All techniques
REC-0005
ST0001Reconnaissance

Eavesdropping

Description

Adversaries seek to passively (and sometimes semi-passively) capture mission communications across terrestrial networks and RF/optical links to reconstruct protocols, extract telemetry, and derive operational rhythms. On networks, packet captures, logs, and flow data from ground stations, mission control, and cloud backends can expose service boundaries, authentication patterns, and automation. In the RF domain, wideband recordings, spectrograms, and demodulation of TT&C and payload links, spanning VHF/UHF through S/L/X/Ka and, increasingly, optical, enable identification of modulation/coding, framing, and beacon structures. Even when links are encrypted, metadata such as carrier plans, symbol rates, polarization, and cadence can support traffic analysis, timing attacks, or selective interference. Community capture networks and open repositories amplify the reach of a modest adversary.

Mappings

EU regulation articles

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    Eavesdropping on TT&C and payload links is the canonical case 85(1)'s cryptographic-concept obligation addresses — the operator must define crypto mechanisms specifically to defeat passive interception.

  • eu-space-actArt. 85(3)
    addresses
    high
    direct

    85(3)(a) requires end-to-end authentication of links between satellite control centres and the space segment; 85(3)(b) requires telecommand encryption based on risk assessment — both directly counter eavesdropping.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Art. 21(2)(h) requires cryptography and, where appropriate, encryption policies covering TT&C and payload links; it addresses eavesdropping by mandating link encryption, while the deployed encryption, not the policy obligation, is what reduces wideband recordings to traffic-analysis surface only.

ENISA controls

  • Communications security with strong cryptographic mechanisms directly defeats RF and packet eavesdropping by preventing unauthorized disclosure during transmission.

  • Transmission security explicitly counters interception and the derivation of intelligence by analysis of transmission characteristics — the core eavesdropping yield.

  • Traffic flow security is precisely the control aimed at defeating traffic analysis and metadata-derived adversary inferences that drive eavesdropping value.

  • Cryptography and key management provides the encryption that turns wideband recordings into ciphertext for the eavesdropping adversary.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0005 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.