01
FUNCTION 01FUNCTION 02FUNCTION 03FUNCTION 05INCIDENT RESPONSEPREPAREDNESSFUNCTION 04
Function Four
INCIDENT RESPONSE
PREPAREDNESS

Master Exposure Management.

“The adversary suffers when every path they take ends in a trap.”

Kestrel Orbital’s platform model, the threat catalogue, and the attack paths Dana Whitfield walked with you yesterday all sit in one shared form. Today you sit down with Maya Reyes and the Security Operations Center to turn every path into a detection that fires and a playbook that runs, continually enumerating the attack paths of exposed and isolated platform elements. The signatures and playbooks you write today support Executive Order 14144’s detect-report-recover requirement and the NIS2 reporting deadlines: a 24-hour warning, a 72-hour notification, a one-month report.

MODULE FOUR
01/18
02
DAY 4

DAY 4 START

Today you turn each attack path into a detection signature that fires on those data sources and a response playbook that runs when it fires. You are back with Maya Reyes, who briefed the threat sources on Day 2 and now writes detections against the paths Dana drew on Day 3. Maya has spent years writing rules that fire on things nobody could name; today every one of hers points at an enumerated element. Each day’s work lands on the day before it. This is the detect-report-recover capability Executive Order 14144 requires, exercised inside the reporting deadlines NIS2 sets.

MODULE FOUR
02/18
03
Learn

Set the context

Before you write a single signature, fix what Day 3 handed you and today's job: the attack-path map and the data and signal source named at each step, marked Available, Partial or Gap, and the task of turning each one into an alarm that actually fires.

MODULE FOUR
03/18
04
Learn

WRITE THE SIGNATURES & PLAYBOOKS

Six artifacts on the table. Security Operations runs the detections and acts on the alerts, and today the center lays its working reality on the table the same way Satellite Design & Engineering opened its artifacts yesterday. Click an artifact for what it constrains about the signatures you write today.

01TELEMETRY SOURCES▷ What it constrains

Sets what a signature can observe at all. A source Day 3 marked Available can be authored against today; one marked Gap is recorded as a detection gap with the collection that would close it.

MODULE FOUR
04/18
05
Day 4

CHECKPOINT

Five questions on what Day 3 handed you and today's job: the attack-path map you build on, the sources that see each step, and why every detection ties back to a path. Answer to confirm the context before you learn the method.

MODULE FOUR
05/18
06
Learn

Learn the method

One repeatable way to turn a path into a detection: the six-step AN-DET enumeration, each signature a complete RootA rule anchored through TDM to the one element it watches and referencing the path it covers, with its response playbook written alongside it.

MODULE FOUR
06/18
07
Apply

INCIDENT RESPONSE PREPARATION PROCESS

Seven steps, fixed order, walked once per signature; the dashed loop repeats until every catalogued attack path has at least one detection. Constraint: a signature that is not a complete RootA rule, or whose TDM does not hold exactly one element, is rejected. Second deliverable: step 07 binds the response, one playbook per signature: one trigger, the entry condition, then approved actions across assess, contain, recover and report. Every action names one element, one Responsible executor and Mission Lead as the Accountable decider, at a level read off its reversibility class. The report stage is where the NIS2 clocks are met or missed.

Click a step for its rule and the action it takes
↻ repeat per signature until every path has a detection
▷ The process
STEP 01 OF 07
01Enumerate the LAYER

LAYER = AN, fixed; identifies this as an Analytic Layer element.

▷ Example from the course

A detection signature is the SOC’s own instrument, not a platform part, so the layer is fixed at AN.

MODULE FOUR
07/18
08
Learn

ROOTA, OPEN DETECTION LANGUAGE

RootA is an open public-domain detection-engineering language from the SOC Prime team, released in 2023. Every AN-DET is a complete RootA rule, base fields plus the meteorstorm anchor block, so the portfolio ports across every SIEM your organization runs and a peer’s machine can route it to the exact element it watches. Below is the worked rule for AN:DET:Detection Signature:01: click any field to expand it and read what it does.

▷ an-det-01-out-of-pattern-command.yml
▷ Field 1 · name

Mandatory. The rule title Security Operations sees in the alert console. It states the goal and the method, not an internal ticket number.

▷ Why RootA
Open and vendor-neutral

Public-domain specification. No procurement gate, no vendor contract. A rule you write today is a rule a peer operator, such as a fellow Space-ISAC member, could pull tomorrow and run on a different SIEM with no rewrite.

AAPPLY
MODULE FOUR
08/18
09
Day 4

CHECKPOINT

Five questions on the method you just learned: the AN-DET layer and TAG, the one-element TDM anchor, the reference to the attack path, and why every signature is a complete RootA rule. Answer before you enumerate.

MODULE FOUR
09/18
10
Apply

Enumerate the signatures and playbooks

Work segment by segment, Ground through Space, writing one signature and one response playbook per path, and recording every path whose source is a Gap as a detection gap with the collection that would close it.

