01
FUNCTION 01FUNCTION 02FUNCTION 05FUNCTION 04CONVERGED DETECTIONENGINEERINGFUNCTION 03
Function Three
CONVERGED DETECTION
ENGINEERING

Trace each threat into its attack path, and enumerate the sources that detect it.

“The adversary suffers when they cannot hide, and every move is seen.”

Kestrel Orbital’s three departments share the Day-1 data model and a catalogue of four AN-THR threats. Today Dana Whitfield takes the lead for Satellite Design & Engineering: for every threat you enumerate its attack path as an AN-ATT element, then enumerate the sources needed to observe each step. The paths curate one normalized set of required data and signal sources and produce the attack-path elements and detection methods Executive Order 14144 requires for command and control.

MODULE THREE
01/17
02
DAY 3

DAY 3 START

Today you trace how an adversary would move through the telecommand path to realize each Day 2 threat, and name the data you would need to see each step. Yesterday Maya Reyes grounded the threats; today you work with Dana Whitfield, systems engineer in Satellite Design & Engineering. She wrote the update path an adversary would ride, and she has never had to describe it as an attacker would. Her build knowledge turns each threat into a walkable path, the department’s first full working day inside the shared model. The paths and the required sources they carry feed the detection methods Executive Order 14144 requires.

MODULE THREE
02/17
03
Learn

Set the context

Before you trace a single attack, fix what Day 2 handed you and today's job: the anchored threat set, and the task of showing how an adversary would actually move to realize each one.

MODULE THREE
03/17
04
L1

MAP THE ATTACK PATHS

Six artifacts on the table. Satellite Design & Engineering owns the deepest knowledge of how the platform actually moves data and commands, and today the department lays that knowledge open: the six Kestrel Orbital artifacts below, brought to the table because two days of shared work earned the ask. You walk them together for every attack path you enumerate today; each tells you something different about where an attacker could enter, pivot, and what they would touch.

ARCHITECTURE
▷ ARTIFACT · 01
ARCHITECTURE

System block diagrams: what subsystem connects to what, over which bus, with which authentication boundary.

COMMAND FLOWS
▷ ARTIFACT · 02
COMMAND FLOWS

How a single telecommand actually moves from operator console through C&DH to the receiving subsystem.

DATA FLOWS
▷ ARTIFACT · 03
DATA FLOWS

How mission data moves on-board, where it’s buffered, where it’s signed, where it’s downlinked.

INTERFACE SPECS
▷ ARTIFACT · 04
INTERFACE SPECS

Wire-level protocol specs: CCSDS framing, MIL-STD-1553 bus traffic, SpaceWire, internal handshakes.

FLIGHT SOFTWARE
▷ ARTIFACT · 05
FLIGHT SOFTWARE

What runs on the OBC, how commands are parsed and dispatched, what behaviors are hard-coded vs reconfigurable.

SUPPLY CHAIN
▷ ARTIFACT · 06
SUPPLY CHAIN

Vendor provenance for each firmware and hardware item: who built it, when, with which signing pipeline.

MODULE THREE
04/17
05
Day 3

CHECKPOINT

Five questions on what Day 2 handed you and today’s job: the threat set you build on, the mandate the paths feed, and why Satellite Design & Engineering leads. Answer to confirm the context before you learn the method.

MODULE THREE
05/17
06
Learn

Learn the method

One repeatable way to turn a threat into a route: the AN-ATT enumeration, tracing the elements an adversary crosses from first access to objective, and naming the data that would reveal each step.

MODULE THREE
06/17
07
Apply

CONVERGED DETECTION ENGINEERING PROCESS

What you could not write on Monday: which elements sit between an adversary and the thing they want. You can now, because every one of them is named and parented. Eight steps, fixed order, one walk per path. A path inherits its threat’s TOE as its anchor, one element, so threat, path, signature and measure all name the same thing and one ordinal carries them. Where the route ends is the objective waypoint, and that may be a different element. Steps 07 and 08 are the ones teams drop: they turn “we should have logs” into named sources on named elements, each marked Available, Partial or Gap with an owner, so a missing source becomes a finding instead of a silence.

