{
  "schema": "meteorstorm-analytic-eten/v2",
  "platform": "Kestrel Orbital Day-1 CONOPS",
  "count": 16,
  "columns": [
    "eten",
    "layer",
    "tag",
    "label",
    "ordinal",
    "source",
    "target_type",
    "target_ref",
    "rds",
    "rss",
    "playbook",
    "resiliency_goal",
    "related_refs",
    "description",
    "roota"
  ],
  "entries": [
    {
      "eten": "AN:THR:Threat:00",
      "layer": "AN",
      "tag": "THR",
      "label": "Threat",
      "ordinal": "00",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "SVC:CP:Control Plane:09",
      "rds": "",
      "rss": "",
      "playbook": "",
      "resiliency_goal": "",
      "related_refs": "",
      "description": "state-sponsored actor gains persistent access to the SATCOM management network and abuses the provider-to-customer trust relationship to push a malicious modem update (KA-SAT / AcidRain class: the February 2022 attack that pushed a malicious modem update and disabled tens of thousands of terminals across Europe).",
      "roota": ""
    },
    {
      "eten": "AN:THR:Threat:01",
      "layer": "AN",
      "tag": "THR",
      "label": "Threat",
      "ordinal": "01",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:SW:Software:04",
      "rds": "",
      "rss": "",
      "playbook": "",
      "resiliency_goal": "",
      "related_refs": "",
      "description": "adversary with stolen or coerced command authority issues unauthorized telecommands to the on-orbit satellite.",
      "roota": ""
    },
    {
      "eten": "AN:THR:Threat:02",
      "layer": "AN",
      "tag": "THR",
      "label": "Threat",
      "ordinal": "02",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:SI:Signal:00",
      "rds": "",
      "rss": "",
      "playbook": "",
      "resiliency_goal": "",
      "related_refs": "",
      "description": "RF actor sustains noise injection across uplink/downlink bands to deny communications.",
      "roota": ""
    },
    {
      "eten": "AN:THR:Threat:03",
      "layer": "AN",
      "tag": "THR",
      "label": "Threat",
      "ordinal": "03",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:FW:Firmware:01",
      "rds": "",
      "rss": "",
      "playbook": "",
      "resiliency_goal": "",
      "related_refs": "",
      "description": "adversary subverts the flight-software update supply chain and pushes a backdoored firmware update to the operational satellite over the command-and-update path.",
      "roota": ""
    },
    {
      "eten": "AN:ATT:Attack Path:00",
      "layer": "AN",
      "tag": "ATT",
      "label": "Attack Path",
      "ordinal": "00",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "SVC:CP:Control Plane:09",
      "rds": "RDS:00 Management-network remote-access record @ SVC:CP:Control Plane:08 [unassessed]; RDS:01 Management-plane firmware-push operation record @ SVC:CP:Control Plane:09 [Available, src-ground-aca-010]; RDS:02 Terminal-fleet firmware inventory and deployed-hash record @ AST:SW:Software:03 [unassessed]",
      "rss": "RSS:00 Fleet-wide carrier and demodulator lock status at the gateway @ AST:SI:Signal:00 [unassessed]",
      "playbook": "",
      "resiliency_goal": "",
      "related_refs": "AN:THR:Threat:00",
      "description": "A state-sponsored actor reaches the SATCOM management network, abuses the legitimate modem management interface and the provider-to-customer trust relationship, and pushes a wiper as a firmware update, bricking the modem fleet (KA-SAT / AcidRain class).",
      "roota": ""
    },
    {
      "eten": "AN:ATT:Attack Path:01",
      "layer": "AN",
      "tag": "ATT",
      "label": "Attack Path",
      "ordinal": "01",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:SW:Software:04",
