01
FUNCTION 01FUNCTION 05FUNCTION 04FUNCTION 03CONTEXTUALIZEDTHREAT MODELINGFUNCTION 02
Function Two
CONTEXTUALIZED
THREAT MODELING

Master Contextualized Threat Modeling.

“The adversary suffers when every strike they imagine is already prepared for.”

Yesterday Theo Lindgren and Dana Whitfield reconciled Satellite Operations and Satellite Design & Engineering into one Kestrel Orbital CONOPS of forty-four enumerated elements. Today Maya Reyes brings the Security Operations Center threat picture, and you enumerate threats across the kinetic, cyber, electronic-warfare, and naturally occurring domains against those same elements: today's intelligence grounds three cyber threats and one electronic-warfare threat, and the other domains wait until a source confirms a target on this platform. The catalogue feeds the risk analysis NIS2 Article 21(2)(a) requires, on the command-and-control scope Executive Order 14144 protects.

MODULE TWO
01/18
02
DAY 2

DAY 2 START

Today you work with Maya Reyes, analyst lead in the Security Operations Center. She has been tracking these actors for a year and has never been able to say which parts of the platform they would land on. You can, because yesterday gave her forty-four enumerated elements to aim at. Together you enumerate real adversary threats against those elements, so each threat’s Target of Exploitation (TOE) names the exact part of the command path it would target. This is contextualized threat modeling: the Security Operations Center records its findings in the same data model the three departments built yesterday, and that data model gains its first Analytic Layer elements. The resulting threat catalogue feeds the risk analysis the NIS2 Directive requires under Article 21(2)(a), across the command-and-control scope Executive Order 14144 protects.

MODULE TWO
02/18
03
Learn

Set the context

Before you enumerate a single threat, fix what Day 1 handed you and what today asks: the 44-element CONOPS you build on, the mandates that put the telecommand path in scope, and the five intel sources your threats must cite.

MODULE TWO
03/18
04
Learn

THREAT INTEL COMES FROM A RANGE OF SOURCES

Day 2 opens in the Security Operations Center, and this time the department is presenting, not being sold. Its analysts brief the room, Satellite Operations and Satellite Design & Engineering included, on the kinds of sources threat intelligence lands from. Click a source for how you cite it; today’s working source is highlighted.

MODULE TWO
04/18
05
Learn

A THREAT RESEARCH PAPER HAS ARRIVED

Today’s working source is in the room. Walk the three panels: what arrived, how to read it with the departments, and what else is coming before you enumerate. Click a panel for the full brief.

01WHAT ARRIVED

A credible peer-reviewed research report on command-and-control threats, prepared against the platform you defend. It walks the three operational enclaves (Space, Link, Ground), names the potential attacks each one currently faces, and lists the platform subsystems each attack would touch. Open the report before going further.

MODULE TWO
05/18
06
Day 2

CHECKPOINT

Five questions on what Day 1 handed you and today’s job: the CONOPS you build on, the mandates in scope, and the five intel sources. Answer to confirm the context before you learn the method.

MODULE TWO
06/18
07
Learn

Learn the method

One repeatable way to turn intelligence into an enumerated threat: the six-step AN-THR enumeration, every threat’s Target of Exploitation (TOE) naming the exact element it targets.

MODULE TWO
07/18
08
Learn

CONTEXTUALIZED THREAT MODELING PROCESS

Day 1 gave you the root: a taxonomy that names every part, an ontology that binds each part to its parent. That is what enrichment can finally attach to. A threat stops being a document about the platform and becomes an element bound to a named piece of it, and because the taxonomy is published, your MISP instance and any threat intel platform that imports it already read it, out to the Space ISAC exchange. Six steps, fixed order, one walk per threat. The ORDINAL opens the chain Days 3 to 5 carry; the TOE names the one element it anchors to. A threat that cannot name an element waits outside the catalogue, on the record.

Click a step for its rule, and what it buys you downstream
↻ repeat per threat until the priority list is covered
▷ The process
STEP 01 OF 06
01Enumerate the LAYER

Fixed at AN. The layer answers one question before any other: is this a part of the platform, or something you concluded about it? Threats are conclusions, so they live in the Analytic Layer, never among the structural elements they point at.

▷ Example from the course

Yesterday you wrote 44 structural elements. Today you write findings about them. Setting the layer first is what keeps a threat from being mistaken for a thing the platform owns.

MODULE TWO
08/18
09
Day 2

CHECKPOINT

Five questions on contextualized threat modeling: what an AN-THR element is, how its TOE names the element it targets, and the enumeration steps. Answer to confirm the method before you read the threat set.

MODULE TWO
09/18
10
Apply

Enumerate the threats

Review the set the room enumerated segment by segment, Ground through Space: four AN-THR elements, each written against the elements it targets, in one shared form. Day 1 walked the platform from orbit down; the enumeration ran from the ground up, where the report lands its heaviest findings. The room did the enumerating; your pass is to read each element against the six steps and confirm it would survive review.