Click a step for its rule and the action it takes
↻ repeat per path until every threat has a realizable path
▷ The process
STEP 01 OF 08
01Enumerate the LAYER

Fixed at AN. The layer settles one question before any other: is this part of the platform, or something you concluded about it? A path is a conclusion, so it never sits among the structural elements it crosses.

▷ Example from the course

Day 1’s elements are the platform. A path is what the Security Operations Center and engineering concluded about moving through them, which is why it enters the analytic layer and never the decomposition.

MODULE THREE
07/17
08
Day 3

CHECKPOINT

Five questions on converged detection engineering: what an AN-ATT path is, the one element it anchors to, the waypoints that describe the route, and the RDS and RSS required sources the element carries. Answer to confirm the method before you read the path set.

MODULE THREE
08/17
09
Apply

Enumerate the attack paths

Work segment by segment, Ground through Space. Each path anchors to the element its threat already names, traces the route an adversary would take to reach it as waypoints, then states on that same element the data and signal sources a defensive cyber operator must hold to see it.

MODULE THREE
09/17
10
Apply

ATTACK PATHS WALKED · 4 ELEMENTS

One attack path per Day-2 threat, walked with Satellite Design & Engineering. Every path names the entry, pivot, and objective the attacker would cross, anchors to its driving threat’s TOE wherever the route itself ends, and carries on that element the sources a defensive cyber operator must hold: RDS for what arrives as a record, RSS for what is measured in the physical layer.

Mass modem firmware-wipe via management-plane abuseGround
AN:ATT:Attack Path:00
Mass modem firmware-wipe via management-plane abuse
entry
SVC:CP:Control Plane:08
pivot
SVC:CP:Control Plane:09
objective
AST:SW:Software:03
Command-authority compromiseGround
AN:ATT:Attack Path:01
Command-authority compromise
entry
AST:HW:Hardware:04
pivot
AST:SW:Software:04
objective
SVC:CP:Control Plane:13
Sustained RF noise injection across uplink/downlink bandsLink
AN:ATT:Attack Path:02
Sustained RF noise injection across uplink/downlink bands
entry
SVC:HY:Hybrid:01
pivot
SVC:HY:Hybrid:02
objective
AST:SI:Signal:00
Malicious on-orbit firmware updateSpace
AN:ATT:Attack Path:03
Malicious on-orbit firmware update
entry
SVC:CP:Control Plane:04
pivot
SVC:CP:Control Plane:02
objective
AST:FW:Firmware:01
Click a path for its full record: waypoints, the RDS and RSS required sources with their states, driving threat and confidence
4PATHS
MODULE THREE
10/17
11
Day 3

CHECKPOINT

Five questions on the set you built: the four paths, grounded versus hypothesis, coverage gaps, and what Day 4 does next. Answer to confirm the catalogue before you present it.

MODULE THREE
11/17
12
PRESENT

THE ATTACK-PATH CATALOGUE

Segments
SPACE
1 path
▸ expand
LINK
1 path
▸ expand
GROUND
2 paths
▸ expand
SEG
SEG:SP:Space:00
SEG:LI:Link:00
SEG:GR:Ground:00
PCE
PCE:OR:Orbital:00
PCE:TE:Terrestrial:00
PCE:TE:Terrestrial:01
Every AN-ATT attack path on one screen, anchored to the platform it traverses. Click any segment to see its paths; click a card to reveal its ETEN and the waypoints the adversary would cross.
MODULE THREE
12/17
13
Apply

THEORY TO TOOLING

What you built today does not stay in the classroom. The METEORSTORM vocabulary is a published taxonomy, and the moment the shift ends your work ships as machine tags the whole community can read.

