All techniques
RD-0004
ST0002Resource Development

Stage Capabilities

Description

Before execution, adversaries prepare the ground, literally and figuratively. They upload tooling, exploits, procedures, and datasets to infrastructure they own or have compromised, wire up C2 and telemetry pipelines, and pre-configure RF/baseband chains and protocol stacks to match mission parameters. Staging often uses cloud object stores, VPS fleets, or CI/CD runners masquerading as benign automation; artifacts are containerized or signed with hijacked material to blend in. For RF operations, actors assemble demod/encode flowgraphs, precompute CRC/MAC fields and timetags, and script rate/size pacing to fit pass windows. For ground/cloud, they stage credentials, macros, and schedule templates that can push changes or exfiltrate data quickly during handovers or safing. Dry-runs on flatsats/HIL rigs validate timing and error paths; OPSEC measures (rotating domains, domain fronting, traffic mixers) reduce attribution.

Mappings

ENISA controls

  • Boundary monitoring at external entry points and mission-critical internal boundaries surfaces adversary staging activity within or against operator infrastructure.

  • Cyber threat intelligence about staged adversary infrastructure (newly registered domains, phishing kits, leaked tooling) gives the operator advance warning of this technique.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, RD-0004 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.