{
  "schema": "meteorstorm-analytic-eten/v1",
  "platform": "Kestrel Orbital Day-1 CONOPS",
  "marking": "TLP:GREEN",
  "count": 16,
  "columns": [
    "eten",
    "layer",
    "tag",
    "label",
    "ordinal",
    "source",
    "target_type",
    "target_ref",
    "resiliency_goal",
    "related_refs",
    "description",
    "roota"
  ],
  "entries": [
    {
      "eten": "AN:THR:Threat:00:State-sponsored actor targeting the ground ACA management plane to push malicious modem updates.",
      "layer": "AN",
      "tag": "THR",
      "label": "Threat",
      "ordinal": "00",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "SVC:CP:Control Plane:09",
      "resiliency_goal": "",
      "related_refs": "AN:ATT:Attack Path:00; AN:DET:Detection Signature:00; AN:RES:Resilience Measure:00",
      "description": "State-sponsored actor with demonstrated capability to gain persistent access to SATCOM management networks and abuse the provider-to-customer trust relationship to push malicious modem updates (KA-SAT / AcidRain class). Source: composite OSINT threat assessment read against the peer-reviewed research paper.",
      "roota": ""
    },
    {
      "eten": "AN:THR:Threat:01:Cleared operator misusing the console software to issue unauthorized telecommands.",
      "layer": "AN",
      "tag": "THR",
      "label": "Threat",
      "ordinal": "01",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:SW:Software:04",
      "resiliency_goal": "",
      "related_refs": "AN:ATT:Attack Path:01; AN:DET:Detection Signature:01; AN:RES:Resilience Measure:01",
      "description": "Cleared operator with command authority misuses the commanding console software to issue unauthorized telecommands to the vehicle. Source: insider-threat reporting, MITRE ATT&CK T1078 Valid Accounts.",
      "roota": ""
    },
    {
      "eten": "AN:THR:Threat:02:RF actor jamming the uplink and downlink waveforms to deny command and telemetry.",
      "layer": "AN",
      "tag": "THR",
      "label": "Threat",
      "ordinal": "02",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:SI:Signal:00",
      "resiliency_goal": "",
      "related_refs": "AN:ATT:Attack Path:02; AN:DET:Detection Signature:02; AN:RES:Resilience Measure:02",
      "description": "RF actor sustains noise injection across the uplink and downlink bands to deny command and telemetry to the vehicle. Source: ITU interference reporting, documented SATCOM jamming campaigns.",
      "roota": ""
    },
    {
      "eten": "AN:THR:Threat:03:Adversary pushing a backdoored firmware image to the on-board computer over the update path.",
      "layer": "AN",
      "tag": "THR",
      "label": "Threat",
      "ordinal": "03",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:FW:Firmware:01",
      "resiliency_goal": "",
      "related_refs": "AN:ATT:Attack Path:03; AN:DET:Detection Signature:03; AN:RES:Resilience Measure:03",
      "description": "Adversary subverts the flight-software update supply chain and pushes a backdoored firmware image to the on-board computer over the command-and-update path. Source: NIST SP 800-193, SolarWinds supply-chain reporting.",
      "roota": ""
    },
    {
      "eten": "AN:ATT:Attack Path:00:Management-plane entry pivoting through the ground ACA onto the patch path to push a wiper as a firmware update.",
      "layer": "AN",
      "tag": "ATT",
      "label": "Attack Path",
      "ordinal": "00",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "SVC:CP:Control Plane:09",
      "resiliency_goal": "",
      "related_refs": "realizes AN:THR:Threat:00",
