All techniques
LM-0007
ST0007Lateral Movement

Credentialed Traversal

Description

Movement is achieved by reusing legitimate credentials and keys to cross boundaries that rely on trust rather than strict isolation. Using operator or service accounts, maintenance logins, station certificates, or spacecraft-recognized crypto, the adversary invokes gateways that bridge domains, C&DH to payload, crosslink routers to onboard networks, or constellation management planes to individual vehicles. Because the traversal occurs through approved interfaces (file services, table loaders, remote procedure calls, crosslink tasking), actions appear as routine operations while reaching progressively more privileged subsystems or neighboring spacecraft. Where roles and scopes are broad or reused, the same credential opens multiple enclaves, turning authorization itself into the lateral path.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    direct

    Reuse of credentials/keys to cross domain boundaries is the canonical case (2)(d)'s access-management obligation addresses — appropriate-control-mechanisms must enforce role and scope boundaries on credentials.

  • craAnnex I, Part I, (2)(j)
    addresses
    moderate
    inferred

    (2)(j) attack-surface limitation reduces cross-domain gateway count but does not interdict honoring of reused valid credentials; access control and least-privilege scoping (2)(d) interdict the credential-reuse lateral path, so (2)(j) addresses surface exposure.

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    direct

    Detecting credentialed traversal across approved interfaces requires the per-interface recording and monitoring obligation in (2)(l).

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    Credentialed traversal across enclaves is the canonical IAM-failure case 81(1) defends — appropriate-control-mechanisms must scope credentials to limit cross-domain reach.

  • eu-space-actArt. 81(4)
    mitigates
    moderate
    direct

    81(4)'s second subparagraph — the principles of 'need to know' and 'least privilege' — directly limits credential reuse across enclaves.

  • eu-space-actArt. 81(5)
    addresses
    moderate
    direct

    Credentialed traversal (primary: Art. 81(1) + Art. 81(4)) cascades to 81(5) — auto-revocation on no-longer-needed authorizations limits cross-domain reuse.

  • eu-space-actArt. 83(1)
    addresses
    moderate
    direct

    Detecting credentialed traversal across approved interfaces requires per-interface monitoring under 83(1)'s continuous-monitoring obligation.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    inferred

    LM-0007 crosses enclave and vehicle boundaries by reusing operator, service and station credentials where roles and scopes are broad or reused; NIS2 21(2)(i) access control policies and asset management govern this risk.

  • nis2Art. 21(2)(j)
    mitigates
    high
    direct

    Continuous authentication and step-up MFA at enclave boundaries under Art. 21(2)(j) limit a single credential's reach by re-authenticating on cross-domain traversal — precisely the boundaries this technique abuses.

  • nis2-implAnnex 11.2.1
    addresses
    high
    derived

    Access-rights hygiene under the provision/modify/remove obligations bounds the scope of credentialed traversal; over-broad operator and service-account rights are the leverage this technique exploits.

  • nis2-implAnnex 11.3.1
    addresses
    high
    derived

    Privileged-account policy bounds which credentials confer cross-boundary authority; the privileged-account discipline is the procedural lever that constrains how far credentialed traversal can travel.

  • nis2-implAnnex 11.6.1
    addresses
    moderate
    derived

    Secure-authentication procedures (key binding, counters, certificate validation) reduce the trust placed on credentials alone — the assumption credentialed traversal exploits.

  • nis2-implAnnex 11.7.1
    addresses
    high
    derived

    Multi-factor authentication on commanding and administrative paths breaks the convertibility of passively reused credentials into cross-boundary traversal.

ENISA controls

  • Least-privilege access control with separation of duties denies single-credential traversal across multiple enclaves.

  • Provisioning, review, modification, and removal of access rights — including privileged access management — limits credential reuse across multiple subsystems.

  • MFA on credentials raises the cost of reusing a single set of credentials to traverse boundaries.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, LM-0007 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.