MODULE THREE
13/17
14
Tag and share

TAG THE ATTACK PATHS

You can now show the route, not just the destination, and you can send it somewhere. METEORSTORM is what changed: each path names the elements an adversary crosses, in order, in a published vocabulary, so Kestrel’s MISP instance and any threat intel platform that imports the taxonomy already read it, out to the Space ISAC exchange. One path carries four things. Click through them, then follow the strip below to see where the record goes.

01TARGETOne element, and it is the same one all week

Every path names one element it is about, and it is the element its threat already named. That is what keeps the week joined up: yesterday’s threat, today’s path, tomorrow’s signature and Friday’s measure all point at the same service.

Target and objective are not the same thing. The target says what the path is about; the objective says where the route ends. Here they are different elements, and that is normal. A path that can name no element at all is excluded on the record, with the reason.

The target of path 00 · KA-SAT, February 2022
It is about
SVC:CP:Control Plane:09, ground command acceptance, the service that decides who may command
It came from
AN:THR:Threat:00, Day 2’s threat, which named that same element
It is not
the objective. This route ends on AST:SW:Software:03, the patch deployment pipeline
▷ In the real world, this is where the path goes
01 · Confirmed at Kestrel
Security Operations confirms the path against the platform’s own elements. Unconfirmed work stays in the register.
02 · Published from your MISP
Kestrel’s MISP instance carries the record in the same meteorstorm vocabulary you just tagged it with.
03 · Redacted, then across
Mission-sensitive detail, customer identity and ITAR or EAR content are removed, then it crosses as a structured record over the agreed Space ISAC interface.
04 · A member acts on it
A peer reads SVC-CP onto their own control-plane services, and what they send back is routed to whoever owns the element it names.
MIMISP
MODULE THREE
14/17
15
DAY 3 COMPLETE

DAY 3 COMPLETE

You mapped 4 attack paths with Dana Whitfield and Satellite Design & Engineering, each traced through the CONOPS with the detection sources needed to see it. Dana knows where the sources are thin. Tomorrow you take the paths back to Maya Reyes, and Day 4 writes the detection signatures and response playbooks that fire on them.

MODULE THREE
15/17
16
Work role ability confirmation

DAY 3 COMPLETE

What you built today. Four AN-ATT elements enumerated with Dana Whitfield and Satellite Design & Engineering. 2 GROUND, 1 LINK, 1 SPACE. Every element walks an end-to-end attacker traversal through real services and assets on the platform, anchored to public reporting or framework reference. No hypothetical paths; every element is grounded. Satellite Design & Engineering spent the day writing in the language it helped build, and the other two departments can read every path without a briefing. The paths and the RDS and RSS required sources they carry feed the detection methods Executive Order 14144 requires on the command path.

DAY 3 COMPLETE · ATTACK PATHS ENUMERATED WITH SATELLITE DESIGN & ENGINEERING
Working session with Satellite Design & Engineering walking each threat into the attacker’s likely route through the platform
Full Spectrum Space Cybersecurity Professional briefing Security Operations, Satellite Operations, and Satellite Design & Engineering with the platform vocabulary on the wall, threat markers from yesterday still visible AND new blue attack-path traversal lines drawn through specific decomposed elements showing the chains an attacker would walk. Dark operations center setting with cyan task lighting on the board and warm amber ambient lighting.
MODULE THREE
16/17
END
INCIDENT RESPONSEPREPARATIONFUNCTION 04
Function THREE complete · Function Four next

INCIDENT RESPONSE
PREPARATION.

Day 3 is complete: four attack paths enumerated against the command path and the data each would expose, with Satellite Design & Engineering walking every chain beside you. Tomorrow, Incident Response Preparation: you turn today’s paths into the signatures that fire so IR knows which playbook to run.

THE REAL PROBLEM
The team knew which threats applied, but not how an adversary would actually move across the platform to carry them out, or where they could be caught.
WHAT METEORSTORM DELIVERED
A map of attack paths, each tracing the elements an adversary crosses from first access to objective, with the data sources that reveal every step inventoried.
THE KEY IMPROVEMENT

Defense became a route the team can watch. Each path names the parts an attacker crosses, so they know exactly where to place detection.