      "description": "Anchored to the ground ACA management plane, SVC:CP:Control Plane:09. Pivot: entry through the external VPN appliance into the management network, abuse of the ground ACA, through the ACA software (AST:SW:Software:02) and credential store (AST:DA:Data:01) onto the patch path (SVC:CP:Control Plane:12), objective a wiper pushed as a firmware update, modems bricked. Source: Space ISAC advisory, KA-SAT / AcidRain reporting.",
      "roota": ""
    },
    {
      "eten": "AN:ATT:Attack Path:01:Authenticated operator issuing unauthorized telecommands from the console, bypassing single-operator review.",
      "layer": "AN",
      "tag": "ATT",
      "label": "Attack Path",
      "ordinal": "01",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:SW:Software:04",
      "resiliency_goal": "",
      "related_refs": "realizes AN:THR:Threat:01",
      "description": "Anchored to the console operator software, AST:SW:Software:04. Pivot: authenticated operator on the console software issues unauthorized telecommands through the satellite console service (SVC:CP:Control Plane:13), bypassing single-operator review at the ground ACA (SVC:CP:Control Plane:09), objective an out-of-profile command to the vehicle. Source: insider-threat reporting.",
      "roota": ""
    },
    {
      "eten": "AN:ATT:Attack Path:02:Sustained RF noise on the waveforms overwhelming FEC and tracking to deny command and telemetry.",
      "layer": "AN",
      "tag": "ATT",
      "label": "Attack Path",
      "ordinal": "02",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:SI:Signal:00",
      "resiliency_goal": "",
      "related_refs": "realizes AN:THR:Threat:02",
      "description": "Anchored to the uplink and downlink waveforms, AST:SI:Signal:00. Pivot: RF actor injects sustained noise onto the waveforms, overwhelming forward-error correction (SVC:HY:Hybrid:01) and tracking and telemetry (SVC:HY:Hybrid:02), objective denial of command and telemetry. Source: documented jamming campaigns.",
      "roota": ""
    },
    {
      "eten": "AN:ATT:Attack Path:03:Backdoored image staged in the patch pipeline and booted by the on-board computer for persistent control.",
      "layer": "AN",
      "tag": "ATT",
      "label": "Attack Path",
      "ordinal": "03",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:FW:Firmware:01",
      "resiliency_goal": "",
      "related_refs": "realizes AN:THR:Threat:03",
      "description": "Anchored to the on-board computer boot firmware, AST:FW:Firmware:01. Pivot: backdoored image staged in the patch pipeline (AST:SW:Software:03), pushed over the command-and-update path (SVC:CP:Control Plane:12), booted by the on-board computer, objective persistent control of the OBC. Source: NIST SP 800-193.",
      "roota": ""
    },
    {
      "eten": "AN:DET:Detection Signature:00:RootA signature for the chain-00 behavior on SVC:CP:Control Plane:09.",
      "layer": "AN",
      "tag": "DET",
      "label": "Detection Signature",
      "ordinal": "00",
      "source": "observable",
      "target_type": "TDM",
      "target_ref": "SVC:CP:Control Plane:09",
      "resiliency_goal": "",
      "related_refs": "covers AN:ATT:Attack Path:00; AN:THR:Threat:00",
      "description": "RootA rule KO-DET-ACA-MGMT-PUSH-000: Firmware push from ground ACA management interface outside maintenance window. Covers AN:ATT:Attack Path:00 and AN:THR:Threat:00.",
      "roota": "name: KO-DET-ACA-MGMT-PUSH-000\ntitle: Firmware push from ground ACA management interface outside maintenance window\nseverity: high\ntype: query\nclass: behavioral\ndate: 2026-07-26\nmitre-attack:\n  - t1195.002\ndetection:\n  language: splunk-spl-query\n  body: index=ground_aca sourcetype=mgmt action=firmware_push | where in_maintenance_window=false OR vpn_auth_anomaly=true\nlogsource:\n  product: ground-aca\n  service: management-plane\nreferences:\n  - AN:ATT:Attack Path:00\n  - AN:THR:Threat:00\ntags: KO-DET-ACA-MGMT-PUSH-000, acidrain, ground-aca\nlicense: DRL 1.1\nversion: 1\nuuid: a1b2c3d4-0000-4a00-8a00-000000000000\nmeteorstorm:\n  pce: PCE:TE:Terrestrial:00\n  seg: SEG:GR:Ground:00\n  svc: SVC:CP:Control Plane:09\n  an:\n    eten: AN:DET:Detection Signature:00\n    tdm: SVC:CP:Control Plane:09"
