01
FUNCTION 01FUNCTION 02FUNCTION 03FUNCTION 04ADVERSARYMANAGEMENTFUNCTION 05
Function Five
ADVERSARY
MANAGEMENT

Master Adversary Management.

“The adversary suffers when their plans are known, broken, and turned against them.”

Four days ago the Space Cybersecurity Operations and Resilience department existed on paper; today all three departments work from Kestrel Orbital’s platform model, threat catalogue, attack paths, signatures, and playbooks. To close the week you bring Theo Lindgren, Dana Whitfield, and Maya Reyes to one table: you align decomposition, contextualized threat modeling, converged detection engineering, and exposure management with real-world adversary profiles, taking options away from the adversary. The measures feed NIS2’s continuity, backup, and supply-chain duties and Executive Order 14144’s backup-and-failover requirement for command and control.

MODULE FIVE
01/18
02
DAY 5

DAY 5 START

Today you find the exposure that recurs across the week’s command-path work and build resilience measures that shrink, harden, or remove it before launch. Each department has taken its turn this week; today Theo Lindgren leads for Satellite Operations, because a measure that cannot be flown is not a measure. He sits with Dana Whitfield, who can change the build, and Maya Reyes, whose detections stand watch over whatever the two of them decide. These are the continuity, backup, and supply-chain measures NIS2 requires, and the backup and failover Executive Order 14144 expects for command and control.

MODULE FIVE
02/18
03
Learn

Set the context

Before you change a single part, fix what Days 1 through 4 handed you and today's job: the accumulated threats, paths, and detections, and the task of removing the attack surface the adversary keeps relying on.

MODULE FIVE
03/18
04
L1

BUILD THE RESILIENCE MEASURES

Six artifacts on the table. Resilience needs both: operating procedures the crew can run when something goes wrong, and architectural changes that make the failure mode hard or impossible in the first place. So today, for the first time this week, both operating departments are in the room together, each bringing what only it can. The six artifacts below are what you walk together for every measure you enumerate.

OPERATING PROCEDURES
▷ ARTIFACT · 01
OPERATING PROCEDURES

Satellite Operations’ playbook for failover, abort, retry, and safe-mode. New measures must fit what the crew can run during a pass.

ARCHITECTURE REFERENCE
▷ ARTIFACT · 02
ARCHITECTURE REFERENCE

Satellite Design & Engineering’s current architecture map: what’s hardened, what isn’t, what can be rebuilt this cycle.

REDUNDANCY MAP
▷ ARTIFACT · 03
REDUNDANCY MAP

What subsystems already have backup paths, and which paths quietly share a single failure point.

DEGRADED MODES
▷ ARTIFACT · 04
DEGRADED MODES

Platform behavior when individual subsystems are taken off-line: what the mission can still do, what it can’t.

ENG ROADMAP
▷ ARTIFACT · 05
ENG ROADMAP

What architectural changes are already queued vs. proposed; what’s in scope this week vs. next.

PAST LESSONS
▷ ARTIFACT · 06
PAST LESSONS

Resilience patterns from prior incidents on this platform and peer platforms that worked, or didn’t.

MODULE FIVE
04/18
05
Day 5

CHECKPOINT

Five questions on what Days 1 through 4 handed you and today's job: the accumulated CONOPS, threats, paths, and detections, and the task of removing recurring attack surface before launch. Answer to confirm the context before you learn the method.

MODULE FIVE
05/18
06
Learn

Learn the method

One repeatable way to turn a recurring weakness into a fix: the AN-RES enumeration, each measure anchored through TRE to the element it protects and mapped to one of four objectives, Anticipate, Withstand, Recover, Adapt.

MODULE FIVE
06/18
07
Apply

ADVERSARY MANAGEMENT PROCESS

Six steps, fixed order, walked once per measure; the dashed loop repeats until every path worth countering carries one. Constraint: every element carries exactly one TRE element and names its resiliency goal, and it declares the lifecycle of the element it protects and the cadence it holds at, because a measure that cannot be installed is not a control in force.

Click a step for its rule and the action it takes
↻ repeat per measure until every path is countered
▷ The process
STEP 01 OF 06
01Enumerate the LAYER

LAYER = AN, fixed; identifies this as an Analytic Layer element.

