All techniques
RD-0004.01
ST0002Resource Development
sub-technique

Identify/Select Delivery Mechanism

Parent: RD-0004

Description

Adversaries select the pathway that best balances effect, risk, bandwidth, and attribution. Options include over-the-air telecommand injection on TT&C links, manipulation of payload downlinks or user terminals, abuse of crosslinks or gateways, pivoting through commercial ground networks, or pushing malicious updates via supply-chain paths (software, firmware, bitstreams). Selection considers modulation/coding, Doppler and polarization, anti-replay windows, pass geometry, rate/size limits, and expected operator workload (handover, LEOP, safing exits). For ground/cloud paths, actors account for identity boundaries, automation hooks, and change-control cadence. The “delivery mechanism” is end-to-end: RF front-end (antenna, converters, HPAs), baseband/SDR chain, protocol/framing, authentication/counter handling, scheduling, and fallbacks if detection occurs. Rehearsal artifacts, test vectors, mock dictionaries, ephemerides, are built alongside.

Mappings

ENISA controls

  • Malware protection at entry/exit points is relevant to the delivery vectors RD-0004.01 selects among, countering eventual delivery rather than the resource-development selection step itself.

  • Intrusion detection and prevention on mission-critical components detects payload-delivery attempts at the boundary or on the spacecraft itself.

  • Cybersecurity awareness and training is a governance control relevant to resisting the phishing and removable-media delivery RD-0004.01 evaluates, but it does not actively defend against the adversary selecting a delivery mechanism.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, RD-0004.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.