All techniques
REC-0005.01
ST0001Reconnaissance
sub-technique

Uplink Intercept Eavesdropping

Parent: REC-0005

Description

Uplink reconnaissance focuses on capturing the command path from ground to spacecraft to learn telecommand framing, authentication fields, timing, and anti-replay behavior. Valuable artifacts include emission designators, symbol rates, polarization sense, Doppler profiles, and any preambles or ranging tones that gate command acceptance. Even if payload and TT&C share spectrum, their authentication postures often differ, knowledge an adversary can exploit. Partial captures, console screenshots, or training recordings reduce the effort needed to build an SDR pipeline that “looks right” on the air. Where missions authenticate without encrypting the uplink, traffic analysis can reveal command cadence and maintenance windows.

Mappings

EU regulation articles

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    The cryptographic concept under 85(1) defines the crypto posture (algorithms, modes, anti-replay) on the uplink that defeats eavesdropping-derived attack capability.

  • eu-space-actArt. 85(3)
    addresses
    high
    direct

    Uplink interception captures telecommand traffic; 85(3)(a)/(b) require end-to-end authentication and encryption of telecommands — directly defeating uplink eavesdropping.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Uplink confidentiality + authentication under Art. 21(2)(h)'s cryptography-policy obligation prevents reconstruction of telecommand framing, authentication fields, and anti-replay behaviour from captured emissions.

  • nis2-implAnnex 11.6.1
    addresses
    moderate
    inferred

    Authentication based on access control is domain relevant but does not interdict passive interception or traffic analysis; encryption and COMSEC with traffic-flow security are the controls that deny the captured uplink its intelligence value.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security measures (link encryption, perimeter monitoring at ground stations, signal-protection treatment in mission planning) are the obligations under which the entity reduces uplink-intercept utility.

ENISA controls

  • Communications Security governs uplink communications and is relevant to REC-0005.01 domain, but the cited excerpt concerns identifying and rejecting imitative or manipulative deception and does not actively counter passive uplink interception, so addresses rather than mitigates.

  • Encryption on the uplink/downlink to prevent eavesdropping is mandated under cryptography and key management.

  • Cryptographic bidirectional authentication on TT&C sessions limits the value of captured uplink framing for an adversary attempting to impersonate the ground.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0005.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.