▷ Example from the course

A resilience measure is the organization’s own decision about the platform, not a platform part, so the layer is fixed at AN.

MODULE FIVE
07/18
08
Learn

DIGITAL TWIN, THE TEST BENCH FOR RESILIENCE

A resilience measure changes a flying platform, so it is validated on the twin before it reaches orbit: design it, develop it, and validate it against a live-behaving model. Click a capability to see what the bench gives you and the week-final measure it is exercised on.

▷ What the bench gives you
Validate AN-RES on the twin

Apply a candidate measure to the twin first and watch the second-order effects on mission capability, duty cycle, downlink margin, and power budget before it reaches the operational platform.

▷ Exercised on
AN:RES:Resilience Measure:00
Zero-trust segmentation of the device management plane
Objective Anticipate: removes the high-impact path entirely by raising the barrier to management-plane access.
DTTWIN
MODULE FIVE
08/18
09
Day 5

CHECKPOINT

Five questions on the method you just learned: the AN-RES layer and TAG, the TRE anchor, the four resiliency goals, and the digital twin as test bench. Answer before you enumerate.

MODULE FIVE
09/18
10
Apply

Enumerate the resilience measures

Work segment by segment, User through Space, writing a measure that shrinks, hardens, or removes each recurring element, or, where the element cannot be changed, a compensating control on the path to it. Every measure is proven on the digital twin before it touches the live platform.

MODULE FIVE
10/18
11
Apply

WEEK COMPLETE · 4 RESILIENCE MEASURES

One measure per attack path, written with Satellite Operations and Satellite Design & Engineering. Every element names one platform element via TRE, the same element the threat it counters targets, plus the path it counters, its resiliency goal (Anticipate, Withstand, Recover, Adapt per NIST SP 800-160 v2), and the department that owns it. Each also carries the cadence it actually holds at, because a measure protects an element but cannot always be installed on it: two of these four are in force today, one is phased, and one is next-build with a compensating control on the ground.

Zero-trust segmentation of the device management planeGround
AN:RES:Resilience Measure:00
Zero-trust segmentation of the device management plane
Air-gap or strict zero-trust segmentation of the device management plane from external networks; require hardware-rooted attestation on any management-plane access; gate firmware pushes behind dual-approval workflow with a maintenance-window enforcement.
Anticipatein-forceBoth
Dual-control commanding for high-impact actionsGround
AN:RES:Resilience Measure:01
Dual-control commanding for high-impact actions
Dual-control commanding for high-impact actions (a second operator must approve before transmission); per-operator behavior baselines and pre-pass briefings make out-of-pattern actions stand out.
Withstandin-forceBoth
Frequency-agile spread-spectrum link with backup bandLink
AN:RES:Resilience Measure:02
Frequency-agile spread-spectrum link with backup band
Frequency-agile / spread-spectrum link operation with pre-arranged backup band; Satellite Operations switches bands automatically when noise floor exceeds threshold; Satellite Design & Engineering owns the agility waveform.
WithstandphasedBoth
Measured-boot firmware and supply-chain attestationSpace
AN:RES:Resilience Measure:03
Measured-boot firmware and supply-chain attestation
Measured-boot firmware attestation with signed-vendor manifest; supply-chain provenance verification at integration; quarantine of any component whose hash does not match the signed expected value.
Anticipatenext-buildSatellite Design & Engineering
Click a measure for its full record: the one TRE element protected, the path it counters, objective, owner, lifecycle and cadence, and where it is not in force the compensating control and the residual risk
4MEASURES
MODULE FIVE
11/18
12
Day 5

CHECKPOINT

Five questions on the set you just built: its size, how each measure reduces attack surface, and how it completes the five-function week. Answer to close the course's build work.

