Reference card.

Downloads ▾
← Back to course
TLP:GREEN Limited Disclosure · SCORP² community members only
Exported by: verifying identity… Exported at:
Distribution notice. This document is for active SCORP² community members only. Unauthorized distribution will result in revocation of community membership.

Kestrel Orbital Day 1-5 Analytic Layer

Enumerated Taxonomic Element Nomenclature (ETEN) reference

An analytic Enumerated Taxonomic Element Nomenclature (ETEN) names one enrichment element on a platform, in five fields. An enrichment element is an indicator of compromise, an indicator of attack, an attack path, a threat, a detection signature, or a resilience measure, and it enriches the platform's Resilient Cyber Operations context by anchoring to the platform element it concerns.

Resilient Cyber Operations prioritizes real-world information sharing: by default an indicator of compromise, an indicator of attack, an attack path, or a threat is real world, ideally confirmed with a space collective defense community member. The framework also serves exercises and modeling, with one intent: developing real-world detection signatures and resilience measures from simulated activity.

ETEN Example

Layer
AN
Tag
THR
Label
Threat
Ordinal
02
Source
observable
TOE
SVC:CP:Control Plane:09
Description
State-sponsored actor with demonstrated capability to gain persistent access to SATCOM management networks and abuse the provider-to-customer trust relationship to push malicious modem updates (KA-SAT / AcidRain class). Source: composite OSINT threat assessment read against the peer-reviewed research paper.
ETEN
AN:THR:Threat:02:State-sponsored actor targeting the ground ACA management plane to push malicious modem updates.

The Analytic Layer, Overview

Enrichment
The four structural layers (PCE, SEG, SVC, AST) enumerate the platform. The Analytic Layer enriches that decomposition: each AN entry is an enrichment element recording what the analyst knows about specific platform elements. It takes no PARENT; it is not part of the platform.
Taxonomy
Each entry is classified by LAYER, TAG, and LABEL: six elements, AN-IOC, AN-IOA, AN-ATT, AN-THR, AN-DET, AN-RES.
Ontology
Where structural elements bind upward through PARENT, an enrichment element binds through its target reference: TOE for IOC, IOA, ATT, and THR; TDM for DET; TRE for RES. The target is fixed by the tag. The anchor is machine-readable, so an entry enumerated against an AST is reachable from queries against the SVC, SEG, and PCE above it. An anchor names a platform element, never another enrichment element.
THE GATE. The analytic layer was developed for front-line space collective defense. The intent of the layer: entries move operator to operator as machine-to-machine exchange across a trusted network, and a peer acts on an entry without renegotiating its provenance. That intent holds only if every entry declares its SOURCE before enumeration.
observable
Built on a real-world report: a signal or data captured from a system. The standard for IOC, IOA, ATT, THR.
synthetic
Authored data for system resilience engineering and operational exercises.
Collective defense. Under the Space ISAC Exchange sharing mandate (Space Information Sharing and Analysis Center), every finding relevant to Executive Order 14144 or the NIS2 Directive is shared: the indicators, the tactics and techniques, the affected ETENs, and the detection signatures in an open format, so peer operators defend before they are hit. An incoming peer finding enters this catalogue only after peer validation, normalized with its provenance recorded: source framework, source id, source name.

The enumeration that produces every analytic ETEN is governed by the normative process: the source is confirmed at THE GATE, the taxonomy supplies the tag and label, and the target reference anchors the entry to the platform. Each element walks its own six-step process in its section.

The Kestrel Enumeration

The analytic layer is built across Modules 2 to 5, one function per module, against the Day-1 CONOPS: 4 threats in Module 2, 4 attack paths in Module 3, 4 detection signatures in Module 4, and 4 resilience measures in Module 5, 16 enumerated elements in four chains. The contextualized threat model is the Module 2 output, the threats; each later function builds on it. AN-IOC and AN-IOA are live-incident artifacts recorded during operations, not produced by these functions. The platform elements every entry anchors to are in the structural ETEN reference; the analytic element definitions are in the analytic TEN reference.

