Configuration Manipulation - IMP-0009
Definition
Configuration Manipulation is the deliberate alteration of authoritative, non-executable settings or structured artifacts that govern spacecraft behavior. These settings may define thresholds, limits, gains, access rules, routing behavior, schedules, or operating profiles. The existing software, firmware, or programmable logic remains intact. It interprets the altered configuration and operates under the new conditions. This mechanism applies to both operator-managed settings and internal values that are not normally changed during routine operations. It does not include changes to measured or derived information, which fall under Data Manipulation. It also does not include changes to executable code or programmed hardware behavior. Vector: Illustrative Application Collect: If the objective is Collect, an adversary could alter access-control or data-handling settings to expose protected engineering or mission information. Pivot: If the objective is Pivot, an adversary could alter routing or interface configuration to create a path into another connected asset or trust domain. Subvert: TIf the objective is Subvert, an adversary could lower fault thresholds so normal conditions trigger repeated recovery actions and disrupt mission operations. Seize: If the objective is Seize, an adversary could alter command-authorization settings to grant unauthorized tasking authority and restrict the legitimate operator. Disable: If the objective is Disable, an adversary could alter startup configuration so mission software no longer loads, leaving the spacecraft unable to perform its intended mission or an essential mission function.
D3FEND Inferred Relationships
There are no artifacts defined on this offensive technique (yet). Please consider contributing an addition to D3FEND.