| IMP-0001 |
[DEPRECATED] Deception (or Misdirection) |
Measures designed to mislead an adversary by manipulation, distortion, or falsification of evidence or information into a system to induce the adversary to react in a manner prejudicial to their interests. Threat actors may seek to deceive mission stakeholders (or even military decision makers) for a multitude of reasons. Telemetry values could be modified, attacks could be designed to intentionally mimic another threat actor's TTPs, and even allied ground infrastructure could be compromised and used as the source of communications to the spacecraft. |
| IMP-0002 |
[DEPRECATED] Disruption |
Measures designed to temporarily impair the use or access to a system for a period of time. Threat actors may seek to disrupt communications from the victim spacecraft to the ground controllers or other interested parties. By disrupting communications during critical times, there is the potential impact of data being lost or critical actions not being performed. This could cause the spacecraft's purpose to be put into jeopardy depending on what communications were lost during the disruption. This behavior is different than Denial as this attack can also attempt to modify the data and messages as they are passed as a way to disrupt communications. |
| IMP-0003 |
[DEPRECATED] Denial |
Measures designed to temporarily eliminate the use, access, or operation of a system for a period of time, usually without physical damage to the affected system. Threat actors may seek to deny ground controllers and other interested parties access to the victim spacecraft. This would be done exhausting system resource, degrading subsystems, or blocking communications entirely. This behavior is different from Disruption as this seeks to deny communications entirely, rather than stop them for a length of time. |
| IMP-0004 |
[DEPRECATED] Degradation |
Measures designed to permanently impair (either partially or totally) the use of a system. Threat actors may target various subsystems or the hosted payload in such a way to rapidly increase it's degradation. This could potentially shorten the lifespan of the victim spacecraft. |
| IMP-0005 |
[DEPRECATED] Destruction |
Measures designed to permanently eliminate the use of a system, potentially through some physical damage to the system. Threat actors may destroy data, commands, subsystems, or attempt to destroy the victim spacecraft itself. This behavior is different from Degradation, as the individual parts are destroyed rather than put in a position in which they would slowly degrade over time. |
| IMP-0006 |
[DEPRECATED] Theft |
Threat actors may attempt to steal the data that is being gathered, processed, and sent from the victim spacecraft. Many spacecraft have a particular purpose associated with them and the data they gather is deemed mission critical. By attempting to steal this data, the mission, or purpose, of the spacecraft could be lost entirely. |
| IMP-0007 |
Native Functionality Abuse |
Native Functionality Abuse is the deliberate use or triggering of functionality that already exists within a spacecraft architecture. An adversary may invoke the function directly or create conditions that cause it to activate. The function may operate exactly as designed, but the adversary uses it for an unauthorized or harmful purpose. This mechanism includes platform, payload, autonomous, and mission-specific capabilities. It also includes custom flight software functions. The adversary may misuse a function by activating it at the wrong time, repeating it, interrupting it, or directing it toward an unintended purpose.
| Vector | Illustrative Application |
| Collect | If the objective is Collect, an adversary could invoke native diagnostic, memory-dump, sensing, or data-export functionality to obtain information outside authorized mission operations. |
| Pivot | If the objective is Pivot, an adversary could use native crosslink, relay, or routing functionality to route activity through the spacecraft toward another connected asset or trust domain. |
| Subvert | TIf the objective is Subvert, an adversary could deliberately trigger legitimate fault-response or diagnostic functions to disrupt mission operations and divert defenders from other adversary activity. |
| Seize | If the objective is Seize, an adversary could use native command and mission-tasking functionality to assume control of a payload or spacecraft capability and repurpose it for unauthorized operations. |
| Disable | If the objective is Disable, an adversary could use legitimate pointing functionality to expose a mission-critical sensor to the Sun beyond acceptable limits, leaving the spacecraft unable to conduct its intended mission or an essential mission function. |
|
| IMP-0008 |
State or Mode Manipulation |
State or Mode Manipulation is the deliberate alteration of a spacecraft’s operational state, mode, or mission phase. An adversary may force an unauthorized transition, prevent an expected transition, or hold the system in a selected state. This mechanism may affect the spacecraft as a whole or a specific subsystem, payload, software service, or mission function. It applies when the actual operating condition changes. Falsifying only the reported state is instead Data Manipulation.
