Exploit/Payload
Parent: RD-0003
Description
Threat actors obtain or adapt exploits (the trigger) and payloads (the action after exploitation) for space, ground, and cloud components. Targets include flight software parsers and table loaders, bootloaders and patch/update handlers, bus gateways, payload controllers, and ground services. Payloads may be binaries, scripts, or command/procedure sequences that alter modes, bypass FDIR, or stage follow-on access; they can also be “data payloads” that exploit weak validation (malformed tables, ephemeris, or calibration products). Acquisition paths mirror the broader market, brokered N-day/0-day packages, open-source exploits re-tooled for mission stacks, and theft from vendors or researchers. Actors tune timing, size/rate limits, and anti-replay nuances so delivery fits pass windows and link budgets, and they rehearse on flatsats to achieve deterministic outcomes.
Mappings
ENISA controls
Vulnerability management on the operator's systems closes the gaps adversary-obtained exploits target and reduces their value, but it does not prevent the resource-development acquisition of exploits RD-0003.01 performs, so addresses rather than mitigates.
Regular software updates close vulnerabilities and reduce the operational value of an adversary-obtained exploit, but updating the victim system does not prevent the resource-development acquisition of exploits, so this is relevance rather than active mitigation of the technique.
Cyber threat intelligence collection alerts the operator to the existence and pricing of exploits relevant to mission systems before they are deployed.
Cross-reference controls
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
RA-5 (Vulnerability Monitoring and Scanning) mitigates RD-0003.01 by reducing the attack surface adversary exploits target.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SI-2 (Flaw Remediation) mitigates RD-0003.01 by closing the windows in which acquired exploits remain effective.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
T2007.006 'Software vulnerabilities' covers obtaining/exploiting unpatched COTS — directly aligned with RD-0003.01 acquiring exploit code targeting RTOS/middleware/ground services.
T2007.008 'Space Protocol Vulnerabilities' covers acquiring vulnerability info specifically for space protocols — directly aligned with RD-0003.01 obtaining exploits for flight software protocol parsers and bus gateways.
T2007.009 'Tools for attacking space systems' covers obtaining attack tooling — directly aligned with RD-0003.01's exploit/payload acquisition for space, ground, and cloud components.
SPARTA countermeasures
Mapped by SPARTA, not curated by SafeMode Space.
Cite as SafeMode Space, RD-0003.01 (SPARTA v3.2).