The analytic layer, built across Modules 2 to 5 One function per module. Each function consumes the one before it and yields one analytic element type, anchored to the platform through its target field. MODULE 2 Contextualized Threat Modeling AN-THR Threats (4) anchors via TOE MODULE 3 Converged Detection Engineering AN-ATT Attack Paths (4) anchors via TOE MODULE 4 Incident Response Preparation AN-DET Detection Signatures (4) anchors via TDM MODULE 5 Adversary Management AN-RES Resilience Measures (4) anchors via TRE The contextualized threat model is the Module 2 output, the threats; attack paths, detection signatures, and resilience measures build on it in turn. AN-IOC and AN-IOA are live-incident artifacts recorded during operations, not produced by these functions.
The analytic layer across Modules 2 to 5. Contextualized Threat Modeling yields the AN-THR threats; Converged Detection Engineering the AN-ATT attack paths; Incident Response Preparation the AN-DET detection signatures; Adversary Management the AN-RES resilience measures. Each anchors to the platform through its target field, TOE, TDM, or TRE.

L5AN-THR · Threats (4)

Definition: “Known adversarial threat to the platform” (METEORSTORM:AN=THR)

A Threat is the targeted statement: a known adversary capability or campaign directed at the platform or its class of systems. Where an Attack Path records what the platform exposes, a Threat records who or what is likely to exercise that exposure. The two work as a pair: a path with no threat is a hypothetical, and a threat with no path is unmoored from the architecture. Every entry is built on attributed adversary activity: threat-intelligence reporting, government attribution, or a peer-shared adversary profile, so the community reads every threat as evidenced, not assumed.

The three departments, at the table. SCOR runs Function 02, Contextualized Threat Modeling, with all three departments. The Security Operations Center brings the threat intelligence and attribution; the Satellite Operations Center brings the operational picture, what normal commanding and passes look like, so each threat anchors to the right element; Satellite Design and Engineering brings the architecture, confirming which enumerated element a threat can actually reach. The output is the contextualized threat model: every AN-THR anchored by TOE to the platform element it targets.

AN-THR ETEN Process

Step 01
Enumerate the LAYER. AN (fixed).
Step 02
Confirm the source. The threat-intelligence report, government attribution statement, peer-shared adversary profile, or open-source intelligence the threat is drawn from. The source defines the TOE. SOURCE is observable or synthetic.
Step 03
Set the TAG to THR. AN:THR.
Step 04
Assign an ORDINAL. Two digits from 00, one per distinct threat.
Step 05
Enumerate the TOE. One enumerated platform element (PCE, SEG, SVC, or AST) the source states the threat is directed against. Concrete, not broad, at the lowest layer the source resolves.
Step 06
Write the DESCRIPTION. The threat actor or threat class, the assessed capability, plus the source citation. The line a peer operator or peer machine acts on.
AN-THR anchors · TOE, Target of Exploitation AN:THR:Threat:00 state-sponsored SATCOM management actor TOE SVC:CP:Control Plane:09 AN:THR:Threat:01 cleared operator, console misuse TOE AST:SW:Software:04 AN:THR:Threat:02 RF jamming actor TOE AST:SI:Signal:00 AN:THR:Threat:03 supply-chain firmware actor TOE AST:FW:Firmware:01
Each AN-THR entry with its one TOE target, the enumerated platform element from its catalogue entry, in the layer colours of the structural ETEN reference.