MODULE FOUR
10/18
11
Apply

SIGNATURES AND PLAYBOOKS · 4 PAIRS

One signature per path, each bound to the response it authorizes, every one a complete RootA rule so it ports across detection tooling. Every rule names one element through TDM, the same element its threat named, and references the path it covers. Every playbook carries one trigger and approved actions across assess, contain, recover and report, each naming one element, one executor and one decider. The domain is set by what the action changes, not where it happens, and the authority level is read off how reversible it is: reversible is solo, disruptive is co-signed, irreversible is escalated. A path whose source is a Gap keeps its signature and its playbook: the gap is recorded as an enumerable product with the collection that would close it.

Management-plane firmware-push abuseGround
AN:DET:Detection Signature:00
Management-plane firmware-push abuse
Management-plane abuse: detects firmware-push operations from the modem management interface outside maintenance windows, or following a VPN-appliance authentication anomaly.
Source AvailablePB-00
Out-of-pattern command-authority usageGround
AN:DET:Detection Signature:01
Out-of-pattern command-authority usage
Out-of-pattern command authority usage: detects commanding workstation usage outside the operator's normal hours, commands issued without peer review tags, or sequences inconsistent with the active mission profile.
Source PartialPB-01
Sustained RF noise-floor anomalyLink
AN:DET:Detection Signature:02
Sustained RF noise-floor anomaly
Sustained noise-floor anomaly: detects elevated noise across the uplink or downlink bands beyond expected environmental thresholds, sustained for longer than incidental atmospheric events.
Source AvailablePB-02
Firmware-hash mismatch at bootSpace
AN:DET:Detection Signature:03
Firmware-hash mismatch at boot
Firmware-hash mismatch at boot: detects firmware images whose measured hash does not match the signed expected value at boot or after an update.
Source GapPB-03
Click a signature for its full record: what it covers, the one element its TDM names, its source state, and the playbook it authorizes with its RACI
4SIGNATURES
MODULE FOUR
11/18
12
Day 4

CHECKPOINT

Five questions on the set you just built: its size and segment split, how coverage gaps are handled, how the departments use it, and what Day 5 does next. Answer to close Day 4's work.

MODULE FOUR
12/18
13
PRESENT

THE DETECTION CATALOGUE

Segments
SPACE
1 detection
▸ expand
LINK
1 detection
▸ expand
GROUND
2 detections
▸ expand
SEG
SEG:SP:Space:00
SEG:LI:Link:00
SEG:GR:Ground:00
PCE
PCE:OR:Orbital:00
PCE:TE:Terrestrial:00
PCE:TE:Terrestrial:01
Every AN-DET detection signature on one screen, each anchored to the one platform element it observes. Click any segment to see its detections; click a card to reveal its ETEN and the single element its TDM names.
MODULE FOUR
13/18
14
Apply

THEORY TO TOOLING

What you built today does not stay in the classroom. The METEORSTORM vocabulary is a published taxonomy, and the moment the shift ends your work ships as machine tags the whole community can read.

MODULE FOUR
14/18
15
Tag and share

TAG THE SIGNATURES

This is where the week turns defensive. You are no longer describing what an adversary would do; you are writing the thing that watches for it. METEORSTORM is what changed: each signature names the element it watches and carries tags a machine reads, so it is not locked to your SIEM or your platform. One signature carries four things. Click through them.

01TARGETOne element, and the rule says which

A signature watches one element, and it is the element its threat named on Day 2 and its path pivoted through on Day 3. That is what lets a reader know what a rule covers before they deploy it, and what lets Friday’s measure attach to the same scenario without anyone re-deciding what it was about.

A rule with no element to watch is a wish. It cannot be counted as coverage, it cannot be handed to a peer, and nobody can say what is left uncovered when it is switched off.

What signature 00 watches · KA-SAT, February 2022
It watches (TDM)
SVC:CP:Control Plane:09, ground command acceptance, the service that decides who may command
It covers
AN:ATT:Attack Path:00, Day 3’s route, at its pivot
It came from
AN:THR:Threat:00, Day 2’s threat, which named that same element
Its blast radius
the whole modem fleet, which is why the trigger threshold is any confidence and not higher
MIMISP
MODULE FOUR
15/18
16
Incident response preparation

DAY 4 COMPLETE

You wrote a signature and a playbook for every path with Maya Reyes and the Security Operations Center, the evidence behind the organization’s detect-report-recover duties. Maya also declared the gaps she cannot see, honestly. Tomorrow, Day 5 brings Maya, Theo Lindgren, and Dana Whitfield to one table to shrink and harden the exposure that keeps recurring.

MODULE FOUR
16/18
17
Work role ability confirmation

YOU CAN PREPARE THE RESPONSE

What you built today. Four AN-DET elements, each a complete RootA rule written with Maya Reyes and Security Operations, plus one playbook per signature. 2 GROUND, 1 LINK, 1 SPACE. Each rule names one element through TDM, the same element its threat named on Day 2 and its path anchored to on Day 3. Where the source is Available the signature fires; where it is a Gap the rule is still enumerated and the missing collection is named, with an owner. The threat, its path, its signature and the element all carry one number, so any of the three departments can follow the chain unaided. The set feeds Executive Order 14144’s detect-report-recover requirement inside the NIS2 reporting deadlines.