| Vector | Illustrative Application |
| Collect | If the objective is Collect, an adversary could place the spacecraft or payload into a diagnostic mode that exposes protected engineering data or internal system information. |
| Pivot | If the objective is Pivot, an adversary could force a communications subsystem into a relay or bridging mode that provides access to another connected asset or trust domain. |
| Subvert | TIf the objective is Subvert, an adversary could force repeated transitions into safe mode to interrupt mission operations and draw defenders toward an apparent spacecraft fault. |
| Seize | If the objective is Seize, an adversary could place the spacecraft into a maintenance, bypass, or manual-control mode that permits unauthorized tasking of a payload or mission function. |
| Disable | If the objective is Disable, an adversary could hold the spacecraft in a non-mission mode that prevents it from performing its intended mission or an essential mission function. |
|
| IMP-0009 |
Configuration Manipulation |
Configuration Manipulation is the deliberate alteration of authoritative, non-executable settings or structured artifacts that govern spacecraft behavior. These settings may define thresholds, limits, gains, access rules, routing behavior, schedules, or operating profiles. The existing software, firmware, or programmable logic remains intact. It interprets the altered configuration and operates under the new conditions. This mechanism applies to both operator-managed settings and internal values that are not normally changed during routine operations. It does not include changes to measured or derived information, which fall under Data Manipulation. It also does not include changes to executable code or programmed hardware behavior.
| Vector | Illustrative Application |
| Collect | If the objective is Collect, an adversary could alter access-control or data-handling settings to expose protected engineering or mission information. |
| Pivot | If the objective is Pivot, an adversary could alter routing or interface configuration to create a path into another connected asset or trust domain. |
| Subvert | TIf the objective is Subvert, an adversary could lower fault thresholds so normal conditions trigger repeated recovery actions and disrupt mission operations. |
| Seize | If the objective is Seize, an adversary could alter command-authorization settings to grant unauthorized tasking authority and restrict the legitimate operator. |
| Disable | If the objective is Disable, an adversary could alter startup configuration so mission software no longer loads, leaving the spacecraft unable to perform its intended mission or an essential mission function. |
|
| IMP-0010 |
Data Manipulation |
Data Manipulation is the deliberate alteration of information used or handled by a spacecraft. The affected information may come from onboard sensors, external sources, internal processing, or stored records. An adversary may falsify, suppress, replace, delete, or corrupt this information. This mechanism applies when the information itself changes, whether the data is at rest, in use, or being exchanged. Changing the settings that govern how the system interprets that information is Configuration Manipulation. Changing only how the information moves or arrives is Command and Data Flow Manipulation.
| Vector | Illustrative Application |
| Collect | If the objective is Collect, an adversary could alter data labels or indexes so protected information appears in an authorized query or routine downlink. |
| Pivot | If the objective is Pivot, an adversary could alter data exchanged through a trusted spacecraft interface to carry adversary-controlled content into another connected asset. |
| Subvert | TIf the objective is Subvert, an adversary could falsify sensor or state-estimate data so the spacecraft makes incorrect autonomous decisions. |
| Seize | If the objective is Seize, an adversary could alter command-source or authentication data so onboard systems accept unauthorized tasking as legitimate. |
| Disable | If the objective is Disable, an adversary could corrupt stored attitude or navigation data so the spacecraft cannot maintain mission-required pointing. |
|
| IMP-0011 |
Command and Data Flow Manipulation |
Command and Data Flow Manipulation is the d deliberate alteration of the source, destination, path, delivery, availability, timing, sequence, or duplication of commands or data as they move within, to, or from a spacecraft. An adversary may inject an unauthorized command or alter a legitimate command before execution. The adversary may also prevent traffic from arriving, cause it to arrive at the wrong time or destination, or change its sequence. This mechanism applies to both external communications and internal spacecraft pathways. Passive observation alone does not qualify. Altering command or data content may also constitute Data Manipulation.
