-0007 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.