All techniques
REC-0003.02
ST0001Reconnaissance
sub-technique

Commanding Details

Parent: REC-0003

Description

Threat actors study how commands are formed, authorized, scheduled, and delivered. High-value details include the telecommand protocol (e.g., CCSDS TC), framing and CRC/MAC fields, authentication scheme (keys, counters, anti-replay windows), command dictionary/database formats, critical-command interlocks and enable codes, rate and size limits, timetag handling, command queue semantics, and the roles of scripts or procedures that batch actions. They also collect rules governing “valid commanding periods”: line-of-sight windows, station handovers, maintenance modes, safing states, timeouts, and when rapid-response commanding is permitted. With this, an adversary can craft syntactically valid traffic, time injections to coincide with reduced monitoring, or induce desynchronization (e.g., counter resets, stale timetags).

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    direct

    Manufacturer obligation to ensure protection from unauthorized access by appropriate control mechanisms (including authentication, identity, access management) is the design-side defense that converts commanding-detail reconnaissance into a still-blocked command path: even full knowledge of the command schema does not yield acceptance without valid authentication.

  • craAnnex I, Part I, (2)(j)
    addresses
    moderate
    derived

    Manufacturers must design products to limit attack surfaces, including external interfaces; products that minimise commanding-interface exposure (mode-bound commands, locked-down maintenance dictionaries) reduce the value of commanding-detail reconnaissance.

  • eu-space-actArt. 80(3)
    addresses
    moderate
    direct

    Telecommand framing, authentication scheme details, command-dictionary formats, and timetag rules are highly sensitive operator artifacts within 80(3)'s confidentiality categorization scope.

  • eu-space-actArt. 85(1)
    addresses
    moderate
    inferred

    Art. 85(1)'s cryptographic concept is domain-relevant to the authentication scheme REC-0003.02 reconnoiters, but defining the crypto concept does not interdict reconnaissance of its details; information classification would.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Art. 21(2)(h) crypto policy is part of the commanding-scheme design being studied; it does not interdict reconnaissance of command formats, authorization and sequencing from dictionaries and specifications, which is countered by information protection and OPSEC. Addresses (domain relevance).

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Command dictionaries/databases, enable-code stores, and procedure libraries are access-controlled assets; Art. 21(2)(i) governs who within and outside the entity can read them.

  • nis2-implAnnex 11.6.1
    addresses
    high
    direct

    Telecommand authentication procedures (MAC keys, authentication tags, command counters) are the secure-authentication mechanisms the implementing regulation requires the entity to implement; their design quality is what determines whether commanding-detail reconnaissance can be turned into command injection.

  • nis2-implAnnex 12.1.1
    addresses
    high
    derived

    TC framing, packet structures and authentication-field definitions are crown-jewel command-system assets whose classification determines who can reconstruct the commanding interface.

ENISA controls

  • Communications security mandates secure command protocols with strong cryptographic mechanisms that limit what reconnaissance of telecommand framing can yield.

  • Cryptography and key management governs the authentication scheme (keys, counters, anti-replay windows) REC-0003.02 studies and reduces the value of what is learned, but it does not actively prevent the reconnaissance itself, so addresses rather than mitigates.

  • Cryptographically based bidirectional authentication on every command session is the control that turns harvested command details into useless intelligence.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0003.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.