Master Exposure Management.
“The adversary suffers when every path they take ends in a trap.”
Kestrel Orbital’s platform model, the threat catalogue, and the attack paths Dana Whitfield walked with you yesterday all sit in one shared form. Today you sit down with Maya Reyes and the Security Operations Center to turn every path into a detection that fires and a playbook that runs, continually enumerating the attack paths of exposed and isolated platform elements. The signatures and playbooks you write today support Executive Order 14144’s detect-report-recover requirement and the NIS2 reporting deadlines: a 24-hour warning, a 72-hour notification, a one-month report.
DAY 4 START
Today you turn each attack path into a detection signature that fires on those data sources and a response playbook that runs when it fires. You are back with Maya Reyes, who briefed the threat sources on Day 2 and now writes detections against the paths Dana drew on Day 3. Maya has spent years writing rules that fire on things nobody could name; today every one of hers points at an enumerated element. Each day’s work lands on the day before it. This is the detect-report-recover capability Executive Order 14144 requires, exercised inside the reporting deadlines NIS2 sets.
Set the context
Before you write a single signature, fix what Day 3 handed you and today's job: the attack-path map and the data and signal source named at each step, marked Available, Partial or Gap, and the task of turning each one into an alarm that actually fires.
WRITE THE SIGNATURES & PLAYBOOKS
Six artifacts on the table. Security Operations runs the detections and acts on the alerts, and today the center lays its working reality on the table the same way Satellite Design & Engineering opened its artifacts yesterday. Click an artifact for what it constrains about the signatures you write today.
Sets what a signature can observe at all. A source Day 3 marked Available can be authored against today; one marked Gap is recorded as a detection gap with the collection that would close it.
CHECKPOINT
Five questions on what Day 3 handed you and today's job: the attack-path map you build on, the sources that see each step, and why every detection ties back to a path. Answer to confirm the context before you learn the method.
Learn the method
One repeatable way to turn a path into a detection: the six-step AN-DET enumeration, each signature a complete RootA rule anchored through TDM to the one element it watches and referencing the path it covers, with its response playbook written alongside it.
INCIDENT RESPONSE PREPARATION PROCESS
Seven steps, fixed order, walked once per signature; the dashed loop repeats until every catalogued attack path has at least one detection. Constraint: a signature that is not a complete RootA rule, or whose TDM does not hold exactly one element, is rejected. Second deliverable: step 07 binds the response, one playbook per signature: one trigger, the entry condition, then approved actions across assess, contain, recover and report. Every action names one element, one Responsible executor and Mission Lead as the Accountable decider, at a level read off its reversibility class. The report stage is where the NIS2 clocks are met or missed.
LAYER = AN, fixed; identifies this as an Analytic Layer element.
A detection signature is the SOC’s own instrument, not a platform part, so the layer is fixed at AN.
ROOTA, OPEN DETECTION LANGUAGE
RootA is an open public-domain detection-engineering language from the SOC Prime team, released in 2023. Every AN-DET is a complete RootA rule, base fields plus the meteorstorm anchor block, so the portfolio ports across every SIEM your organization runs and a peer’s machine can route it to the exact element it watches. Below is the worked rule for AN:DET:Detection Signature:01: click any field to expand it and read what it does.
Mandatory. The rule title Security Operations sees in the alert console. It states the goal and the method, not an internal ticket number.
Public-domain specification. No procurement gate, no vendor contract. A rule you write today is a rule a peer operator, such as a fellow Space-ISAC member, could pull tomorrow and run on a different SIEM with no rewrite.
CHECKPOINT
Five questions on the method you just learned: the AN-DET layer and TAG, the one-element TDM anchor, the reference to the attack path, and why every signature is a complete RootA rule. Answer before you enumerate.
Enumerate the signatures and playbooks
Work segment by segment, Ground through Space, writing one signature and one response playbook per path, and recording every path whose source is a Gap as a detection gap with the collection that would close it.
SIGNATURES AND PLAYBOOKS · 4 PAIRS
One signature per path, each bound to the response it authorizes, every one a complete RootA rule so it ports across detection tooling. Every rule names one element through TDM, the same element its threat named, and references the path it covers. Every playbook carries one trigger and approved actions across assess, contain, recover and report, each naming one element, one executor and one decider. The domain is set by what the action changes, not where it happens, and the authority level is read off how reversible it is: reversible is solo, disruptive is co-signed, irreversible is escalated. A path whose source is a Gap keeps its signature and its playbook: the gap is recorded as an enumerable product with the collection that would close it.
GroundAN:DET:Detection Signature:00
GroundAN:DET:Detection Signature:01
LinkAN:DET:Detection Signature:02
SpaceAN:DET:Detection Signature:03CHECKPOINT
Five questions on the set you just built: its size and segment split, how coverage gaps are handled, how the departments use it, and what Day 5 does next. Answer to close Day 4's work.
THE DETECTION CATALOGUE
THEORY TO TOOLING
What you built today does not stay in the classroom. The METEORSTORM vocabulary is a published taxonomy, and the moment the shift ends your work ships as machine tags the whole community can read.
TAG THE SIGNATURES
This is where the week turns defensive. You are no longer describing what an adversary would do; you are writing the thing that watches for it. METEORSTORM is what changed: each signature names the element it watches and carries tags a machine reads, so it is not locked to your SIEM or your platform. One signature carries four things. Click through them.
A signature watches one element, and it is the element its threat named on Day 2 and its path pivoted through on Day 3. That is what lets a reader know what a rule covers before they deploy it, and what lets Friday’s measure attach to the same scenario without anyone re-deciding what it was about.
A rule with no element to watch is a wish. It cannot be counted as coverage, it cannot be handed to a peer, and nobody can say what is left uncovered when it is switched off.
SVC:CP:Control Plane:09, ground command acceptance, the service that decides who may commandAN:ATT:Attack Path:00, Day 3’s route, at its pivotAN:THR:Threat:00, Day 2’s threat, which named that same elementDAY 4 COMPLETE
You wrote a signature and a playbook for every path with Maya Reyes and the Security Operations Center, the evidence behind the organization’s detect-report-recover duties. Maya also declared the gaps she cannot see, honestly. Tomorrow, Day 5 brings Maya, Theo Lindgren, and Dana Whitfield to one table to shrink and harden the exposure that keeps recurring.
YOU CAN PREPARE THE RESPONSE
What you built today. Four AN-DET elements, each a complete RootA rule written with Maya Reyes and Security Operations, plus one playbook per signature. 2 GROUND, 1 LINK, 1 SPACE. Each rule names one element through TDM, the same element its threat named on Day 2 and its path anchored to on Day 3. Where the source is Available the signature fires; where it is a Gap the rule is still enumerated and the missing collection is named, with an owner. The threat, its path, its signature and the element all carry one number, so any of the three departments can follow the chain unaided. The set feeds Executive Order 14144’s detect-report-recover requirement inside the NIS2 reporting deadlines.

ADVERSARY
MANAGEMENT.
Day 4 done. Tomorrow, Adversary Management: you write the resilience measures that take options away from the adversary, the continuity and backup protections the mandates expect for command and control.
The map became a working alarm system. Every attack path now has a signature anchored to the one element its threat named and a playbook behind it, and the one path the platform cannot yet see is on the record as a gap.