      "rds": "RDS:00 Operator console session record, host and sign-in time @ AST:HW:Hardware:04 [unassessed]; RDS:01 Command-authority usage record carrying the peer-review tag @ AST:SW:Software:04 [Partial, the peer-review tag stream depends on workflow adoption]; RDS:02 Control-plane command release record with review state @ SVC:CP:Control Plane:13 [unassessed]",
      "rss": "",
      "playbook": "",
      "resiliency_goal": "",
      "related_refs": "AN:THR:Threat:01",
      "description": "An adversary with stolen or coerced command authority issues unauthorized telecommands to the on-orbit satellite directly from a commanding workstation, bypassing peer review.",
      "roota": ""
    },
    {
      "eten": "AN:ATT:Attack Path:02",
      "layer": "AN",
      "tag": "ATT",
      "label": "Attack Path",
      "ordinal": "02",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:SI:Signal:00",
      "rds": "",
      "rss": "RSS:00 Uplink-band received power measurement @ SVC:HY:Hybrid:01 [unassessed]; RSS:01 Link noise-floor and carrier-to-noise measurement @ SVC:HY:Hybrid:02 [unassessed]; RSS:02 Receiver lock status and link-outage measurement @ AST:SI:Signal:00 [Available, src-rx-rf-024]",
      "playbook": "",
      "resiliency_goal": "",
      "related_refs": "AN:THR:Threat:02",
      "description": "Sustained RF noise injection across the uplink and downlink bands to deny communications, optionally timed to overhead passes.",
      "roota": ""
    },
    {
      "eten": "AN:ATT:Attack Path:03",
      "layer": "AN",
      "tag": "ATT",
      "label": "Attack Path",
      "ordinal": "03",
      "source": "observable",
      "target_type": "TOE",
      "target_ref": "AST:FW:Firmware:01",
      "rds": "RDS:00 Update-push activity record on the thermal control service @ SVC:CP:Control Plane:04 [unassessed]; RDS:01 Signed-manifest verification record @ SVC:CP:Control Plane:02 [unassessed]; RDS:02 Boot-time firmware measurement and attestation record @ AST:FW:Firmware:01 [Gap, measured boot is not flown; owner Satellite Design and Engineering]",
      "rss": "",
      "playbook": "",
      "resiliency_goal": "",
      "related_refs": "AN:THR:Threat:03",
      "description": "An adversary subverts the flight-software update supply chain and pushes a backdoored firmware update to the operational satellite over the command-and-update path, where it runs in orbit.",
      "roota": ""
    },
    {
      "eten": "AN:DET:Detection Signature:00",
      "layer": "AN",
      "tag": "DET",
      "label": "Detection Signature",
      "ordinal": "00",
      "source": "observable",
      "target_type": "TDM",
      "target_ref": "SVC:CP:Control Plane:09",
      "rds": "",
      "rss": "",
      "playbook": "PB-00",
      "resiliency_goal": "",
      "related_refs": "AN:ATT:Attack Path:00",
      "description": "Management-plane abuse: detects firmware-push operations from the modem management interface outside maintenance windows, or following a VPN-appliance authentication anomaly.",
      "roota": "an-det-00-mgmt-plane-abuse.yml"
    },
    {
      "eten": "AN:DET:Detection Signature:01",
      "layer": "AN",
      "tag": "DET",
      "label": "Detection Signature",
      "ordinal": "01",
      "source": "observable",
      "target_type": "TDM",
      "target_ref": "AST:SW:Software:04",
      "rds": "",
      "rss": "",
      "playbook": "PB-01",
      "resiliency_goal": "",
      "related_refs": "AN:ATT:Attack Path:01",
      "description": "Out-of-pattern command authority usage: detects commanding workstation usage outside the operator's normal hours, commands issued without peer review tags, or sequences inconsistent with the active mission profile.",
      "roota": "an-det-01-out-of-pattern-command.yml"
    },
    {
      "eten": "AN:DET:Detection Signature:02",
      "layer": "AN",
      "tag": "DET",
      "label": "Detection Signature",