MODULE TWO
10/18
11
Apply

THREATS ENUMERATED · 4 ELEMENTS

The Day-2 threat catalogue against yesterday’s 44-element CONOPS: Ground (2), Link (1), Space (1). Every TOE names exactly one element from the CONOPS, and that element is what the rest of the chain will name. The ordinals 00, 01, 02, 03 come from the SOC’s running threat register, one sequence across every threat the organization tracks, so the scoped set is legitimately non-consecutive.

SATCOM management-network intrusionGround
AN:THR:Threat:00
SATCOM management-network intrusion
state-sponsored actor gains persistent access to the SATCOM management network and abuses the provider-to-customer trust relationship to push a malicious modem update (KA-SAT / AcidRain class: the February 2022 attack that pushed a malicious modem update and disabled tens of thousands of terminals across Europe).
Command-authority compromiseGround
AN:THR:Threat:01
Command-authority compromise
adversary with stolen or coerced command authority issues unauthorized telecommands to the on-orbit satellite.
Jamming campaignLink
AN:THR:Threat:02
Jamming campaign
RF actor sustains noise injection across uplink/downlink bands to deny communications.
Malicious on-orbit firmware updateSpace
AN:THR:Threat:03
Malicious on-orbit firmware update
adversary subverts the flight-software update supply chain and pushes a backdoored firmware update to the operational satellite over the command-and-update path.
Click a threat for its full record: description, TOE targets, acronyms spelled out, and sources
4ETENS
MODULE TWO
11/18
12
Day 2

CHECKPOINT

Five questions on the set you built: the four threats, how they target the platform, who reads them, and what Day 3 does next. Answer to confirm the catalogue before you present it.

MODULE TWO
12/18
13
PRESENT

THE THREAT CATALOGUE

Segments
SPACE
1 threat
▸ expand
LINK
1 threat
▸ expand
GROUND
2 threats
▸ expand
SEG
SEG:SP:Space:00
SEG:LI:Link:00
SEG:GR:Ground:00
PCE
PCE:OR:Orbital:00
PCE:TE:Terrestrial:00
PCE:TE:Terrestrial:01
Every AN-THR threat and the element it targets, on one screen. Click any segment to see its threats; click a card to reveal its ETEN and the SVC and AST elements it targets.
MODULE TWO
13/18
14
Apply

THEORY TO TOOLING

What you built today does not stay in the classroom. The METEORSTORM taxonomy is published openly, and the moment the shift ends your work ships as machine tags the whole community can read.

MODULE TWO
14/18
15
Tag and share

TAG THE THREATS

Yesterday this was a paragraph in an email. Today it is a record another operator can act on without asking you a question. METEORSTORM is what changed: four threats, each anchored to a named element, each carrying tags a machine reads. Click a step to see what each part buys you.

01ANCHOR IT TO AN ELEMENTYou can point at the exact thing that was hit
You can point at the exact thing that was hit. Threat 00 names one element from the Day-1 CONOPS, SVC:CP:Control Plane:09, the ground service that decides who may command, so “the ground station” becomes one service with one owner. Yesterday’s decomposition is what gave you something to point at, and every record you write this week points at it the same way.
MIMISP
MODULE TWO
15/18
16
DAY 2

DAY 2 HAND-OFF

You enumerated 4 threats against the platform with Maya Reyes and the Security Operations Center, every one’s TOE naming the one element it targets, and every ordinal opening a chain the rest of the week carries. Maya hands the catalogue on tonight. Tomorrow you take it to Dana Whitfield, who built the paths those threats would travel, and Day 3 walks each threat into the attack paths and the sources that reveal it.

MODULE TWO
16/18
17
Work role ability confirmation

DAY 2 COMPLETE

  • Four AN-THR elements against the telecommand path, every one with a TOE naming exactly one element from yesterday’s decomposition, and every ordinal opening a chain Days 3, 4 and 5 will carry. 2 GROUND, 1 LINK, 1 SPACE. No free-floating threats; nothing in the set that the platform isn’t actually exposed to. The enumerated set feeds the risk analysis NIS2 Article 21(2)(a) requires for the command-and-control scope Executive Order 14144 protects.
  • One shared threat picture: Maya Reyes in Security Operations, Theo Lindgren in Satellite Operations, and Dana Whitfield in Satellite Design & Engineering all act on the same enumerated set, in one shared form, with no re-translation.
  • You now have your first enumerated threat set. Take the end-of-module exam (10 questions, 90% to pass) to qualify. Tomorrow: Day 3 / Module 03 (Converged Detection Engineering) walks each TOE into the attack paths and detections that catch them.
DAY 2 COMPLETE · THE THREAT PICTURE IS CONTEXTUALIZED
Full Spectrum Space Cybersecurity Professional briefing Security Operations, Satellite Operations, and Satellite Design & Engineering on today’s enumerated threats
Full Spectrum Space Cybersecurity Professional standing in front of a board displaying the METEORSTORM data model with threat indicators overlaid on specific elements, briefing three audiences representing Security Operations, Satellite Operations, and Satellite Design & Engineering. Red threat markers on specific decomposed elements show that the threat picture is grounded in the platform. Dark operations center setting with cyan task lighting on the board and warm amber ambient lighting on the room.
MODULE TWO
17/18
END
CONVERGED DETECTIONENGINEERINGFUNCTION 03
Function TWO complete · Function Three next

CONVERGED DETECTION
ENGINEERING.