Examples, field by field (4)

FieldValue
LAYERAN
TAGTHR
LABELThreat
ORDINAL00
SOURCEobservable
TOESVC:CP:Control Plane:09
DESCRIPTIONState-sponsored actor with demonstrated capability to gain persistent access to SATCOM management networks and abuse the provider-to-customer trust relationship to push malicious modem updates (KA-SAT / AcidRain class). Source: composite OSINT threat assessment read against the peer-reviewed research paper.
ETENAN:THR:Threat:00:State-sponsored actor targeting the ground ACA management plane to push malicious modem updates.
FieldValue
LAYERAN
TAGTHR
LABELThreat
ORDINAL01
SOURCEobservable
TOEAST:SW:Software:04
DESCRIPTIONCleared operator with command authority misuses the commanding console software to issue unauthorized telecommands to the vehicle. Source: insider-threat reporting, MITRE ATT&CK T1078 Valid Accounts.
ETENAN:THR:Threat:01:Cleared operator misusing the console software to issue unauthorized telecommands.
FieldValue
LAYERAN
TAGTHR
LABELThreat
ORDINAL02
SOURCEobservable
TOEAST:SI:Signal:00
DESCRIPTIONRF actor sustains noise injection across the uplink and downlink bands to deny command and telemetry to the vehicle. Source: ITU interference reporting, documented SATCOM jamming campaigns.
ETENAN:THR:Threat:02:RF actor jamming the uplink and downlink waveforms to deny command and telemetry.
FieldValue
LAYERAN
TAGTHR
LABELThreat
ORDINAL03
SOURCEobservable
TOEAST:FW:Firmware:01
DESCRIPTIONAdversary subverts the flight-software update supply chain and pushes a backdoored firmware image to the on-board computer over the command-and-update path. Source: NIST SP 800-193, SolarWinds supply-chain reporting.
ETENAN:THR:Threat:03:Adversary pushing a backdoored firmware image to the on-board computer over the update path.

L5AN-ATT · Attack Paths (4)

Definition: “Known attack path for a converged space system” (METEORSTORM:AN=ATT)

An Attack Path is a conditional statement: a documented sequence of adversary actions that could traverse the platform from entry to impact. Attack Paths are exposures, not observations; they record what is reachable given the architecture. Each one is drawn from real-world reporting: a confirmed exposure observed against the platform or a trusted partner, or documented adversary tradecraft, so the community reads every path as grounded, not guessed.

The three departments, converged. SCOR runs Function 03, Converged Detection Engineering, across the same three. The Security Operations Center traces how an adversary moves to realize each threat; the Satellite Operations Center confirms which moves are visible in operations; Satellite Design and Engineering names the data and signal sources on each element. The output is the AN-ATT attack paths, each anchored to the same element as the threat it realizes, with the pivot in its description.

AN-ATT ETEN Process

Step 01
Enumerate the LAYER. AN (fixed).
Step 02
Confirm the source. The confirmed exposure, red-team report, adversary-behavior catalogue entry (ATT&CK, SPARTA, ATLAS), or peer-shared documentation the path is drawn from. The source defines the TOE. SOURCE is observable or synthetic.
Step 03
Set the TAG to ATT. AN:ATT.
Step 04
Assign an ORDINAL. Two digits from 00, one per distinct path.
Step 05
Enumerate the TOE. One enumerated platform element: the element the path is anchored to, the same element the related AN-THR names. Concrete, at the lowest layer the source resolves.
Step 06
Write the DESCRIPTION. The pivot, entry to objective, in enough detail for another analyst to evaluate it against their own platform, plus the source citation.
AN-ATT anchors · TOE, Target of Exploitation AN:ATT:Attack Path:00 management-plane entry, firmware push TOE SVC:CP:Control Plane:09 AN:ATT:Attack Path:01 unauthorized console telecommands TOE AST:SW:Software:04 AN:ATT:Attack Path:02 sustained RF noise on waveforms TOE AST:SI:Signal:00 AN:ATT:Attack Path:03 backdoored image booted by OBC TOE AST:FW:Firmware:01
Each AN-ATT entry with its one TOE target, the enumerated platform element from its catalogue entry, in the layer colours of the structural ETEN reference.

