01
A space-operations analyst leaning toward a console showing an anomalous telemetry waveform, hand poised above an acknowledge keypad, a second operator turning toward the alert
MISSION FOURDETECT
Mission Four
DETECT.
“An alert is a hypothesis. An incident is a confirmed fact.”

Three things go wrong on this flight and they do not share a cause. Mission Four is scored on whether you can tell which is which with the clock running.

MODULE NINE
01/07
02
Brief

BRIEF THE MISSION

Mission Four is the first flight where the platform acts on you. A shorter, faster run over five ground stations spread across the Pacific and the Americas, with events firing while you work. Several things go wrong and they do not all have the same cause, which is the whole exercise: detect, then confirm, because an alert is not an incident.

▷ Scenario
Orbit regime
Medium Earth orbit, circular
Altitude
About 2,222 km
Inclination
70 degrees
Run
4800 seconds at 2.0x
Ground stations
Tokyo, Anchorage, Houston, Lima, Santiago
Scripted events
Yes, events will fire
▷ Your objective

Detect and confirm, because an alert is not an incident.

MODULE NINE
02/07
03
Mission Four · what each role detects

WHAT YOU DETECT

Three things go wrong on this flight and they do not share a cause. Two are an adversary and one is a part that failed on its own. An alert is a hypothesis; an incident is a confirmed threat, and the gap between them is where this mission is won or lost. Click a role to see what it holds this mission.

▷ MISSION LEAD

You confirm, and you separate. Not everything that broke was broken by somebody.

Focus: confirm, then sort.
  • · Judge which alert is a natural hardware fault rather than adversary activity
  • · Decide which alerts belong in the cyber detection report to command leadership
  • · Log the reaction-wheel fault as a hardware issue, separate from the cyber report
  • · Sign every escalation
A mission lead standing at a supervisory console directing the team, with overview screens behind
EXPECT THE ORDINARY · One of the anomalies is genuine hardware. Reporting it as an attack is the error that discredits the findings that were real.
MODULE NINE
03/07
04
Method

FAULT OR ATTACK

Mission Three taught you the discriminator with time to think. Mission Four asks for it live, with several things wrong at once and a clock running. Three tests settle almost every case, and they run in seconds. Click a step for the reasoning behind it.

▷ Three tests, then separate
Is the wrong answer a tidy one?

A failing sensor produces a messy wrong answer: noise, dropouts, values that contradict themselves from one sample to the next, readings that drift outside anything physically sensible. An attacker producing a false reading has to make it believable, so the false answer is usually clean, internally consistent, and plausible on its own terms. A quantity that has moved somewhere wrong and then stayed there, steadily, is a stronger indicator of an actor than a quantity that is thrashing.

MODULE NINE
04/07
05
Simulate

FLY THE MISSION IN ZENDIR

Zendir, the digital twin and mission simulation platform Kestrel procured, replicates your satellite operations center. Everything you rehearsed here you now do for real inside it: one mission objective and ten scored questions. The ten questions land on the three tests you just walked. Run it in three steps: take your assigned consoles, fly the one objective and answer the ten questions in platform where they are scored, then note the score and come back here for the debrief. Your facilitator provides Zendir access, and two things must be true before you fly.

▷ Before you fly · your attestation
▸ Attest to both before you fly
▷ Scored in Zendir

This mission is worth 100 points, scored in-platform. Points accumulate across Missions One through Five, and the highest cumulative team finishes as the Top SCOR Team.

▷ Sign-off ready
MODULE NINE
05/07
06
Return

NOW THAT YOU ARE BACK

Zendir scored your mission out of 100 toward the Top SCOR Team standings. Note where you landed, then run the debrief while it is fresh. Work these three questions in order; the last one is the one that becomes an engineering update in the quarterly SCOR exercise.

▷ Debrief · 01
What did the platform show you that the deck did not?
The gap between rehearsal and a live console is where the real learning sits.
▷ How to run it

Go around the crew once, one observation each, no discussion until everyone has spoken. Write the observations down before debating them; the first answer is usually the honest one.

MODULE NINE
06/07
END
RESPONDMISSION FIVEMODULE 10
Mission Four complete · Mission Five next

RESPOND.