Day 2 is complete: four threats enumerated against the decomposition, the documented risk basis the mandates expect. Tomorrow, Converged Detection Engineering: you enumerate the attack paths each AN-THR enables and inventory the data needed to detect each step.

THE REAL PROBLEM
The platform was described, but threats were still talked about in generic terms, tied to nothing specific and impossible to rank or defend.
WHAT METEORSTORM DELIVERED
A mission-specific threat set, every threat naming the exact element it targets, feeding the documented risk basis the mandates require.
THE KEY IMPROVEMENT

Threats stopped being abstract. Each one now names the element it attacks, so the team can rank real risk and the next function can trace how each attack would actually unfold.

END
MODULE TWO
18/18
REFERENCE LIBRARY

Standards, Policies & Sources

The instruments this course aligns to. Each element links to its primary source.

U.S. National Security Space Policy

CNSS Policy No. 12 (CNSSP-12)Information-assurance policy for national security space systems.CNSS Instruction 1200 (CNSSI 1200), Aug 2025Implementing requirements: on-board intrusion detection, hardware root-of-trust, patch management.DoDI 8581.01Information-assurance policy for space systems used by the DoD.Space Policy Directive 5 (SPD-5), 2020First comprehensive U.S. cybersecurity principles for space systems.

Executive Orders

EO 14144 (Jan 16, 2025)Strengthening and Promoting Innovation in the Nation’s Cybersecurity.EO 14306 (Jun 6, 2025)Sustaining select efforts, amending EO 13694 and EO 14144.

NIST Standards & FISMA

NIST SP 800-53 Rev. 5Security and privacy controls; IR-3 incident-response testing.NIST SP 800-37 Rev. 2Risk Management Framework; continuous monitoring and annual control assessment.NIST IR 8270Introduction to Cybersecurity for Commercial Satellite Operations.NIST IR 8401Satellite Ground Segment cybersecurity framework profile.NIST IR 8441Cybersecurity Framework Profile for Hybrid Satellite Networks.NIST SP 800-160 Vol. 2 Rev. 1Cyber resiliency goals: Anticipate, Withstand, Recover, Adapt.FISMAFederal Information Security Modernization Act; annual program review obligation.

Threat Frameworks (analytic layer)

MITRE ATT&CKAdversary tactics and techniques knowledge base.MITRE CAPECCommon Attack Pattern Enumeration and Classification; dictionary of attack patterns that exploit known weaknesses.MITRE D3FENDKnowledge graph of defensive countermeasures and techniques, mapped to ATT&CK (NSA-funded, maintained by MITRE).SPARTASpace Attack Research and Tactic Analysis (The Aerospace Corporation).ESA Space ShieldEuropean Space Agency space-system threat framework.

EU & Global

NIS2 Directive (EU 2022/2555)Risk management and 24h/72h incident reporting; space sector in scope.EU Space Act (proposal, 25 Jun 2025)Space-specific resilience and cybersecurity obligations; extraterritorial scope.ENISA Space Threat LandscapeEuropean threat landscape and recommendations for space operators.Cyber Resilience Act (CRA)Connected hardware/software requirements; applies from December 2027.

Open-Source Vocabulary & Tooling

METEORSTORM MISP taxonomyThe course vocabulary, live and open source in the MISP taxonomy repository.MISP / CIRCLComputer Incident Response Center Luxembourg, maintainers of MISP.RootAPublic-domain open detection language (YAML) used in Module 04 to write portable signatures. (github.com/UncoderIO/Roota)Uncoder.IOOpen-source IDE and translation engine that ports RootA rules across SIEM, EDR, and XDR formats.SpaceCOP & Indicators of BehaviorDHS S&T + Aerospace Corp. on-board intrusion-detection prototype.CROO (Cyber Resilience On-Orbit)Proof Labs on-board IDS for the Space Force.

Community & Reporting

Space ISACSpace Information Sharing and Analysis Center.Air & Space Forces MagazineWaterman, “New Cybersecurity Rules for Pentagon’s Commercial Satellite Vendors,” Nov 19, 2025.Via Satellite“DHS Wants Satellite Volunteers to Test New Cyber Tools,” Nov 17, 2025.Defense Daily“New National Space Cybersecurity Policy Emphasizes Intrusion Detection,” Nov 18, 2025.Mayer Brown legal analysis“Securing the Final Frontier,” Dec 11, 2025 (US and EU regulatory map).