ethicallyHackingspace
UTC
Full Spectrum Space Cybersecurity Professional

YOU'VE BEEN HIRED.

Your first morning on the job: at the Kestrel Orbital security gate at sunrise, you present your photo ID badge to the security officer at the gatehouse window. The gatehouse sign carries the Kestrel Orbital falcon-and-orbit emblem, and behind the fence line the campus holds large parabolic satellite antennas and a geodesic radome in morning haze.

You are joining Kestrel Orbital to establish the Space Cybersecurity Operations and Resilience (SCOR) department, driving organizational transformation through the Pentagon of Pain mindset, equipped with the METEORSTORM Resilient Cyber Operations (RCO) Framework: five functions running on one machine-readable data model, where every threat, attack path, detection, and resilience measure normalizes into standardized enumerated elements. MITRE ATT&CK, SPARTA, D3FEND, NIST and the rest stop being a dozen disconnected catalogues, because each one enters as enumerated elements anchored to your own platform. What accumulates is the analytics catalog, your own intelligence and normalized peer-framework content in one lens, curated once and portable everywhere, including machine to machine with the Space Information Sharing and Analysis Center. Your department will bridge the Security Operations Center, the Satellite Operations Center, and Satellite Design & Engineering for Resilient Cyber Operations.

The analytic layer

The Analytics Catalog

The catalog is what the layer produces: the running collection of analytic elements that results from enumerating your own intelligence and normalizing peer-framework content into the six analytic elements, expressed in one nomenclature and anchored to the structural decomposition of the platform you defend. It is not a separate product. It is what an organization ends up with after applying the method consistently. METEORSTORM does not replace the frameworks below. It gives you a way to normalize a fluid and broad range of reference frameworks into one reliable lens, so every framework contributes to the same catalog without forcing its vocabulary on the others.

Different source types feed different elements. The codes in the FEEDS column are recommendations, not restrictions: they name the elements each source most naturally supplies. Threat-intelligence feeds carrying observations from real incidents feed the two indicators, and an indicator entry is never drawn from an architectural framework, because an indicator cannot be theoretical. Adversary-behavior catalogues feed Attack Path and Threat. Control and defensive-technique frameworks feed Detection Signature and Resilience Measure.

FrameworkPublisherFeeds
Trusted threat-intelligence feeds (Space ISAC Exchange, vendor and government reporting, own telemetry)VariousIOC · IOA · ATT · THR · DET · RES
MITRE ATT&CKThe MITRE CorporationATT · THR · RES
MITRE FiGHTThe MITRE Corporation with the U.S. DoD 5G Cross-Functional TeamATT · THR · RES
MITRE ATLASThe MITRE CorporationATT · THR · RES
MITRE CAPECThe MITRE CorporationATT
Aerospace SPARTAThe Aerospace CorporationATT · THR · DET · RES
ESA SPACE-SHIELDEuropean Space AgencyATT · THR · RES
MITRE EMB3DThe MITRE CorporationATT · THR · RES
MITRE D3FENDThe MITRE Corporation, funded by the NSADET · RES
CSA AI Controls MatrixCloud Security AllianceRES
CSA Cloud Controls MatrixCloud Security AllianceRES
CSA Shared Security Responsibility ModelCloud Security AllianceRES
NIST SP 800-160 Volumes 1 and 2National Institute of Standards and TechnologyRES
NIST SP 800-53National Institute of Standards and TechnologyRES

IOC indicator of compromise, IOA indicator of attack, ATT attack path, THR threat, DET detection signature, RES resilience measure. Full definitions and worked examples: analytic TEN reference.

You will build the organizational foundation for resilient cyber operations by implementing:

You will apply the five functions to:

In parallel, you will drive the Pentagon of Pain mindset across Kestrel Orbital. Most security programs measure themselves by what they have installed. This one measures itself by what the adversary has to spend.

Nobody here thinks that way yet. Maya Reyes, analyst lead in the Security Operations Center, has tracked the actors who target operators like this one for a year, and cannot say which part of the platform any of them would land on. Theo Lindgren, senior controller in the Satellite Operations Center, flies the spacecraft every pass and files interference as weather, because there has never been an element to file it against. Dana Whitfield, systems engineer in Satellite Design & Engineering, owns the flight software update path and has never once been asked to see it as a road an adversary would ride. Three good people, three partial views, and an attacker who only has to find the space between them.

