All techniques
PER-0005
ST0005Persistence

Credentialed Persistence

Description

Threat actors may acquire or leverage valid credentials to maintain persistent access to a spacecraft or its supporting command and control (C2) systems. These credentials may include system service accounts, user accounts, maintenance access credentials, cryptographic keys, or other authentication mechanisms that enable continued entry without triggering access alarms. By operating with legitimate credentials, adversaries can sustain access over extended periods, evade detection, and facilitate follow-on tactics such as command execution, data exfiltration, or lateral movement. Credentialed persistence is particularly effective in environments lacking strong credential lifecycle management, segmentation, or monitoring allowing threat actors to exploit trusted pathways while remaining embedded in mission operations.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    direct

    Credentialed persistence is the canonical case (2)(d) addresses: the obligation requires authentication and identity/access-management mechanisms plus reporting on possible unauthorised access — which credential lifecycle hygiene, monitoring, and access-revocation directly target.

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    direct

    Recording and monitoring access to data, services, or functions is the detection layer that catches credential misuse persisting over extended periods.

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    Credentialed persistence — leveraging valid credentials to maintain access — is the canonical case 81(1)'s identity-and-access-management protocols defend against on the spacecraft and ground systems.

  • eu-space-actArt. 81(4)
    mitigates
    moderate
    direct

    81(4)'s issuance/management/revocation/audit lifecycle on credentials limits how long compromised credentials retain access — periodic recertification is the operator-side discipline that defeats long-term credentialed persistence.

  • eu-space-actArt. 81(5)
    addresses
    high
    direct

    Credentialed persistence (primary: Art. 81(1) + Art. 81(4)) cascades to 81(5) — automatic revocation of expired authorizations limits how long persistent credentials retain access.

  • eu-space-actArt. 83(1)
    addresses
    moderate
    direct

    Detection of credentialed-persistence patterns (out-of-pattern access, unusual session timing) requires continuous monitoring under 83(1).

  • nis2Art. 21(2)(i)
    addresses
    moderate
    inferred

    PER-0005 sustains access using valid credentials where credential lifecycle management, segmentation and asset management are weak; NIS2 21(2)(i) access control policies and asset management is the measure that governs this risk.

  • nis2Art. 21(2)(j)
    mitigates
    moderate
    direct

    Multi-factor authentication or continuous authentication under Art. 21(2)(j) defeats the 'operating with legitimate credentials' premise the technique relies on — even valid credentials become single-use without a second factor or session-binding signal.

  • nis2-implAnnex 11.2.1
    addresses
    high
    derived

    Provision, modification and removal of access rights under documented procedures is the operational lever that prevents stale credentials from carrying persistent access across role changes, project transitions and offboarding.

  • nis2-implAnnex 11.3.1
    addresses
    high
    derived

    Service accounts and maintenance accounts are privileged-account population; the privileged-account policy applies strong identification, periodic review and separation-of-duty requirements that detect attacker-controlled long-lived credentials.

  • nis2-implAnnex 11.5.1
    addresses
    high
    derived

    Identity life-cycle management of service accounts, user accounts and maintenance access is the procedural mechanism that bounds the dwell time of credentialed persistence; revoked, rotated or expired credentials cannot underpin long-lived access.

  • nis2-implAnnex 11.7.1
    addresses
    high
    derived

    Multi-factor authentication on accounts that confer commanding access prevents harvested or replayed credentials from yielding live persistence — even a long-lived password is insufficient on its own.

ENISA controls

  • Least-privilege access control with separation of duties limits the reach of any persistently-held credential.

  • Authentication-information management governs the lifecycle of the credentials credentialed persistence depends on, including handling guidance and revocation procedures.

  • Access rights provisioning, review, modification, and removal directly attack credentialed persistence by ensuring credentials do not outlive their legitimate need.

  • MFA limits the value of any single harvested credential, breaking the credentialed-persistence pathway.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, PER-0005 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.