Skip to content
safemode.space
All techniques
DE-0003.13
ST0006Defense Evasion
sub-technique

Trusted Process Reporting Suppression

Parent: DE-0003

Description

Adversaries may leverage process injection methods to execute malicious functionality within trusted onboard software processes in order to suppress, delay, filter, or selectively conceal telemetry and operational reporting associated with unauthorized activity. By operating inside legitimate telemetry handlers, flight software tasks, middleware, or operating system services, attackers can interfere with the generation, aggregation, or transmission of monitoring data before it is downlinked or processed by onboard monitoring systems. Unlike direct modification of individual operational values, this technique focuses on manipulating the reporting path itself to prevent malicious activity from being observed, correlated, or reconstructed by operators or autonomy systems. Examples may include suppressing telemetry associated with unauthorized commands, filtering fault events prior to downlink, selectively disabling event reporting during malicious operations, delaying housekeeping updates, or preventing monitoring services from publishing anomalous state information.

Reproduced verbatim from SPARTA v4.0, including its own citation markers, spelling and formatting. Nothing in the text above is SafeMode Space's wording, and nothing has been corrected.

Notional risk (SPARTA)

High criticalitycritical functions, military, intelligence
18 / 25
Medium criticalitycivil, science, weather, commercial
15 / 25
Low criticalityacademic and research
11 / 25

SPARTA scores each technique three times, once per level of system criticality, because a given technique carries different risk to a military satellite than to a research cubesat. Each score runs from 1 to 25 and is the cell of a five-by-five likelihood-and-impact grid, so it is a position on that grid rather than a multiplication; higher means more risk. Scores of 1 to 10 are the low band, 11 to 19 medium, 20 to 25 high. These are the Aerospace Corporation’s assessments, not SafeMode’s, and SPARTA describes its own derivation of them as subjective. See SPARTA’s notional risk scores for its method.

ESA SPACE-SHIELD

These are SPARTA’s cross-references to ESA SPACE-SHIELD, published by the Aerospace Corporation as assertions about ESA’s catalogue rather than by ESA about its own. SafeMode Space has not adjudicated them. Each link goes to this site’s page for the SPACE-SHIELD entry.

CWE references

  • CWE-1384
  • CWE-1390
  • CWE-172
  • CWE-285
  • CWE-287
  • CWE-300
  • CWE-326
  • CWE-327
  • CWE-330
  • CWE-346
  • CWE-362
  • CWE-662
  • CWE-665
  • CWE-311
  • CWE-345
  • CWE-404
  • CWE-684
  • CWE-923
  • CWE-200
  • CWE-666
  • CWE-653
  • CWE-668
  • CWE-922

These are SPARTA’s cross-references to MITRE’s CWE, published by the Aerospace Corporation as assertions about MITRE’s catalogue rather than by MITRE about its own. SafeMode Space does not hold the CWE catalogue, so these values are reproduced as identifiers and are not resolved or linked here.

Aerospace space threats

  • SV-DCO-1
  • SV-IT-2

These are SPARTA’s own space-threat identifiers, from the Space Threats sheet of the Aerospace Corporation’s SPARTA workbook rather than a cross-reference to anyone else. That sheet is held here as a raw file and has never been parsed into a catalogue, so the values are reproduced as SPARTA gives them and are not linked.

Mappings

What relationship, confidence, and evidence mean
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

Disagree with a mapping here? Send a correction. Say which pair and cite the source text you are reading it against; corrections are the fastest way to improve the corpus.

EU regulation articles

No mappings have been made here yet. That is a statement about this corpus, not about the law: it means curation has not reached this entity, not that nothing applies to it.

No ruling has been recorded either way.

Cross-reference controls

No curated control mappings for this technique yet.

98 imported SPARTA cross-references are listed separately. They carry SPARTA's own relationship and confidence values and were not curated by SafeMode Space.

SPARTA countermeasures

These rows carry no relationship type and no confidence level. SPARTA asserts the pairing itself without qualifying it, and SafeMode Space has not adjudicated these edges, so there is no judgement of ours to record on them.

Tier values are SPARTA's ranking of the countermeasure itself, not of its pairing with this technique. SafeMode Space records no rating of how well a countermeasure works against a particular technique, and SPARTA publishes none.

Cite as SafeMode Space, DE-0003.13 (SPARTA v4.0), https://safemode.space/reference/techniques/de-0003-13, accessed YYYY-MM-DD. Replace YYYY-MM-DD with the date you read the page; the corpus is curated continuously, so mappings can change between readings. To cite one mapping rather than this page, append its anchor to the URL — every mapping row has an id of the form technique--collection--target, the same on every page that lists it. See how to cite. Sources and licence: sources and attribution. A mapping on this page is interpretive analysis of how a technique and a provision relate, not a statement of law and not compliance guidance. Read the disclaimer.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.