01
A mission lead pointing at a wall situational display while two operators in headsets execute commands at adjacent consoles during an active incident response
MISSION FIVE · CAPSTONERESPOND
Mission Five · Capstone
RESPOND.
“Containment first. Recovery second. Adaptation third. In that order.”

The incident is confirmed and the clock is on. Mission Five is scored on the order you work in, contain then recover then adapt, on a spacecraft that is already degraded.

MODULE TEN
01/07
02
Brief

BRIEF THE MISSION

Mission Five reflies Mission Four: same orbit, same run, same five stations, same adversary. Two things differ. The incident is already confirmed, so you are acting rather than deciding whether to act. And the reaction wheel that came back to nominal in Mission Four is stuck from the first second here and never recovers, so you run the entire response on a degraded vehicle.

▷ Scenario
Orbit regime
Medium Earth orbit, circular
Altitude
About 2,222 km
Inclination
70 degrees
Run
4800 seconds at 2.0x
Ground stations
Tokyo, Anchorage, Houston, Lima, Santiago
Scripted events
Yes, events will fire
▷ Your objective

Respond and recover on confirmed adversary activity.

MODULE TEN
02/07
03
Mission Five · what each role does to respond

HOW YOU RESPOND

This is Mission Four's flight with the incident already confirmed, so you are acting rather than deciding whether to act. The order is a dependency, not a preference: contain, then recover, then adapt. Restore into a path the adversary still holds and you have handed it back. Click a role to see what it holds this mission.

▷ MISSION LEAD

You scope it, and you authorize every move.

Focus: scope, sequence, authorize.
  • · Scope the confirmed incident: name which data and which interfaces are in, and which stay out
  • · Lead every report with the same three numbers, so the reader has state, time and load in one line
  • · Hold the contain, recover, adapt order and authorize each action in it
  • · Close with the one-line lesson: alert is not incident, triage first, then act per the playbook
A mission lead standing at a supervisory console directing the team, with overview screens behind
UNDER PRESSURE · The lead names the action, the operator repeats it back, executes, and reports complete. Every action is authorized, including the correct ones.
MODULE TEN
03/07
04
Method

CONTAIN, RECOVER, ADAPT

The order is not a preference, it is a dependency. Restore before you contain and you restore into the adversary's hands. Skip the adapt step and you will run this same mission again with the same result. Click a step for the reasoning behind it.

▷ The response, gate by gate
Name what is in, and defend what is out.

Scope is a boundary, and a boundary that expands to cover everything is not a boundary. Include the data the adversary touched and the interfaces they reached; leave out the subsystems that carried no adversary activity, even when they had a bad day at the same time. Scope that is too wide cannot be closed, because every clean subsystem inside it still has to be cleared before anyone can declare the incident over.

MODULE TEN
04/07
05
Simulate

FLY THE MISSION IN ZENDIR

Zendir, the digital twin and mission simulation platform Kestrel procured, replicates your satellite operations center. Everything you rehearsed here you now do for real inside it: one mission objective and ten scored questions. The ten questions land on the response gates you just walked. Run it in three steps: take your assigned consoles, fly the one objective and answer the ten questions in platform where they are scored, then note the score and come back here for the debrief. Your facilitator provides Zendir access, and two things must be true before you fly.

▷ Before you fly · your attestation
▸ Attest to both before you fly
▷ Scored in Zendir

This mission is worth 100 points, scored in-platform. Points accumulate across Missions One through Five, and the highest cumulative team finishes as the Top SCOR Team.

▷ Stations ready
MODULE TEN
05/07
06
Return

NOW THAT YOU ARE BACK

Zendir scored your mission out of 100 toward the Top SCOR Team standings. Note where you landed, then run the debrief while it is fresh. Work these three questions in order; the last one is the one that becomes an engineering update in the quarterly SCOR exercise. This is the capstone debrief: run the three questions across all five missions, not just this run.

▷ Debrief · 01
What did the platform show you that the deck did not?
The gap between rehearsal and a live console is where the real learning sits.
▷ How to run it

Go around the crew once, one observation each, no discussion until everyone has spoken. Write the observations down before debating them; the first answer is usually the honest one.

MODULE TEN
06/07
END
COURSECOMPLETEFULL SPECTRUM · SPACE CYBER PROFESSIONAL
Mission Five complete · the course is yours

COURSE COMPLETE.

You began without a shared vocabulary. Across five missions you flew and were scored on the full cycle: orient, assign, brief, triage, and respond. The Pentagon of Pain mindset that framed the enumeration week is what these missions drilled into crew habit.

