Crosslink Channel Operating Without Encryption

Monitors crosslink channels for unencrypted data exchanges that could indicate improper configuration or security degradation. Typically the crosslinks are encrypted and an adversary may attempt to put crosslink into clear mode to further attacks.

STIX Pattern

[network-traffic:src_ref.value = 'crosslink' AND network-traffic:encryption_status != 'encrypted']

SPARTA TTPs

ID Name Description
IA-0003 Crosslink via Compromised Neighbor Threat actors may compromise a victim spacecraft via the crosslink communications of a neighboring spacecraft that has been compromised. spacecraft in close proximity are able to send commands back and forth. Threat actors may be able to leverage this access to compromise other spacecraft once they have access to another that is nearby.
LM-0003 Constellation Hopping via Crosslink Threat actors may attempt to command another neighboring spacecraft via crosslink. spacecraft in close proximity are often able to send commands back and forth. Threat actors may be able to leverage this access to compromise another spacecraft.