All techniques
REC-0003.04
ST0001Reconnaissance
sub-technique

Valid Credentials

Parent: REC-0003

Description

Adversaries seek any credential that would let them authenticate as a legitimate actor in space, ground, or supporting cloud networks. Targets include TT&C authentication keys and counters, link-encryption keys, PN codes or spreading sequences, modem and gateway accounts, mission control mission control user and service accounts, station control credentials, VPN and identity-provider tokens, SLE/CSP service credentials, maintenance backdoor accounts, and automation secrets embedded in scripts or CI/CD pipelines. Acquisition paths include spear-phishing, supply-chain compromise, credential reuse across dev/test/ops, logs and core dumps, misconfigured repositories, contractor laptops, and improperly sanitized training data. Because some missions authenticate uplink without encrypting it, possession of valid keys or counters may be sufficient to issue accepted commands from outside official channels.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Manufacturer obligation to provide authentication, identity and access-management mechanisms is the procedural lever that bounds the value of credential reconnaissance: products designed under (2)(d) bind credentials to verified factors so passive harvesting alone does not yield commanding access.

  • craAnnex I, Part I, (2)(e)
    addresses
    moderate
    derived

    Confidentiality protection of stored credential material (encrypted key stores, secure tokens, hardware-backed identity) is the manufacturer-side control that resists in-product credential exfiltration during recon.

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    TT&C authentication keys, link-encryption keys, and operator credentials are exactly the access-rights material 81(1)'s identity-and-access-management protocols govern.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    81(4)'s issuance/management/revocation/audit obligations on credentials directly mitigate credential-leakage scenarios — least-privilege limits the population that can hold TT&C keys.

  • eu-space-actArt. 85(2)
    addresses
    high
    direct

    Cryptographic-key acquisition by adversaries directly attacks the lifecycle (generation, use, storage, distribution, disposal) that 85(2) places on the operator.

  • nis2Art. 21(2)(g)
    addresses
    moderate
    direct

    Spear-phishing, credential reuse, and exposure of secrets in scripts/CI runners are addressed by basic cyber hygiene practices and cybersecurity training under Art. 21(2)(g) that build human resilience to the most common credential-theft vectors.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Cryptographic key management deprives an adversary of usable key material, but it covers only the crypto-key-material subset of this technique, not its dominant scope of broad credential discovery across accounts and tokens via phishing and repositories, where the operative control is identity and access management and information protection. Under the strict bar the cryptographic control covers a subset but not the defining scope, so at NIS2 Art. 21(2)(h) the relationship is addresses.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Mission control accounts, modem credentials, station-control credentials, VPN tokens, SLE/CSP service credentials, and CI/CD secrets are precisely the asset class Art. 21(2)(i)'s access-control + asset-management obligation governs across issuance, storage, rotation, and revocation.

  • nis2Art. 21(2)(j)
    mitigates
    high
    direct

    Multi-factor authentication or continuous authentication under Art. 21(2)(j) directly defeats reuse of credentials harvested from phishing, supply-chain compromise, repos, dumps, contractor laptops, or sanitised training data.

  • nis2-implAnnex 11.5.1
    addresses
    high
    direct

    Identity life-cycle management is the precise control the implementing regulation requires the entity to apply to operator identities, service accounts and tokens — the targets of credential reconnaissance.

  • nis2-implAnnex 11.6.1
    addresses
    high
    derived

    Secure authentication procedures determine the value of any harvested credentials; if the entity authenticates with state-of-the-art methods bound to device or context, intercepted secrets are not directly usable.

  • nis2-implAnnex 11.7.1
    addresses
    high
    direct

    Multi-factor authentication is the procedural and technical defense that converts credential-reconnaissance success into a still-blocked authentication attempt.

  • nis2-implAnnex 12.1.1
    addresses
    moderate
    derived

    Credentials, tokens and key material are top-classification assets whose handling controls determine whether the recon adversary can ever harvest them in the first place.

ENISA controls

  • The secure workload-to-workload authenticator policy explicitly forbids static authenticators in scripts and configuration files — the embedded automation secrets REC-0003.04 hunts.

  • Cryptography and key management protects TT&C keys, link-encryption keys, and counters — exactly the credential families REC-0003.04 targets in space and ground.

  • Authentication-information management governs allocation, handling, and revocation of every credential REC-0003.04 attempts to acquire.

  • Multi-factor authentication makes harvested credentials substantially less useful for masquerading on ground or cloud accounts.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0003.04 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.