END
MODULE THREE
17/17
REFERENCE LIBRARY

Standards, Policies & Sources

The instruments this course aligns to. Each element links to its primary source.

U.S. National Security Space Policy

CNSS Policy No. 12 (CNSSP-12)Information-assurance policy for national security space systems.CNSS Instruction 1200 (CNSSI 1200), Aug 2025Implementing requirements: on-board intrusion detection, hardware root-of-trust, patch management.DoDI 8581.01Information-assurance policy for space systems used by the DoD.Space Policy Directive 5 (SPD-5), 2020First comprehensive U.S. cybersecurity principles for space systems.

Executive Orders

EO 14144 (Jan 16, 2025)Strengthening and Promoting Innovation in the Nation’s Cybersecurity.EO 14306 (Jun 6, 2025)Sustaining select efforts, amending EO 13694 and EO 14144.

NIST Standards & FISMA

NIST SP 800-53 Rev. 5Security and privacy controls; IR-3 incident-response testing.NIST SP 800-37 Rev. 2Risk Management Framework; continuous monitoring and annual control assessment.NIST IR 8270Introduction to Cybersecurity for Commercial Satellite Operations.NIST IR 8401Satellite Ground Segment cybersecurity framework profile.NIST IR 8441Cybersecurity Framework Profile for Hybrid Satellite Networks.NIST SP 800-160 Vol. 2 Rev. 1Cyber resiliency goals: Anticipate, Withstand, Recover, Adapt.FISMAFederal Information Security Modernization Act; annual program review obligation.

Threat Frameworks (analytic layer)

MITRE ATT&CKAdversary tactics and techniques knowledge base.MITRE CAPECCommon Attack Pattern Enumeration and Classification; dictionary of attack patterns that exploit known weaknesses.MITRE D3FENDKnowledge graph of defensive countermeasures and techniques, mapped to ATT&CK (NSA-funded, maintained by MITRE).SPARTASpace Attack Research and Tactic Analysis (The Aerospace Corporation).ESA Space ShieldEuropean Space Agency space-system threat framework.

EU & Global

NIS2 Directive (EU 2022/2555)Risk management and 24h/72h incident reporting; space sector in scope.EU Space Act (proposal, 25 Jun 2025)Space-specific resilience and cybersecurity obligations; extraterritorial scope.ENISA Space Threat LandscapeEuropean threat landscape and recommendations for space operators.Cyber Resilience Act (CRA)Connected hardware/software requirements; applies from December 2027.

Open-Source Vocabulary & Tooling

METEORSTORM MISP taxonomyThe course vocabulary, live and open source in the MISP taxonomy repository.MISP / CIRCLComputer Incident Response Center Luxembourg, maintainers of MISP.RootAPublic-domain open detection language (YAML) used in Module 04 to write portable signatures. (github.com/UncoderIO/Roota)Uncoder.IOOpen-source IDE and translation engine that ports RootA rules across SIEM, EDR, and XDR formats.SpaceCOP & Indicators of BehaviorDHS S&T + Aerospace Corp. on-board intrusion-detection prototype.CROO (Cyber Resilience On-Orbit)Proof Labs on-board IDS for the Space Force.

Community & Reporting

Space ISACSpace Information Sharing and Analysis Center.Air & Space Forces MagazineWaterman, “New Cybersecurity Rules for Pentagon’s Commercial Satellite Vendors,” Nov 19, 2025.Via Satellite“DHS Wants Satellite Volunteers to Test New Cyber Tools,” Nov 17, 2025.Defense Daily“New National Space Cybersecurity Policy Emphasizes Intrusion Detection,” Nov 18, 2025.Mayer Brown legal analysis“Securing the Final Frontier,” Dec 11, 2025 (US and EU regulatory map).