MODULE FIVE
12/18
13
PRESENT

THE RESILIENCE CATALOGUE

Segments
SPACE
1 measure
▸ expand
LINK
1 measure
▸ expand
GROUND
2 measures
▸ expand
SEG
SEG:SP:Space:00
SEG:LI:Link:00
SEG:GR:Ground:00
PCE
PCE:OR:Orbital:00
PCE:TE:Terrestrial:00
PCE:TE:Terrestrial:01
Every AN-RES resilience measure on one screen, anchored to the platform it hardens. Click any segment to see its measures; click a card to reveal its ETEN, the one TRE element it hardens, and the cadence it actually holds at.
MODULE FIVE
13/18
14
Apply

THEORY TO TOOLING

What you built today does not stay in the classroom. The METEORSTORM vocabulary is a published taxonomy, and the moment the shift ends your work ships as machine tags the whole community can read.

MODULE FIVE
14/18
15
Tag and share

TAG THE MEASURES

This is where the week stops describing the adversary and starts taking options away from them. METEORSTORM is what changed: each measure names the element it protects, the path it counters and the goal it serves, in tags a machine reads, so a peer can adopt it without re-deriving your reasoning. One measure carries four things. Click through them.

01TARGETOne element, and the week ends where it started

A measure protects one element, and it is the element the threat named on Day 2, the path pivoted through on Day 3 and the signature watched on Day 4. Four records, four days, one service. That is what lets a peer pull the whole story in a single query instead of reading four documents that never said they were about the same thing.

It is also what makes coverage auditable. Because every measure names the path it counters, any path with no measure against it is visible as an uncovered path with an owner, rather than as an absence nobody notices.

What measure 00 protects · KA-SAT, February 2022
It protects (TRE)
SVC:CP:Control Plane:09, ground command acceptance, the service that decides who may command
It counters
AN:ATT:Attack Path:00, Day 3’s route
It closes
the pivot Day 4’s signature was written to watch
It came from
AN:THR:Threat:00, where the chain opened on Day 2
MIMISP
MODULE FIVE
15/18
16
DAY 5 COMPLETE

DAY 5 COMPLETE

You built resilience measures across the platform with Theo Lindgren and Dana Whitfield. The week is complete: you carried one platform from decomposition all the way to resilience, and Theo, Dana, and Maya Reyes now describe it the same way, which none of them could do on Monday. The five deliverables together support the organization’s response to Executive Order 14144 and the NIS2 Directive.

MODULE FIVE
16/18
17
Work role ability confirmation

DAY 5 COMPLETE · FULL WEEK IN HAND

What you built today. Four AN-RES elements written with Theo Lindgren and Dana Whitfield, feeding the continuity, backup, and supply-chain duties NIS2 assigns and the command-and-control failover EO 14144 expects. 2 GROUND, 1 LINK, 1 SPACE. Every measure names the structural element it protects, the threat or attack path it counters, the resiliency goal (Anticipate / Withstand / Recover / Adapt), and the department(s) who own it, a Satellite Operations procedure, a Satellite Design & Engineering change, or both. Every measure also names the lifecycle of the element it protects and the cadence it holds at: two in force, one phased, one next-build with a ground-side compensating control and a recorded residual risk, because a measure that cannot be installed on a flying vehicle is routed to the next build rather than counted as coverage. End of week. You now hold a working decomposition, an anchored threat set, an attack-path set, a signature + playbook set, and a resilience-measure set against the same reference platform. Every set is written in the same five-field language: the evidence base the two regulators expect, and the substance the organization’s Space ISAC channel carries.

DAY 5 COMPLETE · RESILIENCE WRITTEN WITH SATOPS + SATDEV/ENG
Both operating departments in the room because resilience needs operating procedures and architectural change
Full Spectrum Space Cybersecurity Professional briefing the same three departments with the same platform vocabulary on the wall, threat markers, attack-path lines, and detection badges all visible from prior days, with new purple resilience-measure shields overlaid on specific elements showing where the platform has been hardened. A four-quadrant resilience-objectives map (Anticipate, Withstand, Recover, Adapt) sits as a small inset on the lower-right of the board. Dark operations center setting.
MODULE FIVE
17/18
END
COURSECOMPLETECOURSE COMPLETE
Function FIVE complete

COURSE
COMPLETE.

Five days, five disciplines, one artifact set. You’re the person at your work-center who ties Security Operations, Satellite Operations, and Satellite Design & Engineering together.

