All techniques
REC-0002
ST0001Reconnaissance

Gather Spacecraft Descriptors

Description

Threat actors compile a concise but highly actionable dossier of “who/what/where/when” attributes about the spacecraft and mission. Descriptors include identity elements (mission name, NORAD catalog number, COSPAR international designator, call signs), mission class and operator, country of registry, launch vehicle and date, orbit regime and typical ephemerides, and any publicly filed regulatory artifacts (e.g., ITU/FCC filings). They also harvest operational descriptors such as ground network affiliations, common pass windows by latitude band, and staffing patterns implied by press, social media, and schedules. Even when each item is benign, the aggregate picture enables precise timing (e.g., during beta-angle peaks, eclipse seasons, or planned maintenance), realistic social-engineering pretexts, and better targeting of ground or cloud resources that support the mission.

Mappings

EU regulation articles

  • eu-space-actArt. 80(3)
    addresses
    moderate
    direct

    Even though some descriptors (NORAD/COSPAR) are public, operational descriptors (pass windows, staffing patterns, ground-network affiliations) are operator-controlled information that 80(3) requires to be categorized for confidentiality.

ENISA controls

  • Cyber threat intelligence governs the operator threat-intelligence posture, marginally relevant to awareness of reconnaissance rather than actively preventing the gathering of spacecraft descriptors.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0002 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.