    },
    {
      "eten": "AN:DET:Detection Signature:01:RootA signature for the chain-01 behavior on AST:SW:Software:04.",
      "layer": "AN",
      "tag": "DET",
      "label": "Detection Signature",
      "ordinal": "01",
      "source": "observable",
      "target_type": "TDM",
      "target_ref": "AST:SW:Software:04",
      "resiliency_goal": "",
      "related_refs": "covers AN:ATT:Attack Path:01; AN:THR:Threat:01",
      "description": "RootA rule KO-DET-CONSOLE-OOP-001: Out-of-pattern commanding from the operator console. Covers AN:ATT:Attack Path:01 and AN:THR:Threat:01.",
      "roota": "name: KO-DET-CONSOLE-OOP-001\ntitle: Out-of-pattern commanding from the operator console\nseverity: high\ntype: query\nclass: behavioral\ndate: 2026-07-26\nmitre-attack:\n  - t1078\ndetection:\n  language: splunk-spl-query\n  body: index=console sourcetype=command | where hour_of_day NOT IN (operator_shift) OR peer_review_tag=null OR off_mission_profile=true\nlogsource:\n  product: console-ops\n  service: command-audit\nreferences:\n  - AN:ATT:Attack Path:01\n  - AN:THR:Threat:01\ntags: KO-DET-CONSOLE-OOP-001, insider, console\nlicense: DRL 1.1\nversion: 1\nuuid: a1b2c3d4-0001-4a00-8a00-000000000000\nmeteorstorm:\n  pce: PCE:TE:Terrestrial:00\n  seg: SEG:GR:Ground:00\n  svc: SVC:CP:Control Plane:13\n  ast: AST:SW:Software:04\n  an:\n    eten: AN:DET:Detection Signature:01\n    tdm: AST:SW:Software:04"
    },
    {
      "eten": "AN:DET:Detection Signature:02:RootA signature for the chain-02 behavior on AST:SI:Signal:00.",
      "layer": "AN",
      "tag": "DET",
      "label": "Detection Signature",
      "ordinal": "02",
      "source": "observable",
      "target_type": "TDM",
      "target_ref": "AST:SI:Signal:00",
      "resiliency_goal": "",
      "related_refs": "covers AN:ATT:Attack Path:02; AN:THR:Threat:02",
      "description": "RootA rule KO-DET-RF-NOISE-002: Sustained noise-floor anomaly on the uplink and downlink bands. Covers AN:ATT:Attack Path:02 and AN:THR:Threat:02.",
      "roota": "name: KO-DET-RF-NOISE-002\ntitle: Sustained noise-floor anomaly on the uplink and downlink bands\nseverity: high\ntype: query\nclass: behavioral\ndate: 2026-07-26\ndetection:\n  language: splunk-spl-query\n  body: index=rf_metrics | stats avg(noise_floor_db) as nf by band, _time span=5m | where nf > env_threshold_db AND sustained_minutes > 10\nlogsource:\n  product: rf-frontend\n  service: snr-telemetry\nreferences:\n  - AN:ATT:Attack Path:02\n  - AN:THR:Threat:02\ntags: KO-DET-RF-NOISE-002, jamming, rf\nlicense: DRL 1.1\nversion: 1\nuuid: a1b2c3d4-0002-4a00-8a00-000000000000\nmeteorstorm:\n  pce: PCE:TE:Terrestrial:01\n  seg: SEG:LI:Link:00\n  svc: SVC:HY:Hybrid:02\n  ast: AST:SI:Signal:00\n  an:\n    eten: AN:DET:Detection Signature:02\n    tdm: AST:SI:Signal:00"
    },
    {
      "eten": "AN:DET:Detection Signature:03:RootA signature for the chain-03 behavior on AST:FW:Firmware:01.",
      "layer": "AN",
      "tag": "DET",
      "label": "Detection Signature",
      "ordinal": "03",
      "source": "observable",
      "target_type": "TDM",
      "target_ref": "AST:FW:Firmware:01",
      "resiliency_goal": "",
      "related_refs": "covers AN:ATT:Attack Path:03; AN:THR:Threat:03",
      "description": "RootA rule KO-DET-FW-HASH-003: Firmware hash mismatch at boot on the on-board computer. Covers AN:ATT:Attack Path:03 and AN:THR:Threat:03.",