      "ordinal": "02",
      "source": "observable",
      "target_type": "TDM",
      "target_ref": "AST:SI:Signal:00",
      "rds": "",
      "rss": "",
      "playbook": "PB-02",
      "resiliency_goal": "",
      "related_refs": "AN:ATT:Attack Path:02",
      "description": "Sustained noise-floor anomaly: detects elevated noise across the uplink or downlink bands beyond expected environmental thresholds, sustained for longer than incidental atmospheric events.",
      "roota": "an-det-02-rf-noise-floor-anomaly.yml"
    },
    {
      "eten": "AN:DET:Detection Signature:03",
      "layer": "AN",
      "tag": "DET",
      "label": "Detection Signature",
      "ordinal": "03",
      "source": "observable",
      "target_type": "TDM",
      "target_ref": "AST:FW:Firmware:01",
      "rds": "",
      "rss": "",
      "playbook": "PB-03",
      "resiliency_goal": "",
      "related_refs": "AN:ATT:Attack Path:03",
      "description": "Firmware-hash mismatch at boot: detects firmware images whose measured hash does not match the signed expected value at boot or after an update.",
      "roota": "an-det-03-firmware-hash-mismatch.yml"
    },
    {
      "eten": "AN:RES:Resilience Measure:00",
      "layer": "AN",
      "tag": "RES",
      "label": "Resilience Measure",
      "ordinal": "00",
      "source": "observable",
      "target_type": "TRE",
      "target_ref": "SVC:CP:Control Plane:09",
      "rds": "",
      "rss": "",
      "playbook": "",
      "resiliency_goal": "Anticipate",
      "related_refs": "AN:ATT:Attack Path:00",
      "description": "Air-gap or strict zero-trust segmentation of the device management plane from external networks; require hardware-rooted attestation on any management-plane access; gate firmware pushes behind dual-approval workflow with a maintenance-window enforcement.",
      "roota": ""
    },
    {
      "eten": "AN:RES:Resilience Measure:01",
      "layer": "AN",
      "tag": "RES",
      "label": "Resilience Measure",
      "ordinal": "01",
      "source": "observable",
      "target_type": "TRE",
      "target_ref": "AST:SW:Software:04",
      "rds": "",
      "rss": "",
      "playbook": "",
      "resiliency_goal": "Withstand",
      "related_refs": "AN:ATT:Attack Path:01",
      "description": "Dual-control commanding for high-impact actions (a second operator must approve before transmission); per-operator behavior baselines and pre-pass briefings make out-of-pattern actions stand out.",
      "roota": ""
    },
    {
      "eten": "AN:RES:Resilience Measure:02",
      "layer": "AN",
      "tag": "RES",
      "label": "Resilience Measure",
      "ordinal": "02",
      "source": "observable",
      "target_type": "TRE",
      "target_ref": "AST:SI:Signal:00",
      "rds": "",
      "rss": "",
      "playbook": "",
      "resiliency_goal": "Withstand",
      "related_refs": "AN:ATT:Attack Path:02",
      "description": "Frequency-agile / spread-spectrum link operation with pre-arranged backup band; Satellite Operations switches bands automatically when noise floor exceeds threshold; Satellite Design & Engineering owns the agility waveform.",
      "roota": ""
    },
    {
      "eten": "AN:RES:Resilience Measure:03",
      "layer": "AN",
      "tag": "RES",
      "label": "Resilience Measure",
      "ordinal": "03",
      "source": "observable",
      "target_type": "TRE",
      "target_ref": "AST:FW:Firmware:01",
      "rds": "",
      "rss": "",
      "playbook": "",
      "resiliency_goal": "Anticipate",
      "related_refs": "AN:ATT:Attack Path:03",
      "description": "Measured-boot firmware attestation with signed-vendor manifest; supply-chain provenance verification at integration; quarantine of any component whose hash does not match the signed expected value.",
      "roota": ""
    }
  ]
}