Mission Four is complete and scored. Mission Five reflies it with the incident already confirmed, so you act rather than decide whether to act, and this time the reaction wheel never recovers.

CARRY FORWARD
Which findings you confirmed, and which you correctly kept out of the report.
IN MISSION FIVE
Scope, containment, recovery from a known-good source, and the one change that closes it.
MODULE NINE
07/07
REFERENCE LIBRARY

Standards, Policies & Sources

The instruments this course aligns to. Each element links to its primary source.

U.S. National Security Space Policy

CNSS Policy No. 12 (CNSSP-12)Information-assurance policy for national security space systems.CNSS Instruction 1200 (CNSSI 1200), Aug 2025Implementing requirements: on-board intrusion detection, hardware root-of-trust, patch management.DoDI 8581.01Information-assurance policy for space systems used by the DoD.Space Policy Directive 5 (SPD-5), 2020First comprehensive U.S. cybersecurity principles for space systems.

Executive Orders

EO 14144 (Jan 16, 2025)Strengthening and Promoting Innovation in the Nation’s Cybersecurity.EO 14306 (Jun 6, 2025)Sustaining select efforts, amending EO 13694 and EO 14144.

NIST Standards & FISMA

NIST SP 800-53 Rev. 5Security and privacy controls; IR-3 incident-response testing.NIST SP 800-37 Rev. 2Risk Management Framework; continuous monitoring and annual control assessment.NIST IR 8270Introduction to Cybersecurity for Commercial Satellite Operations.NIST IR 8401Satellite Ground Segment cybersecurity framework profile.NIST IR 8441Cybersecurity Framework Profile for Hybrid Satellite Networks.NIST SP 800-160 Vol. 2 Rev. 1Cyber resiliency goals: Anticipate, Withstand, Recover, Adapt.FISMAFederal Information Security Modernization Act; annual program review obligation.

Threat Frameworks (analytic layer)

MITRE ATT&CKAdversary tactics and techniques knowledge base.MITRE CAPECCommon Attack Pattern Enumeration and Classification; dictionary of attack patterns that exploit known weaknesses.MITRE D3FENDKnowledge graph of defensive countermeasures and techniques, mapped to ATT&CK (NSA-funded, maintained by MITRE).SPARTASpace Attack Research and Tactic Analysis (The Aerospace Corporation).ESA Space ShieldEuropean Space Agency space-system threat framework.

EU & Global

NIS2 Directive (EU 2022/2555)Risk management and 24h/72h incident reporting; space sector in scope.EU Space Act (proposal, 25 Jun 2025)Space-specific resilience and cybersecurity obligations; extraterritorial scope.ENISA Space Threat LandscapeEuropean threat landscape and recommendations for space operators.Cyber Resilience Act (CRA)Connected hardware/software requirements; applies from December 2027.

Open-Source Vocabulary & Tooling

METEORSTORM MISP taxonomyThe course vocabulary, live and open source in the MISP taxonomy repository.MISP / CIRCLComputer Incident Response Center Luxembourg, maintainers of MISP.RootAPublic-domain open detection language (YAML) used in Module 04 to write portable signatures. (github.com/UncoderIO/Roota)Uncoder.IOOpen-source IDE and translation engine that ports RootA rules across SIEM, EDR, and XDR formats.SpaceCOP & Indicators of BehaviorDHS S&T + Aerospace Corp. on-board intrusion-detection prototype.CROO (Cyber Resilience On-Orbit)Proof Labs on-board IDS for the Space Force.

Community & Reporting

Space ISACSpace Information Sharing and Analysis Center.Air & Space Forces MagazineWaterman, “New Cybersecurity Rules for Pentagon’s Commercial Satellite Vendors,” Nov 19, 2025.Via Satellite“DHS Wants Satellite Volunteers to Test New Cyber Tools,” Nov 17, 2025.Defense Daily“New National Space Cybersecurity Policy Emphasizes Intrusion Detection,” Nov 18, 2025.Mayer Brown legal analysis“Securing the Final Frontier,” Dec 11, 2025 (US and EU regulatory map).