All techniques
REC-0003
ST0001Reconnaissance

Gather Spacecraft Communications Information

Description

Threat actors assemble a detailed picture of the mission’s RF and networking posture across TT&C and payload links. Useful elements include frequency bands and allocations, emission designators, modulation/coding, data rates, polarization sense, Doppler profiles, timing and ranging schemes, link budgets, and expected Eb/N0 margins. They also seek antenna characteristics, beacon structures, and whether transponders are bent-pipe or regenerative. On the ground, they track station locations, apertures, auto-track behavior, front-end filters/LNAs, and handover rules, plus whether services traverse SLE, SDN, or commercial cloud backbones. Even small details, polarization sense, roll-off factors, or beacon cadence, shrink the search space for interception, spoofing, or denial. The outcome is a lab-replicable demod/decode chain and a calendar of advantageous windows.

Mappings

EU regulation articles

  • eu-space-actArt. 80(3)
    addresses
    high
    direct

    Comm posture details (frequency allocations, link budgets, antenna characteristics, station geometries) are operator-controlled artifacts that 80(3) categorizes for confidentiality.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    inferred

    Art. 84(2)'s requirement to comply with Annex VII point 5.1 governs network-and-information-system protection in this technique's domain, but the cited text names no mechanism interdicting passive link interception; it establishes domain relevance, not vector interdiction. Link encryption or emission control would be the interdicting mitigation.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Art. 21(2)(h) crypto policy does not hide RF and networking posture (bands, modulation, polarization, ground stations), which is observable regardless of encryption; the operative control is EMSEC and OPSEC. Addresses (domain relevance).

  • nis2-implAnnex 12.1.1
    addresses
    high
    derived

    Frequency plans, link-budget tables, modulation and FEC parameters are mission-critical communications assets; their classification level drives the storage and dissemination controls that determine the recon surface for an adversary's RF profile of the mission.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    direct

    Network security obligations apply to the comms architecture and the protection of comms-configuration management — recon for the RF posture is fundamentally a network-security observable.

ENISA controls

  • Communications security mandates secure protocols and crypto-bypass prevention that defeat the link reconnaissance REC-0003 performs.

  • Transmission security explicitly counters derivation of intelligence by analysis of transmission characteristics — exactly REC-0003's deliverable.

  • Information classification governs the protective marking of link budgets, station locations, and beacon structures whose disclosure REC-0003 exploits.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0003 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.