All techniques
RD-0003.01
ST0002Resource Development
sub-technique

Exploit/Payload

Parent: RD-0003

Description

Threat actors obtain or adapt exploits (the trigger) and payloads (the action after exploitation) for space, ground, and cloud components. Targets include flight software parsers and table loaders, bootloaders and patch/update handlers, bus gateways, payload controllers, and ground services. Payloads may be binaries, scripts, or command/procedure sequences that alter modes, bypass FDIR, or stage follow-on access; they can also be “data payloads” that exploit weak validation (malformed tables, ephemeris, or calibration products). Acquisition paths mirror the broader market, brokered N-day/0-day packages, open-source exploits re-tooled for mission stacks, and theft from vendors or researchers. Actors tune timing, size/rate limits, and anti-replay nuances so delivery fits pass windows and link budgets, and they rehearse on flatsats to achieve deterministic outcomes.

Mappings

ENISA controls

  • Vulnerability management on the operator's systems closes the gaps adversary-obtained exploits target and reduces their value, but it does not prevent the resource-development acquisition of exploits RD-0003.01 performs, so addresses rather than mitigates.

  • Regular software updates close vulnerabilities and reduce the operational value of an adversary-obtained exploit, but updating the victim system does not prevent the resource-development acquisition of exploits, so this is relevance rather than active mitigation of the technique.

  • Cyber threat intelligence collection alerts the operator to the existence and pricing of exploits relevant to mission systems before they are deployed.

Cross-reference controls

  • mitre-attack-enterpriseT1588Obtain Capabilities
    relates to
    moderate

    Mapped by SPARTA, not curated by SafeMode Space.

  • mitre-attack-enterpriseT1588.005Exploits
    relates to
    moderate

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5PM-16Threat Awareness Program
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5RA-10Threat Hunting
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5RA-3Risk Assessment
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5RA-3(2)Use of All-source Intelligence
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5RA-3(3)Dynamic Threat Awareness
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5RA-5Vulnerability Monitoring and Scanning
    addresses
    high

    RA-5 (Vulnerability Monitoring and Scanning) mitigates RD-0003.01 by reducing the attack surface adversary exploits target.

  • nist-80053-rev5SA-3System Development Life Cycle
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8Security and Privacy Engineering Principles
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SI-2Flaw Remediation
    mitigates
    moderate

    SI-2 (Flaw Remediation) mitigates RD-0003.01 by closing the windows in which acquired exploits remain effective.

  • nist-80053-rev5SI-4(24)Indicators of Compromise
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SR-8Notification Agreements
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • space-shieldT2007.006Software vulnerabilities
    addresses
    high

    T2007.006 'Software vulnerabilities' covers obtaining/exploiting unpatched COTS — directly aligned with RD-0003.01 acquiring exploit code targeting RTOS/middleware/ground services.

  • T2007.008 'Space Protocol Vulnerabilities' covers acquiring vulnerability info specifically for space protocols — directly aligned with RD-0003.01 obtaining exploits for flight software protocol parsers and bus gateways.

  • T2007.009 'Tools for attacking space systems' covers obtaining attack tooling — directly aligned with RD-0003.01's exploit/payload acquisition for space, ground, and cloud components.

SPARTA countermeasures

Cite as SafeMode Space, RD-0003.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.