Skip to content
safemode.space
All techniques
IMP-0007
ST0009Impact

Native Functionality Abuse

Description

Native Functionality Abuse is the deliberate use or triggering of functionality that already exists within a spacecraft architecture. An adversary may invoke the function directly or create conditions that cause it to activate. The function may operate exactly as designed, but the adversary uses it for an unauthorized or harmful purpose. This mechanism includes platform, payload, autonomous, and mission-specific capabilities. It also includes custom flight software functions. The adversary may misuse a function by activating it at the wrong time, repeating it, interrupting it, or directing it toward an unintended purpose.
VectorIllustrative Application
CollectIf the objective is Collect, an adversary could invoke native diagnostic, memory-dump, sensing, or data-export functionality to obtain information outside authorized mission operations.
PivotIf the objective is Pivot, an adversary could use native crosslink, relay, or routing functionality to route activity through the spacecraft toward another connected asset or trust domain.
SubvertTIf the objective is Subvert, an adversary could deliberately trigger legitimate fault-response or diagnostic functions to disrupt mission operations and divert defenders from other adversary activity.
SeizeIf the objective is Seize, an adversary could use native command and mission-tasking functionality to assume control of a payload or spacecraft capability and repurpose it for unauthorized operations.
DisableIf the objective is Disable, an adversary could use legitimate pointing functionality to expose a mission-critical sensor to the Sun beyond acceptable limits, leaving the spacecraft unable to conduct its intended mission or an essential mission function.

Reproduced verbatim from SPARTA v4.0, including its own citation markers, spelling and formatting. Nothing in the text above is SafeMode Space's wording, and nothing has been corrected.

Mappings

No mappings have been made here yet. That is a statement about this corpus, not about the law: it means curation has not reached this entity, not that nothing applies to it.

No ruling has been recorded either way.

Cite as SafeMode Space, IMP-0007 (SPARTA v4.0), https://safemode.space/reference/techniques/imp-0007, accessed YYYY-MM-DD. Replace YYYY-MM-DD with the date you read the page; the corpus is curated continuously, so mappings can change between readings. To cite one mapping rather than this page, append its anchor to the URL — every mapping row has an id of the form technique--collection--target, the same on every page that lists it. See how to cite. Sources and licence: sources and attribution. A mapping on this page is interpretive analysis of how a technique and a provision relate, not a statement of law and not compliance guidance. Read the disclaimer.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.