All techniques
RD-0002
ST0002Resource Development

Compromise Infrastructure

Description

Rather than purchasing or renting assets, adversaries compromise existing infrastructure, mission-owned, third-party, or shared, to obtain ready-made reach into space, ground, or cloud environments with the benefit of plausible attribution. Targets range from physical RF chains and timing sources to mission control servers, automation/scheduling systems, SLE/CSP gateways, identity providers, and cloud data paths. Initial access often comes via stolen credentials, spear-phishing of operators and vendors, exposed remote-support paths, misconfigured multi-tenant platforms, or lateral movement from enterprise IT into operations enclaves. Once resident, actors can pre-position tools, modify configurations, suppress logging, and impersonate legitimate stations or operators to support later Execution, Exfiltration, or Denial.

Mappings

EU regulation articles

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    Compromise of mission-owned infrastructure (mission control, automation, identity providers) is the canonical case 81(1)'s identity-and-access-management protocols defend against.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    Compromise-infrastructure scenarios (primary: Art. 81(1)) cascade to 81(4) — credential lifecycle audit detects unauthorized retention of access on operator infrastructure.

  • eu-space-actArt. 83(1)
    addresses
    high
    direct

    Continuous detection and monitoring under 83(1) is required to detect compromise of operator infrastructure that adversaries leverage as a stepping stone.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to infrastructure compromise but names no specific interdicting mechanism in the cited text.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Adversary residency in mission, third-party, or shared infrastructure is a paradigmatic incident the entity's incident-handling capability under Art. 21(2)(b) must detect, contain, and document — including pre-positioned tools and suppressed logging.

  • nis2Art. 21(2)(g)
    addresses
    moderate
    direct

    Spear-phishing of operators and vendors is one of the named initial-access routes; Art. 21(2)(g)'s basic cyber hygiene practices and cybersecurity training raise the floor of human resilience to that vector.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Mission control servers, automation/scheduling systems, SLE/CSP gateways, identity providers, and cloud data paths are the precise asset class Art. 21(2)(i)'s access-control + asset-management obligation governs across enclaves.

  • nis2Art. 21(2)(j)
    addresses
    high
    direct

    Multi-factor authentication or continuous authentication under Art. 21(2)(j) directly defeats the stolen-credential, exposed-remote-support, and lateral-IT-to-ops paths that drive most infrastructure compromise.

  • nis2Art. 23(1)
    triggers obligation
    high
    direct

    Confirmed compromise of mission, partner, or shared infrastructure that supports the provision of essential services is a significant incident; Art. 23(1) requires notification of the CSIRT/competent authority without undue delay.

  • nis2Art. 23(2)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) treats compromise of the entity's infrastructure (used as resource staging) as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats infrastructure compromise as significant. Art. 23(3) significance is met when the staged-resource use enables operational disruption or considerable damage downstream; for resource-development-only cases (no follow-on impact), significance attaches to the unauthorized access itself.

  • nis2Art. 23(4)
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Infrastructure-compromise detection often surfaces via egress anomalies; awareness can lag the compromise window.

  • nis2-implAnnex 11.2.1
    addresses
    high
    derived

    Provision, modification and removal of access rights is the operational mechanism that bounds an attacker's footprint inside compromised infrastructure; stale or over-broad rights are the leverage the technique exploits.

  • nis2-implAnnex 3.4.1
    addresses
    high
    derived

    Compromise of the entity's infrastructure (used as adversary staging) requires Annex 3.4.1 assessment to determine whether observed activity constitutes an incident before Annex 3.5.1 response activates.

  • nis2-implAnnex 3.4.2
    addresses
    moderate
    derived

    Operational assessment for infrastructure-compromise events evaluates dwell time, scope and lateral-movement potential to drive Annex 3.5.1 response.

  • nis2-implAnnex 3.5.1
    addresses
    moderate
    derived

    Incident-response procedures determine whether a compromise used as adversary infrastructure is detected and evicted before it is operationalized for mission impact.

  • nis2-implAnnex 3.6.1
    addresses
    moderate
    derived

    Post-incident review of infrastructure-compromise events identifies which segments allowed adversary staging and remediation gaps.

  • nis2-implAnnex 3.6.2
    addresses
    moderate
    derived

    Improvements from infrastructure-compromise post-incident review typically include hardening of compromised segments and detection-coverage extensions.

  • nis2-implAnnex 3.6.3
    addresses
    moderate
    derived

    Annex 3.6.3 planned-interval tracking applies to infrastructure-compromise events.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations are the protection envelope around the entity's infrastructure; an adversary compromising existing infrastructure for staging is acting against precisely the controls Annex 6.7 requires the entity to maintain.

ENISA controls

  • Supplier security management governs the contractual and audit posture of the legitimate-infrastructure providers an adversary attempts to compromise.

  • Intrusion detection and prevention on mission-critical components surfaces the compromise activity central to RD-0002.

  • Cybersecurity awareness and training addresses the human attack vector (phishing, credential theft) that RD-0002 uses to compromise infrastructure, a program relevant to the technique rather than an active technical defense.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, RD-0002 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.