All techniques
REC-0001.07
ST0001Reconnaissance
sub-technique

Payload

Parent: REC-0001

Description

Adversaries pursue a clear picture of payload type, operating modes, command set, and data paths to and from the bus and ground. High-value details include vendor and model, operating constraints (thermal, pointing, contamination), mode transition logic, timing of calibrations, safety inhibits and interlocks, firmware/software update paths, data formatting and compression, and any crypto posture differences between payload links and the main command link. Payload ICDs often reveal addresses, message identifiers, and gateway locations where payload traffic bridges to the C&DH or data-handling networks, creating potential pivot points. Knowledge of duty cycles and scheduler entries enables timing attacks that coincide with high-power or high-rate operations to stress power/thermal margins or saturate storage and downlink. Even partial information, calibration script names, test vectors, or engineering telemetry mnemonics, can shrink the search space for reverse engineering.

Mappings

EU regulation articles

  • eu-space-actArt. 80(3)
    addresses
    high
    direct

    Payload ICDs reveal addresses, message IDs, gateway locations, and crypto-posture differences with the bus — high-confidentiality operator artifacts within 80(3)'s categorization scope.

  • eu-space-actArt. 91(3)
    relates to
    low
    direct

    When payload reconnaissance involves third-party hosted-payload context, 91(3)'s pre-defined-agreements-with-third-party-entities clause governs how payload details are exchanged and protected.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Payload ICDs, command sets, gateway locations, and engineering-telemetry mnemonics are the precise asset class Art. 21(2)(i)'s access-control + asset-management requirement is meant to govern, particularly where payload traffic bridges to C&DH networks.

  • nis2-implAnnex 12.1.1
    addresses
    high
    derived

    Payload command sets, operating modes and data-paths are sensitive mission assets whose classification drives the control regime that constrains payload-reconnaissance leakage.

  • nis2-implAnnex 12.2.1
    addresses
    moderate
    derived

    Handling-of-payload-asset policy governs how payload command-set documentation moves between operator, payload vendor and customer environments.

ENISA controls

  • Criticality analysis identifying payload as a mission-critical function prioritises protection of its command sets and is relevant, but criticality analysis is a governance control and does not itself actively defend against the reconnaissance REC-0001.07 performs.

  • Classifying payload ICDs, calibration scripts, and engineering telemetry per risk rating governs their protection and is relevant to limiting REC-0001.07 gathering, but classification is governance and does not actively defend against reconnaissance.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0001.07 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.