The Pentagon names five areas where mastery provably raises an attacker’s cost, complexity, and risk. Each one falls to a different day of your week, and each of those three carries two of the five, with Day 1 shared between Theo and Dana. By the end of the week all three will be asking the question none of them asks today: what did that just cost the people trying to get in?

Your mission extends beyond producing technical artifacts. You will help Kestrel Orbital operate as one resilient organization and become a harder target, the organization’s contribution to the space community’s collective defense.

The mindset

The Pentagon of Pain

Five areas of mastery: the lens you hold over the five functions, each naming what a day of your week takes away from the attacker. Three carry their day’s function name outright; Decomposition is the mastery behind Day 1’s Concept of Operations, and Exposure Management is the mastery Day 4’s detection and playbook work builds toward, the traps at the end of every path. Budget scatters across checkboxes; the adversary only needs one path. These five close the paths.

  1. 01
    Master Decomposition
    “The adversary suffers when you know your platform better than they ever can.”
    Day 1 · Theo Lindgren, Satellite Operations, and Dana Whitfield, Satellite Design & Engineering
  2. 02
    Master Contextualized Threat Modeling
    “The adversary suffers when every strike they imagine is already prepared for.”
    Day 2 · Maya Reyes, Security Operations
  3. 03
    Master Converged Detection Engineering
    “The adversary suffers when they cannot hide, and every move is seen.”
    Day 3 · Dana Whitfield, Satellite Design & Engineering
  4. 04
    Master Exposure Management
    “The adversary suffers when every path they take ends in a trap.”
    Day 4 · Maya Reyes, Security Operations
  5. 05
    Master Adversary Management
    “The adversary suffers when their plans are known, broken, and turned against them.”
    Day 5 · Theo Lindgren, Satellite Operations

You will not build the department alone. Each of the three departments has given you one contact, and those three work every function beside you, from the decomposition on Day 1 to the response on your last day.

Maya Reyes, analyst lead in the Kestrel Orbital Security Operations Center, at her workstation.
Security OperationsMaya ReyesAnalyst Lead, Security Operations CenterWith Maya you build the threat catalogue and the detection signatures that fire on it. She brings the intelligence; you both anchor it to elements the platform can name.
Theo Lindgren, senior controller in the Kestrel Orbital Satellite Operations Center, at his console.
Satellite OperationsTheo LindgrenSenior Controller, Satellite Operations CenterWith Theo you build the concept of operations and the resilience measures that survive contact with a live pass. He flies the platform every day and knows what it does under load.
Dana Whitfield, systems engineer in Kestrel Orbital Satellite Design and Engineering, at her workbench.
Satellite Design & EngineeringDana WhitfieldSystems Engineer, Satellite Design & EngineeringWith Dana you build the platform decomposition and the attack paths through it. She owns the flight software and the update path an adversary would target.

Before day one, you sit through orientation: how the team thinks, why space is no longer a sanctuary, and the shared language that holds the rest of the work together.

Begin Orientation · METEORSTORM Overview

Your first five days on the job. One function each day, in order, applying the METEORSTORM cyber resilience framework end to end on the platform. Each function's deliverable supports the organization's work to meet Executive Order 14144 and the NIS2 Directive, and the taxonomy you stand up on Day 1 is what the Space ISAC sharing mandate exchanges.

▷ The organization checks your readiness

Before the organization puts you on the floor, it verifies your command of the framework. Twenty-five questions, drawn at random across the five functions you just applied. This is the only written exam in the course; the five missions ahead are scored in the simulation platform. Score 80% or better to pass. Retakes are unlimited and your best score stands. Your results include a topic breakdown and a question-by-question review showing exactly what to revisit.

Sit Your Final Exam
Finish Day 5 to unlock

With the digital twin deployed, you run five exercises against a simulation of the platform you defend, one mission each day, from standing up the team to running a full incident response. Each mission builds the organizational reflexes the mandates demand: detect, report, and recover as Executive Order 14144 requires, within the deadlines the NIS2 Directive sets.