All techniques
RD-0004.02
ST0002Resource Development
sub-technique

Upload Exploit/Payload

Parent: RD-0004

Description

Having chosen a path, adversaries pre-position the specific packages and procedures they intend to use: binary exploits, malicious tables and ephemerides, patch images, modem profiles, and operator macros that chain actions. On compromised or leased infrastructure, they stage these items where execution will be fastest, provider portals, scheduler queues, ground station file drops, or automation repos, with triggers tied to pass start, beacon acquisition, or operator shift changes. Artifacts are formatted to mission protocols (framing, CRC/MAC, timetags), chunked to meet rate/size constraints, and signed or wrapped to evade superficial checks. Anti-forensics (timestamp tampering, log suppression, ephemeral storage) reduce audit visibility, while fallback payloads are kept for alternate modes (safe-mode dictionaries, recovery consoles).

Mappings

EU regulation articles

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Pre-positioned binaries, malicious tables, and operator macros staged inside the entity's automation repos, scheduler queues, or ground-station file drops are detectable artefacts the entity's incident-handling capability under Art. 21(2)(b) must surface — including via anti-forensics-resistant logging.

  • nis2Art. 21(2)(d)
    addresses
    moderate
    direct

    Staging on third-party provider portals, leased ground-station file drops, and partner automation repos rides supplier and service-provider trust boundaries; supplier-relationship security under Art. 21(2)(d) governs the integrity expectations for those touchpoints.

  • nis2Art. 21(3)
    addresses
    moderate
    derived

    Primary mapping to Art. 21(2)(d) covers third-party tooling and exploit-acquisition supply paths the adversary leverages. Art. 21(3) procedurally extends to assessment of those tooling suppliers' secure-development practices, since the entity's operational tooling and uplink chain inherit the supplier's vulnerability-management discipline.

ENISA controls

  • Separation of development/testing/production environments is relevant to limiting cross-environment contamination if adversary-staged artefacts reach operator environments, governing isolation rather than defending the adversary-side staging.

  • Mission-system update validation prior to deployment is the named defense against pre-positioned adversary payloads in update pipelines and ground file drops.

  • Boundary monitoring at provider portals, ground-station file drops, and automation repos surfaces staged-payload activity prior to triggering.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, RD-0004.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.