All techniques
IA-0007.02
ST0003Initial Access
sub-technique

Malicious Commanding via Valid GS

Parent: IA-0007

Description

Adversaries may use a compromised, mission-owned ground system to transmit legitimate-looking commands to the target spacecraft. Because the ground equipment is already configured for the mission, correct waveforms, framing, dictionaries, and scheduling, the attacker’s traffic blends with routine operations. Initial access unfolds by inserting commands or procedures into existing timelines, modifying rate/size limits or command queues, or invoking maintenance dictionaries and rapid-response workflows that accept broader command sets. Pre-positioned scripts can chain actions across multiple passes and stations, while telemetry routing provides immediate feedback to refine follow-on steps. Exfiltration can be embedded in standard downlink channels or forwarded through gateways as ordinary mission data. The distinguishing feature is that command origin appears valid, transmitted from approved apertures using expected parameters, so the first execution event is not a protocol anomaly but a misuse of legitimate command authority obtained through the compromised ground system.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Manufacturer authentication obligations require strong, factor-based identity verification on commanding consoles; valid-GS misuse (using already-configured ground equipment) is bounded when the product enforces independent multi-factor authentication on commanding actions.

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    derived

    Logging/monitoring obligation requires products to record commanding activity, surfacing anomalous command sequences from otherwise-legitimate operator workstations.

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    Issuing valid-looking commands from a compromised mission ground system is exactly what 81(1)'s IAM protocols defend — operator credentials and procedures must be restricted to legitimate users.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    81(4)'s issuance/management/revocation/audit lifecycle on credentials limits how long compromised operator accounts retain access — the audit clause supports detection of malicious commanding.

  • eu-space-actArt. 81(5)
    addresses
    moderate
    direct

    Malicious commanding via valid GS (primary: Art. 81(1) + Art. 81(4)) is mitigated by 81(5)'s auto-revocation — limiting how long compromised operator credentials retain access.

  • eu-space-actArt. 83(1)
    addresses
    high
    direct

    When commanding rides legitimate ground equipment, continuous detection under 83(1) is the discipline that surfaces anomalous timeline insertions or queue manipulations.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Inserted procedures into existing timelines, modified rate/size limits, and queued commands transmitted from approved apertures — even when each frame is technically valid — are the misuse-of-legitimate-authority pattern Art. 21(2)(b)'s incident-handling capability must detect via behavioural baselines.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Command queues, procedure libraries, dictionaries, and rapid-response/maintenance workflows are access-controlled assets; Art. 21(2)(i) is the obligation that constrains who can edit them and how their use is audited.

  • nis2Art. 21(2)(j)
    addresses
    moderate
    direct

    Continuous authentication or step-up MFA on operator sessions under Art. 21(2)(j) raises the bar against an attacker reusing a legitimate ground-segment session to insert procedures across multiple passes.

  • nis2Art. 23(1)
    triggers obligation
    moderate
    direct

    Confirmed misuse of legitimate command authority to alter spacecraft state from approved apertures is a significant incident with severe operational disruption potential; Art. 23(1) reporting applies.

  • nis2Art. 23(2)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) treats malicious commanding via a valid GS as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats this technique as significant. Art. 23(3) significance is met because malicious commanding produces operational disruption directly on the spacecraft; cross-border impact attaches when the spacecraft serves multi-Member-State users.

  • nis2Art. 23(4)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Malicious-commanding events are often visible in command-history audits; awareness can lag the action by minutes to days.

  • nis2-implAnnex 11.3.1
    addresses
    high
    derived

    Operator commanding accounts are privileged accounts; the privileged-account policy specifies strong identification, separated administration and review obligations that constrain how a compromised mission-owned GS can issue mission-affecting commands.

  • nis2-implAnnex 11.7.1
    addresses
    high
    derived

    Multi-factor authentication on commanding consoles is the procedural lever that prevents valid GS infrastructure (already configured for the mission) from being driven by a compromised credential alone.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface anomalous command sequences on otherwise legitimate operator workstations; this is the detective control for valid-GS-misuse.

  • nis2-implAnnex 3.3.1
    addresses
    moderate
    derived

    Malicious commanding via valid GS produces command-history anomalies operators are positioned to spot; Annex 3.3.1 mechanism captures those reports and feeds the Annex 3.2.1 monitoring pipeline this technique's primary mapping invokes.

ENISA controls

  • Four-eyes principle and separation of duties make insertion of malicious commands into existing timelines visible to a second operator.

  • Cryptographic bidirectional authentication on every command session forces commands from a compromised operator account to still pass per-session crypto, plus four-eyes-equivalent checks.

  • On-board cyber-actor-actions detection function is the named control that surfaces malicious commanding from a compromised but legitimate ground system.

  • Critical-telemetry-points monitoring for valid/processed and rejected commands surfaces unusual commanding patterns even when origin appears valid.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0007.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.