All techniques
REC-0005.02
ST0001Reconnaissance
sub-technique

Downlink Intercept

Parent: REC-0005

Description

Downlink collection aims to harvest housekeeping telemetry, event logs, ephemerides, payload data, and operator annotations that reveal system state and procedures. Even when payload content is encrypted, ancillary channels (beacons, health/status, low-rate engineering downlink) can disclose mode transitions, battery and thermal margins, safing events, and next-pass predictions. Community ground networks and public dashboards may inadvertently provide stitched datasets that make trend analysis trivial. Captured framing and coding parameters also help an adversary build testbeds and refine timing for later actions.

Mappings

EU regulation articles

  • eu-space-actArt. 80(3)
    addresses
    moderate
    inferred

    Art. 80(3)'s information categorization is domain-relevant to downlink eavesdropping (it drives crypto policy), but categorization itself does not interdict the reconnaissance.

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    Downlink eavesdropping captures housekeeping/payload data; 85(1)'s cryptographic concept must cover downlink confidentiality where the operator's risk assessment requires it.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Art. 21(2)(h) obliges cryptography and encryption policies covering the downlink; it addresses downlink intercept by requiring those measures, while the deployed telemetry encryption, not the policy article, is what prevents intercepts from yielding mission state and operator annotations.

  • nis2-implAnnex 12.1.1
    addresses
    moderate
    derived

    Downlink content (housekeeping telemetry, payload products, event logs) is the asset whose classification determines whether downlink intercept exposes mission-critical information; the entity must classify this content so encryption and link-protection decisions are properly calibrated.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations cover the downlink processing chain at the entity's ground stations and require protection of telemetry pipelines from unauthorized observation.

ENISA controls

  • Communications security with confidentiality preservation during transmission directly defeats downlink intercept of housekeeping telemetry and payload data.

  • Traffic flow security on downlinks defeats the metadata-only inferences (mode transitions, safing events) that downlink eavesdropping otherwise yields when payload content is encrypted.

  • Data encryption on payload, telemetry, and bus-payload links is the core defense against downlink intercept yield.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0005.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.