Master Contextualized Threat Modeling.
“The adversary suffers when every strike they imagine is already prepared for.”
Yesterday Theo Lindgren and Dana Whitfield reconciled Satellite Operations and Satellite Design & Engineering into one Kestrel Orbital CONOPS of forty-four enumerated elements. Today Maya Reyes brings the Security Operations Center threat picture, and you enumerate threats across the kinetic, cyber, electronic-warfare, and naturally occurring domains against those same elements: today's intelligence grounds three cyber threats and one electronic-warfare threat, and the other domains wait until a source confirms a target on this platform. The catalogue feeds the risk analysis NIS2 Article 21(2)(a) requires, on the command-and-control scope Executive Order 14144 protects.
DAY 2 START
Today you work with Maya Reyes, analyst lead in the Security Operations Center. She has been tracking these actors for a year and has never been able to say which parts of the platform they would land on. You can, because yesterday gave her forty-four enumerated elements to aim at. Together you enumerate real adversary threats against those elements, so each threat’s Target of Exploitation (TOE) names the exact part of the command path it would target. This is contextualized threat modeling: the Security Operations Center records its findings in the same data model the three departments built yesterday, and that data model gains its first Analytic Layer elements. The resulting threat catalogue feeds the risk analysis the NIS2 Directive requires under Article 21(2)(a), across the command-and-control scope Executive Order 14144 protects.
Set the context
Before you enumerate a single threat, fix what Day 1 handed you and what today asks: the 44-element CONOPS you build on, the mandates that put the telecommand path in scope, and the five intel sources your threats must cite.
THREAT INTEL COMES FROM A RANGE OF SOURCES
Day 2 opens in the Security Operations Center, and this time the department is presenting, not being sold. Its analysts brief the room, Satellite Operations and Satellite Design & Engineering included, on the kinds of sources threat intelligence lands from. Click a source for how you cite it; today’s working source is highlighted.
A THREAT RESEARCH PAPER HAS ARRIVED
Today’s working source is in the room. Walk the three panels: what arrived, how to read it with the departments, and what else is coming before you enumerate. Click a panel for the full brief.
A credible peer-reviewed research report on command-and-control threats, prepared against the platform you defend. It walks the three operational enclaves (Space, Link, Ground), names the potential attacks each one currently faces, and lists the platform subsystems each attack would touch. Open the report before going further.
CHECKPOINT
Five questions on what Day 1 handed you and today’s job: the CONOPS you build on, the mandates in scope, and the five intel sources. Answer to confirm the context before you learn the method.
Learn the method
One repeatable way to turn intelligence into an enumerated threat: the six-step AN-THR enumeration, every threat’s Target of Exploitation (TOE) naming the exact element it targets.
CONTEXTUALIZED THREAT MODELING PROCESS
Day 1 gave you the root: a taxonomy that names every part, an ontology that binds each part to its parent. That is what enrichment can finally attach to. A threat stops being a document about the platform and becomes an element bound to a named piece of it, and because the taxonomy is published, your MISP instance and any threat intel platform that imports it already read it, out to the Space ISAC exchange. Six steps, fixed order, one walk per threat. The ORDINAL opens the chain Days 3 to 5 carry; the TOE names the one element it anchors to. A threat that cannot name an element waits outside the catalogue, on the record.
Fixed at AN. The layer answers one question before any other: is this a part of the platform, or something you concluded about it? Threats are conclusions, so they live in the Analytic Layer, never among the structural elements they point at.
Yesterday you wrote 44 structural elements. Today you write findings about them. Setting the layer first is what keeps a threat from being mistaken for a thing the platform owns.
CHECKPOINT
Five questions on contextualized threat modeling: what an AN-THR element is, how its TOE names the element it targets, and the enumeration steps. Answer to confirm the method before you read the threat set.
Enumerate the threats
Review the set the room enumerated segment by segment, Ground through Space: four AN-THR elements, each written against the elements it targets, in one shared form. Day 1 walked the platform from orbit down; the enumeration ran from the ground up, where the report lands its heaviest findings. The room did the enumerating; your pass is to read each element against the six steps and confirm it would survive review.
THREATS ENUMERATED · 4 ELEMENTS
The Day-2 threat catalogue against yesterday’s 44-element CONOPS: Ground (2), Link (1), Space (1). Every TOE names exactly one element from the CONOPS, and that element is what the rest of the chain will name. The ordinals 00, 01, 02, 03 come from the SOC’s running threat register, one sequence across every threat the organization tracks, so the scoped set is legitimately non-consecutive.
GroundAN:THR:Threat:00
GroundAN:THR:Threat:01
LinkAN:THR:Threat:02
SpaceAN:THR:Threat:03CHECKPOINT
Five questions on the set you built: the four threats, how they target the platform, who reads them, and what Day 3 does next. Answer to confirm the catalogue before you present it.
THE THREAT CATALOGUE
THEORY TO TOOLING
What you built today does not stay in the classroom. The METEORSTORM taxonomy is published openly, and the moment the shift ends your work ships as machine tags the whole community can read.
TAG THE THREATS
Yesterday this was a paragraph in an email. Today it is a record another operator can act on without asking you a question. METEORSTORM is what changed: four threats, each anchored to a named element, each carrying tags a machine reads. Click a step to see what each part buys you.
SVC:CP:Control Plane:09, the ground service that decides who may command, so “the ground station” becomes one service with one owner. Yesterday’s decomposition is what gave you something to point at, and every record you write this week points at it the same way.DAY 2 HAND-OFF
You enumerated 4 threats against the platform with Maya Reyes and the Security Operations Center, every one’s TOE naming the one element it targets, and every ordinal opening a chain the rest of the week carries. Maya hands the catalogue on tonight. Tomorrow you take it to Dana Whitfield, who built the paths those threats would travel, and Day 3 walks each threat into the attack paths and the sources that reveal it.
DAY 2 COMPLETE
- Four
AN-THRelements against the telecommand path, every one with a TOE naming exactly one element from yesterday’s decomposition, and every ordinal opening a chain Days 3, 4 and 5 will carry. 2 GROUND, 1 LINK, 1 SPACE. No free-floating threats; nothing in the set that the platform isn’t actually exposed to. The enumerated set feeds the risk analysis NIS2 Article 21(2)(a) requires for the command-and-control scope Executive Order 14144 protects. - One shared threat picture: Maya Reyes in Security Operations, Theo Lindgren in Satellite Operations, and Dana Whitfield in Satellite Design & Engineering all act on the same enumerated set, in one shared form, with no re-translation.
- You now have your first enumerated threat set. Take the end-of-module exam (10 questions, 90% to pass) to qualify. Tomorrow: Day 3 / Module 03 (Converged Detection Engineering) walks each TOE into the attack paths and detections that catch them.

CONVERGED DETECTION
ENGINEERING.
Day 2 is complete: four threats enumerated against the decomposition, the documented risk basis the mandates expect. Tomorrow, Converged Detection Engineering: you enumerate the attack paths each AN-THR enables and inventory the data needed to detect each step.
Threats stopped being abstract. Each one now names the element it attacks, so the team can rank real risk and the next function can trace how each attack would actually unfold.
