Payload Communication Channel
Description
Many payloads maintain communications separate from the primary TT&C, direct downlinks to user terminals, customer networks, or experimenter VPNs. An adversary who implants code in the payload (or controls its gateway) can route host-bus data into these channels, embed content within payload products (e.g., steganographic fields in imagery/telemetry), or schedule covert file transfers alongside legitimate deliveries. Because these paths are expected to carry high-rate mission data and may bypass TT&C monitoring, they provide a discreet conduit to exfiltrate payload or broader spacecraft information without altering the primary command link’s profile.
Mappings
EU regulation articles
(2)(e) confidentiality is the data-protection domain but encryption-at-rest does not interdict an implant that reads plaintext host-bus data and forwards it; recording/monitoring (2)(l) and attack-surface limitation on auxiliary channels (2)(j) interdict the covert conduit, so (2)(e) addresses confidentiality posture.
Steganographic embedding of host-bus data into payload products manipulates transmitted data that the user did not authorize for that channel — within (2)(f)'s integrity scope.
Payload comms separate from primary TT&C is exactly the kind of additional external interface (2)(j) requires the product designer to constrain — particularly when bus data can be routed into channels that bypass TT&C monitoring.
Routing host-bus data into payload comms channels manipulates network-and-information-system data flow — 84(2)'s Annex VII point 5.1 integrity scope covers payload-bus segregation.
84(3)'s only-authorized-devices rule governs which subsystems can write to payload comms channels — preventing host-bus data from being injected into payload-customer downlinks.
Payload comms in hosted-payload contexts traverse third-party-customer paths; 91(3)'s pre-defined-agreements-with-third-party-entities clause governs how the operator constrains payload-channel use.
Payload comms channels often run through customer/experimenter networks under separate operational control; supplier-relationship security under Art. 21(2)(d) covers the boundary the technique exploits to route host-bus data into payload-side downlinks.
Art. 21(2)(h) crypto policy does not interdict exfiltration routed out through payload communication channels by an onboard implant; the operative control is channel segregation and egress monitoring. Addresses (domain relevance).
Primary mapping to Art. 21(2)(d) covers the payload-vendor relationship that supplies the implanted code or controls the gateway. Art. 21(3) extends to scrutiny of that vendor's secure-development practices and vulnerability handling, the procedural mechanism for catching covert exfil paths planted upstream of integration.
Access-rights provisioning across the host–payload boundary is the operational lever that bounds whether payload code can read bus telemetry or host-bus data for embedding in payload products.
Payload vendors, gateway operators and customer-network providers are direct suppliers under the supply-chain policy; the policy frames the integrity expectations imposed on the payload-communications channel and its endpoints.
Payload vendors and gateway operators handle ongoing communications channels; Annex 5.1.6 monitoring detects supplier-side incidents that could open covert payload-channel exfiltration.
Annex 5.1.7 follow-up procedures convert payload-vendor monitoring signals into channel-isolation and gateway-restriction actions.
Network segmentation between hosted payload and host-bus subsystems is the architectural control that prevents host-bus data from being routed into payload-side communications channels for covert exfiltration.
ENISA controls
Third-party risk management governs the payload-operator and customer-network agreements through which EXF-0010 routes host-bus content.
Least-privilege access control between payload commanding and host-bus data denies the implant the privileges needed to route host content into payload links.
Boundary monitoring on the bus/payload interface surfaces unauthorised content routed from host bus into payload communication channels.
Cross-reference controls
- csf-2-0DE.CM-01Networks and network services are monitored to find potentially adverse eventsaddressesmoderate
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records EXF-0010 against SI-4 System Monitoring, and CSF 2.0's own crosswalk names that control as an informative reference for DE.CM-01. Through SPARTA: SPARTA's catalog maps EXF-0010 to countermeasure CM0036 Session Termination, and that countermeasure's own CSF references include DE.CM-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.
- csf-2-0DE.CM-09Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse eventsaddressesmoderate
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records EXF-0010 against SI-4 System Monitoring, and CSF 2.0's own crosswalk names that control as an informative reference for DE.CM-09. Through SPARTA: SPARTA's catalog maps EXF-0010 to countermeasure CM0036 Session Termination, and that countermeasure's own CSF references include DE.CM-09. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15. DE.CM-09 is one of CSF's broader outcomes, so this edge locates the technique within CSF's structure rather than naming a specific defence.
- csf-2-0PR.DS-01The confidentiality, integrity, and availability of data-at-rest are protectedaddressesmoderate
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records EXF-0010 against SI-4 System Monitoring, and CSF 2.0's own crosswalk names that control as an informative reference for PR.DS-01. Through SPARTA: SPARTA's catalog maps EXF-0010 to countermeasure CM0002 COMSEC; CM0030 Crypto Key Management, and that countermeasure's own CSF references include PR.DS-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.
- csf-2-0PR.DS-02The confidentiality, integrity, and availability of data-in-transit are protectedaddressesmoderate
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records EXF-0010 against SI-4 System Monitoring, and CSF 2.0's own crosswalk names that control as an informative reference for PR.DS-02. Through SPARTA: SPARTA's catalog maps EXF-0010 to countermeasure CM0002 COMSEC; CM0029 TRANSEC; CM0030 Crypto Key Management, and that countermeasure's own CSF references include PR.DS-02. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.
- csf-2-0PR.DS-10The confidentiality, integrity, and availability of data-in-use are protectedaddressesmoderate
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records EXF-0010 against SI-4 System Monitoring, and CSF 2.0's own crosswalk names that control as an informative reference for PR.DS-10. Through SPARTA: SPARTA's catalog maps EXF-0010 to countermeasure CM0039 Least Privilege, and that countermeasure's own CSF references include PR.DS-10. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15. PR.DS-10 is one of CSF's broader outcomes, so this edge locates the technique within CSF's structure rather than naming a specific defence.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1011 Exfiltration Over Other Network Medium; SafeMode's curated mapping records EXF-0010 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Payload communication channels (direct-to-user terminals, customer VPN-tunneled feeds, experimenter relay paths) are non-primary network media distinct from the TT&C channel — SPARTA EXF-0010 covers using these for exfil, exact match for T1011 'Exfiltration Over Other Network Medium'. Tactic-aligned.
A payload communication channel that routes host-bus data to customer networks is exactly the undocumented flow the diagram obligation exists to make visible.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, csf-2-0, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, csf-2-0, nist-ir-8441, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, csf-2-0, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
- nist-80053-rev5AC-17(2)Protection of Confidentiality and Integrity Using Encryptionrelates tomoderate
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, csf-2-0, nist-ir-8441, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SA-9 addresses external-services contracts with hosted-payload customers that determine payload-channel governance.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, csf-2-0, nist-ir-8441, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, csf-2-0, nist-ir-8441, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, csf-2-0, nist-ir-8441, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, csf-2-0, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, csf-2-0, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, csf-2-0, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, csf-2-0
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8323r1, csf-2-0, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8323r1, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
- nist-80053-rev5SI-19(4)Removal, Masking, Encryption, Hashing, or Replacement of Direct Identifiersrelates tomoderate
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SI-4 mitigates EXF-0010 by surfacing anomalies on payload-channel traffic indicating exfil use.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
T2021 'Exfiltration Over Payload Channel' is the direct cross-framework counterpart of EXF-0010 — both describe malicious software sending data through the payload communications channel as a discreet conduit bypassing TT&C monitoring.
SPARTA countermeasures
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Cite as SafeMode Space, EXF-0010 (SPARTA v3.2).