THE REAL PROBLEM
The team could see and respond to attacks, but the parts of the platform the adversary kept relying on stayed exposed. Defense reacted to attacks instead of removing what made them possible.
WHAT METEORSTORM DELIVERED
A set of resilience measures that shrink, harden, or remove the elements that recurred across the threats and attack paths, cutting the adversary's attack surface before launch.
THE KEY IMPROVEMENT

Defense went from reacting to attacks to removing what makes them possible. The parts the adversary leaned on most are now cut back or gone, and the platform is described once and defended as one resilient system. Course complete.

END
MODULE FIVE
18/18
REFERENCE LIBRARY

Standards, Policies & Sources

The instruments this course aligns to. Each element links to its primary source.

U.S. National Security Space Policy

CNSS Policy No. 12 (CNSSP-12)Information-assurance policy for national security space systems.CNSS Instruction 1200 (CNSSI 1200), Aug 2025Implementing requirements: on-board intrusion detection, hardware root-of-trust, patch management.DoDI 8581.01Information-assurance policy for space systems used by the DoD.Space Policy Directive 5 (SPD-5), 2020First comprehensive U.S. cybersecurity principles for space systems.

Executive Orders

EO 14144 (Jan 16, 2025)Strengthening and Promoting Innovation in the Nation’s Cybersecurity.EO 14306 (Jun 6, 2025)Sustaining select efforts, amending EO 13694 and EO 14144.

NIST Standards & FISMA

NIST SP 800-53 Rev. 5Security and privacy controls; IR-3 incident-response testing.NIST SP 800-37 Rev. 2Risk Management Framework; continuous monitoring and annual control assessment.NIST IR 8270Introduction to Cybersecurity for Commercial Satellite Operations.NIST IR 8401Satellite Ground Segment cybersecurity framework profile.NIST IR 8441Cybersecurity Framework Profile for Hybrid Satellite Networks.NIST SP 800-160 Vol. 2 Rev. 1Cyber resiliency goals: Anticipate, Withstand, Recover, Adapt.FISMAFederal Information Security Modernization Act; annual program review obligation.

Threat Frameworks (analytic layer)

MITRE ATT&CKAdversary tactics and techniques knowledge base.MITRE CAPECCommon Attack Pattern Enumeration and Classification; dictionary of attack patterns that exploit known weaknesses.MITRE D3FENDKnowledge graph of defensive countermeasures and techniques, mapped to ATT&CK (NSA-funded, maintained by MITRE).SPARTASpace Attack Research and Tactic Analysis (The Aerospace Corporation).ESA Space ShieldEuropean Space Agency space-system threat framework.

EU & Global

NIS2 Directive (EU 2022/2555)Risk management and 24h/72h incident reporting; space sector in scope.EU Space Act (proposal, 25 Jun 2025)Space-specific resilience and cybersecurity obligations; extraterritorial scope.ENISA Space Threat LandscapeEuropean threat landscape and recommendations for space operators.Cyber Resilience Act (CRA)Connected hardware/software requirements; applies from December 2027.

Open-Source Vocabulary & Tooling

METEORSTORM MISP taxonomyThe course vocabulary, live and open source in the MISP taxonomy repository.MISP / CIRCLComputer Incident Response Center Luxembourg, maintainers of MISP.RootAPublic-domain open detection language (YAML) used in Module 04 to write portable signatures. (github.com/UncoderIO/Roota)Uncoder.IOOpen-source IDE and translation engine that ports RootA rules across SIEM, EDR, and XDR formats.SpaceCOP & Indicators of BehaviorDHS S&T + Aerospace Corp. on-board intrusion-detection prototype.CROO (Cyber Resilience On-Orbit)Proof Labs on-board IDS for the Space Force.

Community & Reporting

Space ISACSpace Information Sharing and Analysis Center.Air & Space Forces MagazineWaterman, “New Cybersecurity Rules for Pentagon’s Commercial Satellite Vendors,” Nov 19, 2025.Via Satellite“DHS Wants Satellite Volunteers to Test New Cyber Tools,” Nov 17, 2025.Defense Daily“New National Space Cybersecurity Policy Emphasizes Intrusion Detection,” Nov 18, 2025.Mayer Brown legal analysis“Securing the Final Frontier,” Dec 11, 2025 (US and EU regulatory map).