All techniques
LM-0001
ST0007Lateral Movement

Hosted Payload

Description

The adversary pivots through the host–payload boundary to reach additional subsystems. Hosted payloads exchange power, time, housekeeping, and data with the bus via defined gateways (e.g., SpaceWire, 1553, Ethernet) and often support file services, table loads, and command dictionaries distinct from the host’s. A foothold on the payload can be used to inject traffic through the gateway processor, request privileged services (time/ephemeris distribution, firmware loads), or ride shared backplanes where payload traffic is bridged into C&DH networks. In some designs, payload processes execute on host compute or expose maintenance modes that temporarily widen access, creating paths from the payload into attitude, power, storage, or recorder resources. The movement is transitive: compromise a co-resident unit, then traverse the trusted interface that already exists for mission operations.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    direct

    Authentication and access-management mechanisms across the gateway processor between host and payload mitigate the privileged-service requests (time/ephemeris distribution, firmware loads) that LM-0001 abuses.

  • craAnnex I, Part I, (2)(j)
    addresses
    high
    direct

    The host–payload boundary IS an external interface and shared-bus interaction surface; (2)(j)'s limit-attack-surfaces obligation places product-design responsibility on segmenting it.

  • eu-space-actArt. 81(3)
    addresses
    moderate
    direct

    81(3)(b)'s restrict-access-to-critical-functions clause covers the host-payload boundary — limiting the population that can reach across the gateway.

  • eu-space-actArt. 84(3)
    addresses
    high
    direct

    Hosted payload command sets traversing the host bus must obey 84(3)'s only-authorized-devices-communicate rule at the gateway processor.

  • eu-space-actArt. 91(3)
    addresses
    moderate
    direct

    91(3) explicitly governs hosted-payload contexts; the pre-defined-agreements-with-third-party-entities clause shapes the access discipline at the host-payload boundary.

  • nis2Art. 21(2)(d)
    addresses
    moderate
    direct

    The host–payload boundary is a direct supplier/service-provider relationship in hosted-payload arrangements; Art. 21(2)(d)'s supplier-relationship security obligation governs the trust framework around the gateway services payload traffic traverses.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Gateway processors, file services, table-load endpoints, time/ephemeris distribution paths, and shared backplanes between payload and bus are precisely the asset class Art. 21(2)(i)'s access-control + asset-management obligation governs.

  • nis2Art. 21(3)
    addresses
    moderate
    direct

    Payload-provider segmentation maturity and key-management discipline vary by supplier; Art. 21(3) requires the entity to take those payload-specific vulnerabilities into account when riding the host bus.

  • nis2-implAnnex 11.2.1
    addresses
    high
    derived

    Access-rights provisioning across the host–payload boundary is the operational lever that bounds which payload commands reach the bus and which bus telemetry the payload can read.

  • nis2-implAnnex 6.8.1
    addresses
    high
    derived

    Network segmentation between hosted payload and host-bus subsystems is the architectural control that blocks payload-to-bus pivot via SpaceWire/1553/Ethernet gateways and shared file services.

ENISA controls

  • Third-party risk management covers hosted-payload operator agreements where command dictionaries and gateway services differ between payload and host.

  • Least-privilege access control between hosted payload and host-bus management functions denies LM-0001's transit through trusted interfaces.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, LM-0001 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.