SIGNATURES & PLAYBOOKS WRITTEN WITH THE SECURITY OPERATIONS CENTER
Working session with Security Operations turning each attack path into a deployable detection plus a response playbook the on-call analyst can run
Full Spectrum Space Cybersecurity Professional briefing the same three departments with the same platform vocabulary on the wall, threat markers and attack-path lines from prior days still visible, with new green detection-signature badges overlaid on specific elements showing where Security Operations will observe the adversary, plus a small playbook stack icon on the table. Dark operations center setting.
MODULE FOUR
17/18
END
ADVERSARYMANAGEMENTFUNCTION 05
Function FOUR complete · Function Five next

ADVERSARY
MANAGEMENT.

Day 4 done. Tomorrow, Adversary Management: you write the resilience measures that take options away from the adversary, the continuity and backup protections the mandates expect for command and control.

THE REAL PROBLEM
The team had the attack-path map and knew which sources could see each step, but nothing was written to fire when an attack ran, and coverage was unknown.
WHAT METEORSTORM DELIVERED
A portfolio of complete RootA rules, each anchored to the one element it watches and referencing the attack path it covers, with a response playbook behind each one.
THE KEY IMPROVEMENT

The map became a working alarm system. Every attack path now has a signature anchored to the one element its threat named and a playbook behind it, and the one path the platform cannot yet see is on the record as a gap.

END
MODULE FOUR
18/18
REFERENCE LIBRARY

Standards, Policies & Sources

The instruments this course aligns to. Each element links to its primary source.

U.S. National Security Space Policy

CNSS Policy No. 12 (CNSSP-12)Information-assurance policy for national security space systems.CNSS Instruction 1200 (CNSSI 1200), Aug 2025Implementing requirements: on-board intrusion detection, hardware root-of-trust, patch management.DoDI 8581.01Information-assurance policy for space systems used by the DoD.Space Policy Directive 5 (SPD-5), 2020First comprehensive U.S. cybersecurity principles for space systems.

Executive Orders

EO 14144 (Jan 16, 2025)Strengthening and Promoting Innovation in the Nation’s Cybersecurity.EO 14306 (Jun 6, 2025)Sustaining select efforts, amending EO 13694 and EO 14144.

NIST Standards & FISMA

NIST SP 800-53 Rev. 5Security and privacy controls; IR-3 incident-response testing.NIST SP 800-37 Rev. 2Risk Management Framework; continuous monitoring and annual control assessment.NIST IR 8270Introduction to Cybersecurity for Commercial Satellite Operations.NIST IR 8401Satellite Ground Segment cybersecurity framework profile.NIST IR 8441Cybersecurity Framework Profile for Hybrid Satellite Networks.NIST SP 800-160 Vol. 2 Rev. 1Cyber resiliency goals: Anticipate, Withstand, Recover, Adapt.FISMAFederal Information Security Modernization Act; annual program review obligation.

Threat Frameworks (analytic layer)

MITRE ATT&CKAdversary tactics and techniques knowledge base.MITRE CAPECCommon Attack Pattern Enumeration and Classification; dictionary of attack patterns that exploit known weaknesses.MITRE D3FENDKnowledge graph of defensive countermeasures and techniques, mapped to ATT&CK (NSA-funded, maintained by MITRE).SPARTASpace Attack Research and Tactic Analysis (The Aerospace Corporation).ESA Space ShieldEuropean Space Agency space-system threat framework.

EU & Global

NIS2 Directive (EU 2022/2555)Risk management and 24h/72h incident reporting; space sector in scope.EU Space Act (proposal, 25 Jun 2025)Space-specific resilience and cybersecurity obligations; extraterritorial scope.ENISA Space Threat LandscapeEuropean threat landscape and recommendations for space operators.Cyber Resilience Act (CRA)Connected hardware/software requirements; applies from December 2027.

Open-Source Vocabulary & Tooling

METEORSTORM MISP taxonomyThe course vocabulary, live and open source in the MISP taxonomy repository.MISP / CIRCLComputer Incident Response Center Luxembourg, maintainers of MISP.RootAPublic-domain open detection language (YAML) used in Module 04 to write portable signatures. (github.com/UncoderIO/Roota)Uncoder.IOOpen-source IDE and translation engine that ports RootA rules across SIEM, EDR, and XDR formats.SpaceCOP & Indicators of BehaviorDHS S&T + Aerospace Corp. on-board intrusion-detection prototype.CROO (Cyber Resilience On-Orbit)Proof Labs on-board IDS for the Space Force.

Community & Reporting

Space ISACSpace Information Sharing and Analysis Center.Air & Space Forces MagazineWaterman, “New Cybersecurity Rules for Pentagon’s Commercial Satellite Vendors,” Nov 19, 2025.Via Satellite“DHS Wants Satellite Volunteers to Test New Cyber Tools,” Nov 17, 2025.Defense Daily“New National Space Cybersecurity Policy Emphasizes Intrusion Detection,” Nov 18, 2025.Mayer Brown legal analysis“Securing the Final Frontier,” Dec 11, 2025 (US and EU regulatory map).