| Vector | Illustrative Application |
| Collect | If the objective is Collect, an adversary could duplicate or redirect protected telemetry to an unauthorized destination. |
| Pivot | If the objective is Pivot, an adversary could route activity through spacecraft communication paths to reach another connected asset or trust domain. |
| Subvert | TIf the objective is Subvert, an adversary could delay or reorder commands and telemetry to disrupt operations and mislead defenders. |
| Seize | If the objective is Seize, an adversary could suppress legitimate command traffic while forwarding unauthorized commands to assume control of mission functions. |
| Disable | If the objective is Disable, an adversary could block command or data flows required for the spacecraft to conduct its intended mission or an essential mission function. |
|
| IMP-0012 |
Software, Firmware, or Programmable Logic Manipulation |
Software, Firmware, or Programmable Logic Manipulation is the deliberate alteration of the implementation that controls spacecraft behavior. An adversary may modify executable code, replace firmware, or load altered programmable logic. The change may affect startup, command processing, autonomy, security enforcement, or subsystem control. This mechanism applies when the implementation itself changes. Changing only the settings used by an unchanged implementation is Configuration Manipulation. Changing only the information processed by that implementation is Data Manipulation.
| Vector | Illustrative Application |
| Collect | If the objective is Collect, an adversary could modify onboard software to copy protected engineering or mission data into an accessible store or downlink stream. |
| Pivot | If the objective is Pivot, an adversary could alter communications software or programmable routing logic to pass attacker activity into another connected asset or trust domain. |
| Subvert | TIf the objective is Subvert, an adversary could alter fault-management software to suppress valid faults or generate misleading recovery activity. |
| Seize | If the objective is Seize, an adversary could modify command-authorization software so attacker tasking is accepted while legitimate operator commands are rejected. |
| Disable | If the objective is Disable, an adversary could replace mission software or programmable logic with an altered implementation that prevents an essential mission function from operating. |
|
| IMP-0013 |
Resource Exhaustion or Contention |
Resource Exhaustion or Contention is the deliberate depletion or monopolization of a finite spacecraft resource. Exhaustion reduces the available capacity. Contention prevents legitimate functions from obtaining the resource when needed. The resource may support computing, storage, or communications. It may also support power, thermal control, or physical actuation. Consumables such as propellant are within scope. This mechanism applies even when availability later recovers. Changing resource limits or allocation rules is Configuration Manipulation. Falsifying resource status is Data Manipulation.
| Vector | Illustrative Application |
| Collect | If the objective is Collect, an adversary could gradually consume processing capacity or electrical power to monitor and identify system thresholds, automated responses, and operator procedures. |
| Pivot | If the objective is Pivot, an adversary could deliberately deplete propellant to provoke a close-proximity inspection and create an otherwise unavailable attack path or proximity window for operations against the inspecting spacecraft. |
| Subvert | TIf the objective is Subvert, an adversary could consume processor capacity or electrical power until legitimate mission functions operate below required performance. |
| Seize | If the objective is Seize, an adversary could monopolize command-processing or payload resources to exclude the legitimate operator and reserve the capability for unauthorized use. |
| Disable | If the objective is Disable, an adversary could exhaust propellant or another mission-critical consumable until the spacecraft can no longer perform its intended mission or an essential mission function. |
|
| IMP-0014 |
Timing or Synchronization Manipulation |
Timing or Synchronization Manipulation is the deliberate alteration of a spacecraft’s time reference or synchronization state. An adversary may shift the onboard clock or corrupt a trusted timing source. The adversary may also break the temporal alignment between coordinated functions. This mechanism applies when the system uses an altered sense of time or loses required synchronization. It may affect command validation and scheduled activity. It may also affect navigation, communications, or distributed processing. Delaying traffic without changing the system’s time basis is Command and Data Flow Manipulation. Changing a stored schedule or timing setting is Configuration Manipulation.
| Vector | Illustrative Application |
| Collect | If the objective is Collect, an adversary could introduce controlled clock drift to learn synchronization tolerances and observe when automated or operator responses occur. |
| Pivot | If the objective is Pivot, an adversary could alter onboard time to trigger a scheduled crosslink or communication session with another asset and create an intermediary attack path. |
| Subvert | TIf the objective is Subvert, an adversary could desynchronize sensor inputs and onboard processing so the spacecraft makes decisions from temporally inconsistent information. |
| Seize | If the objective is Seize, an adversary could manipulate system time to invalidate legitimate control sessions and preserve unauthorized access. |
| Disable | If the objective is Disable, an adversary could desynchronize a mission-critical navigation or payload function until the spacecraft can no longer conduct its intended mission or an essential mission function. |
|