All techniques
PER-0003
ST0005Persistence

Ground System Presence

Description

The adversary maintains long-lived access by residing within mission ground infrastructure that already has end-to-end reach to the spacecraft. Persistence can exist in operator workstations and mission control software, schedulers/orchestrators, station control (antenna/mount, modem/baseband), automation scripts and procedure libraries, identity and ticketing systems, and cloud-hosted mission services. With this foothold, the actor can repeatedly queue commands, updates, or file transfers during routine passes; mirror legitimate operator behavior to blend in; and refresh their tooling as software is upgraded. Presence on the ground also supports durable reconnaissance (pass plans, dictionaries, key/counter states) and continuous staging so each window to the vehicle can be exploited without re-establishing access.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Authentication and access-management obligations on ground-system products are what bound the convertibility of foothold to commanding access; manufacturer-implemented MFA and identity-binding break long-dwell credential leverage.

  • craAnnex I, Part I, (2)(j)
    addresses
    high
    derived

    Limited attack surfaces on ground-system products bound the surface where persistent attacker presence can hide; manufacturers must minimise admin consoles, debug ports and management APIs.

  • craAnnex I, Part I, (2)(l)
    addresses
    high
    derived

    Logging and monitoring obligation requires products to record relevant internal activity; long-dwell attacker behaviour leaves observable signatures that the (2)(l) instrumentation surfaces.

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    Persistent ground-system access is the canonical case 81(1)'s identity-and-access-management protocols defend against — credential lifecycle and audit are the discipline that detects and revokes residency.

  • eu-space-actArt. 81(4)
    addresses
    high
    direct

    81(4)'s issuance/management/revocation/audit obligations on credentials directly counter long-lived ground-system residency — periodic recertification limits attacker persistence.

  • eu-space-actArt. 81(5)
    addresses
    high
    direct

    Long-lived ground-system presence (primary: Art. 81(1) IAM + Art. 81(4) lifecycle) is directly defeated by 81(5)'s automatic-revocation-when-no-longer-needed clause — orphaned/unused credentials self-expire.

  • eu-space-actArt. 83(1)
    addresses
    high
    direct

    Continuous monitoring under 83(1) detects long-lived ground-system presence through anomalous behavior, lateral-movement signals, and out-of-pattern automation activity.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Adversary residency in operator workstations, mission control software, schedulers, automation, IdPs, and cloud-hosted mission services is an ongoing high-severity incident; Art. 21(2)(b)'s incident-handling capability must detect, contain, document, and remediate that footprint.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Operator workstations, schedulers/orchestrators, station-control systems, automation scripts, procedure libraries, identity/ticketing systems, and cloud-hosted mission services are precisely the asset class Art. 21(2)(i)'s access-control + asset-management obligation governs.

  • nis2Art. 21(2)(j)
    addresses
    moderate
    direct

    Continuous authentication and step-up MFA on operator/admin sessions under Art. 21(2)(j) are what limit a persistent attacker's ability to refresh tooling, queue commands across passes, and mirror legitimate operator behaviour.

  • nis2Art. 23(1)
    triggers obligation
    moderate
    direct

    Confirmed persistent compromise of mission ground systems supporting essential services causes severe operational disruption per Art. 23(3)(a); Art. 23(1) reporting (24h early warning, 72h notification) applies.

  • nis2Art. 23(2)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) treats persistent attacker presence in the ground system as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats GS persistence as significant. Art. 23(3) significance applies conditionally on the persistence enabling downstream impact (operational disruption, theft); persistence alone is preparatory but, on a NIS2-regulated GS, the access-level criterion typically meets the considerable-damage threshold once detected.

  • nis2Art. 23(4)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Persistent presence is usually discovered via threat-hunting or post-incident review; awareness lags initial implant.

  • nis2-implAnnex 11.2.1
    addresses
    high
    derived

    Access-rights provisioning hygiene (revocation on role change, periodic review) is the operational lever that bounds the dwell time of persistent attacker access to ground systems.

  • nis2-implAnnex 11.7.1
    addresses
    high
    derived

    Multi-factor authentication on operator workstations and TT&C automation breaks the conversion from persistent foothold to live commanding access, even where the attacker has achieved long-lived credential capture.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring-and-logging procedures are the principal detective control for ground-system persistence; long-dwell attacker behaviour leaves observable signatures across operator workstations, auth servers and gateway equipment.

  • nis2-implAnnex 3.3.1
    addresses
    moderate
    derived

    Persistent ground-system presence produces analyst-visible anomalies (off-hours activity, account-usage drift, unexpected service-account behaviour); Annex 3.3.1 mechanism captures those analyst reports as the upstream feeder for the Annex 3.2.1 monitoring already in place.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security measures protect operator workstations, mission-control servers and gateway equipment from persistent attacker presence; the network-security obligations are the protective envelope around the ground-segment infrastructure this technique inhabits.

  • nis2-implAnnex 6.8.1
    addresses
    high
    derived

    Network segmentation isolates persistent footholds from spreading across the ground segment; segmentation discipline limits the spacecraft-reachability of an attacker established on a single workstation.

ENISA controls

  • Least-privilege access control on operator workstations, schedulers, and station control directly attacks the foothold PER-0003 maintains in mission ground infrastructure.

  • MFA on operator and automation accounts limits long-lived credential-only persistence in mission ground infrastructure.

  • Intrusion detection and prevention with documented baselines surfaces the durable reconnaissance and continuous staging that defines PER-0003 ground presence.

  • A documented incident response plan governs procedures for responding to ground-system presence, relevant to shortening dwell time rather than actively preventing the persistence.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, PER-0003 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.