      "roota": "name: KO-DET-FW-HASH-003\ntitle: Firmware hash mismatch at boot on the on-board computer\nseverity: high\ntype: query\nclass: behavioral\ndate: 2026-07-26\nmitre-attack:\n  - t1542\ndetection:\n  language: splunk-spl-query\n  body: index=obc_boot sourcetype=attestation | where measured_hash != signed_expected_hash\nlogsource:\n  product: obc\n  service: boot-attestation\nreferences:\n  - AN:ATT:Attack Path:03\n  - AN:THR:Threat:03\ntags: KO-DET-FW-HASH-003, supply-chain, firmware\nlicense: DRL 1.1\nversion: 1\nuuid: a1b2c3d4-0003-4a00-8a00-000000000000\nmeteorstorm:\n  pce: PCE:OR:Orbital:00\n  seg: SEG:SP:Space:00\n  svc: SVC:HY:Hybrid:00\n  ast: AST:FW:Firmware:01\n  an:\n    eten: AN:DET:Detection Signature:03\n    tdm: AST:FW:Firmware:01"
    },
    {
      "eten": "AN:RES:Resilience Measure:00:Zero-trust segmentation and dual-approval on the ground ACA management plane.",
      "layer": "AN",
      "tag": "RES",
      "label": "Resilience Measure",
      "ordinal": "00",
      "source": "observable",
      "target_type": "TRE",
      "target_ref": "SVC:CP:Control Plane:09",
      "resiliency_goal": "Withstand",
      "related_refs": "counters AN:ATT:Attack Path:00; AN:THR:Threat:00",
      "description": "Zero-trust segmentation of the ground ACA management plane from external networks, with hardware-rooted attestation and dual-approval on every management-plane action. Protects SVC:CP:Control Plane:09. Source: internal engineering, KA-SAT / AcidRain lesson.",
      "roota": ""
    },
    {
      "eten": "AN:RES:Resilience Measure:01:Dual-control commanding and per-operator baselines in the console software.",
      "layer": "AN",
      "tag": "RES",
      "label": "Resilience Measure",
      "ordinal": "01",
      "source": "observable",
      "target_type": "TRE",
      "target_ref": "AST:SW:Software:04",
      "resiliency_goal": "Withstand",
      "related_refs": "counters AN:ATT:Attack Path:01; AN:THR:Threat:01",
      "description": "Dual-control commanding for high-impact actions, a second operator approving before transmission, with per-operator behavior baselines and pre-pass briefings enforced in the console software. Protects AST:SW:Software:04. Source: internal engineering.",
      "roota": ""
    },
    {
      "eten": "AN:RES:Resilience Measure:02:Frequency-agile spread-spectrum link with automatic band switch on noise threshold.",
      "layer": "AN",
      "tag": "RES",
      "label": "Resilience Measure",
      "ordinal": "02",
      "source": "observable",
      "target_type": "TRE",
      "target_ref": "AST:SI:Signal:00",
      "resiliency_goal": "Withstand",
      "related_refs": "counters AN:ATT:Attack Path:02; AN:THR:Threat:02",
      "description": "Frequency-agile, spread-spectrum link operation with a pre-arranged backup band; Satellite Operations switches bands automatically when the noise floor exceeds threshold; Satellite Design and Engineering owns the agility waveform. Protects AST:SI:Signal:00. Source: internal engineering.",
      "roota": ""
    },
    {
      "eten": "AN:RES:Resilience Measure:03:Measured-boot attestation with signed-vendor manifest and hash-mismatch quarantine.",
      "layer": "AN",
      "tag": "RES",
      "label": "Resilience Measure",
      "ordinal": "03",
      "source": "observable",
      "target_type": "TRE",
      "target_ref": "AST:FW:Firmware:01",
      "resiliency_goal": "Anticipate",
      "related_refs": "counters AN:ATT:Attack Path:03; AN:THR:Threat:03",
      "description": "Measured-boot firmware attestation with a signed-vendor manifest, supply-chain provenance verification at integration, and quarantine of any image whose hash does not match the signed expected value. Protects AST:FW:Firmware:01. Source: internal engineering, NIST SP 800-193.",
      "roota": ""
    }
  ]
}