
“An alert is a hypothesis. An incident is a confirmed fact.”
Three things go wrong on this flight and they do not share a cause. Mission Four is scored on whether you can tell which is which with the clock running.
BRIEF THE MISSION
Mission Four is the first flight where the platform acts on you. A shorter, faster run over five ground stations spread across the Pacific and the Americas, with events firing while you work. Several things go wrong and they do not all have the same cause, which is the whole exercise: detect, then confirm, because an alert is not an incident.
- Orbit regime
- Medium Earth orbit, circular
- Altitude
- About 2,222 km
- Inclination
- 70 degrees
- Run
- 4800 seconds at 2.0x
- Ground stations
- Tokyo, Anchorage, Houston, Lima, Santiago
- Scripted events
- Yes, events will fire
Detect and confirm, because an alert is not an incident.
WHAT YOU DETECT
Three things go wrong on this flight and they do not share a cause. Two are an adversary and one is a part that failed on its own. An alert is a hypothesis; an incident is a confirmed threat, and the gap between them is where this mission is won or lost. Click a role to see what it holds this mission.
You confirm, and you separate. Not everything that broke was broken by somebody.
- · Judge which alert is a natural hardware fault rather than adversary activity
- · Decide which alerts belong in the cyber detection report to command leadership
- · Log the reaction-wheel fault as a hardware issue, separate from the cyber report
- · Sign every escalation

FAULT OR ATTACK
Mission Three taught you the discriminator with time to think. Mission Four asks for it live, with several things wrong at once and a clock running. Three tests settle almost every case, and they run in seconds. Click a step for the reasoning behind it.
A failing sensor produces a messy wrong answer: noise, dropouts, values that contradict themselves from one sample to the next, readings that drift outside anything physically sensible. An attacker producing a false reading has to make it believable, so the false answer is usually clean, internally consistent, and plausible on its own terms. A quantity that has moved somewhere wrong and then stayed there, steadily, is a stronger indicator of an actor than a quantity that is thrashing.
FLY THE MISSION IN ZENDIR
Zendir, the digital twin and mission simulation platform Kestrel procured, replicates your satellite operations center. Everything you rehearsed here you now do for real inside it: one mission objective and ten scored questions. The ten questions land on the three tests you just walked. Run it in three steps: take your assigned consoles, fly the one objective and answer the ten questions in platform where they are scored, then note the score and come back here for the debrief. Your facilitator provides Zendir access, and two things must be true before you fly.
This mission is worth 100 points, scored in-platform. Points accumulate across Missions One through Five, and the highest cumulative team finishes as the Top SCOR Team.
NOW THAT YOU ARE BACK
Zendir scored your mission out of 100 toward the Top SCOR Team standings. Note where you landed, then run the debrief while it is fresh. Work these three questions in order; the last one is the one that becomes an engineering update in the quarterly SCOR exercise.
Go around the crew once, one observation each, no discussion until everyone has spoken. Write the observations down before debating them; the first answer is usually the honest one.
RESPOND.
Mission Four is complete and scored. Mission Five reflies it with the incident already confirmed, so you act rather than decide whether to act, and this time the reaction wheel never recovers.