More than that, the shared vocabulary you have worked in since the first module is a deployed Malware Information Sharing Platform (MISP) taxonomy: the three departments deployed it and used it to tag the week’s enumerations in Modules 1 to 5, and it matches the information-sharing posture of the Space Information Sharing and Analysis Center. Space collective defense is not waiting on more training, it is waiting on more participating teams, and you are one. Remember the role: you do not have to be the expert in every console or signature. Security Operations, Satellite Operations, and Satellite Design & Engineering may come from different organizations, and the Full Spectrum professional is the one who builds the cross-functional team across them and gives it one shared language.

WHAT TO DO NEXT
Take the after-action’s adaptation back to the team that runs your real platform and make the one change it names. Then share whatever finding your team is permitted to share, through Space-ISAC.
MODULE TEN
07/07
REFERENCE LIBRARY

Standards, Policies & Sources

The instruments this course aligns to. Each element links to its primary source.

U.S. National Security Space Policy

CNSS Policy No. 12 (CNSSP-12)Information-assurance policy for national security space systems.CNSS Instruction 1200 (CNSSI 1200), Aug 2025Implementing requirements: on-board intrusion detection, hardware root-of-trust, patch management.DoDI 8581.01Information-assurance policy for space systems used by the DoD.Space Policy Directive 5 (SPD-5), 2020First comprehensive U.S. cybersecurity principles for space systems.

Executive Orders

EO 14144 (Jan 16, 2025)Strengthening and Promoting Innovation in the Nation’s Cybersecurity.EO 14306 (Jun 6, 2025)Sustaining select efforts, amending EO 13694 and EO 14144.

NIST Standards & FISMA

NIST SP 800-53 Rev. 5Security and privacy controls; IR-3 incident-response testing.NIST SP 800-37 Rev. 2Risk Management Framework; continuous monitoring and annual control assessment.NIST IR 8270Introduction to Cybersecurity for Commercial Satellite Operations.NIST IR 8401Satellite Ground Segment cybersecurity framework profile.NIST IR 8441Cybersecurity Framework Profile for Hybrid Satellite Networks.NIST SP 800-160 Vol. 2 Rev. 1Cyber resiliency goals: Anticipate, Withstand, Recover, Adapt.FISMAFederal Information Security Modernization Act; annual program review obligation.

Threat Frameworks (analytic layer)

MITRE ATT&CKAdversary tactics and techniques knowledge base.MITRE CAPECCommon Attack Pattern Enumeration and Classification; dictionary of attack patterns that exploit known weaknesses.MITRE D3FENDKnowledge graph of defensive countermeasures and techniques, mapped to ATT&CK (NSA-funded, maintained by MITRE).SPARTASpace Attack Research and Tactic Analysis (The Aerospace Corporation).ESA Space ShieldEuropean Space Agency space-system threat framework.

EU & Global

NIS2 Directive (EU 2022/2555)Risk management and 24h/72h incident reporting; space sector in scope.EU Space Act (proposal, 25 Jun 2025)Space-specific resilience and cybersecurity obligations; extraterritorial scope.ENISA Space Threat LandscapeEuropean threat landscape and recommendations for space operators.Cyber Resilience Act (CRA)Connected hardware/software requirements; applies from December 2027.

Open-Source Vocabulary & Tooling

METEORSTORM MISP taxonomyThe course vocabulary, live and open source in the MISP taxonomy repository.MISP / CIRCLComputer Incident Response Center Luxembourg, maintainers of MISP.RootAPublic-domain open detection language (YAML) used in Module 04 to write portable signatures. (github.com/UncoderIO/Roota)Uncoder.IOOpen-source IDE and translation engine that ports RootA rules across SIEM, EDR, and XDR formats.SpaceCOP & Indicators of BehaviorDHS S&T + Aerospace Corp. on-board intrusion-detection prototype.CROO (Cyber Resilience On-Orbit)Proof Labs on-board IDS for the Space Force.

Community & Reporting

Space ISACSpace Information Sharing and Analysis Center.Air & Space Forces MagazineWaterman, “New Cybersecurity Rules for Pentagon’s Commercial Satellite Vendors,” Nov 19, 2025.Via Satellite“DHS Wants Satellite Volunteers to Test New Cyber Tools,” Nov 17, 2025.Defense Daily“New National Space Cybersecurity Policy Emphasizes Intrusion Detection,” Nov 18, 2025.Mayer Brown legal analysis“Securing the Final Frontier,” Dec 11, 2025 (US and EU regulatory map).