Examples, field by field (4)

FieldValue
LAYERAN
TAGATT
LABELAttack Path
ORDINAL00
SOURCEobservable
TOESVC:CP:Control Plane:09
DESCRIPTIONAnchored to the ground ACA management plane, SVC:CP:Control Plane:09. Pivot: entry through the external VPN appliance into the management network, abuse of the ground ACA (SVC:CP:Control Plane:09), through the ACA software (AST:SW:Software:02) and credential store (AST:DA:Data:01) onto the patch path (SVC:CP:Control Plane:12), objective a wiper pushed as a firmware update, modems bricked. Source: Space ISAC advisory, KA-SAT / AcidRain reporting.
ETENAN:ATT:Attack Path:00:Management-plane entry pivoting through the ground ACA onto the patch path to push a wiper as a firmware update.
FieldValue
LAYERAN
TAGATT
LABELAttack Path
ORDINAL01
SOURCEobservable
TOEAST:SW:Software:04
DESCRIPTIONAnchored to the console operator software, AST:SW:Software:04. Pivot: authenticated operator on the console software issues unauthorized telecommands through the satellite console service (SVC:CP:Control Plane:13), bypassing single-operator review at the ground ACA (SVC:CP:Control Plane:09), objective an out-of-profile command to the vehicle. Source: insider-threat reporting.
ETENAN:ATT:Attack Path:01:Authenticated operator issuing unauthorized telecommands from the console, bypassing single-operator review.
FieldValue
LAYERAN
TAGATT
LABELAttack Path
ORDINAL02
SOURCEobservable
TOEAST:SI:Signal:00
DESCRIPTIONAnchored to the uplink and downlink waveforms, AST:SI:Signal:00. Pivot: RF actor injects sustained noise onto the waveforms, overwhelming forward-error correction (SVC:HY:Hybrid:01) and tracking and telemetry (SVC:HY:Hybrid:02), objective denial of command and telemetry. May be paired with timing knowledge of overhead passes. Source: documented jamming campaigns.
ETENAN:ATT:Attack Path:02:Sustained RF noise on the waveforms overwhelming FEC and tracking to deny command and telemetry.
FieldValue
LAYERAN
TAGATT
LABELAttack Path
ORDINAL03
SOURCEobservable
TOEAST:FW:Firmware:01
DESCRIPTIONAnchored to the on-board computer boot firmware, AST:FW:Firmware:01. Pivot: backdoored image staged in the patch pipeline (AST:SW:Software:03), pushed over the command-and-update path (SVC:CP:Control Plane:12), booted by the on-board computer, objective persistent control of the OBC. Source: NIST SP 800-193.
ETENAN:ATT:Attack Path:03:Backdoored image staged in the patch pipeline and booted by the on-board computer for persistent control.

L5AN-DET · Detection Signatures (4)

Definition: “Pattern, signal, or logic that triggers on contextualized threat behavior, expressed in RootA format” (METEORSTORM:AN=DET)

A Detection Signature is the coverage statement: the written commitment to see a specific behavior when it produces observable activity. A threat or attack path with no matching signature is a detection gap, and the gap is itself an enumerable analytic product. Every entry is a complete RootA rule (SOC Prime RootA specification v1.0.0), the open, vendor-neutral wrapper over the native query language it was authored in, extended with a METEORSTORM block that anchors the rule to its enumerated platform element, so a signature written by one operator deploys and routes in another operator’s stack without translation. In the ontology, AN-DET binds through TDM, Target of Detection Method: the element the signature observes, which may differ from the elements it protects.

The three departments, engineering coverage. SCOR runs Function 04, Incident Response Preparation, as a joint product. The Security Operations Center authors the RootA signature; the Satellite Operations Center validates it against real telemetry so it fires without drowning operations in false positives; Satellite Design and Engineering confirms the source is instrumented on the element. Each AN-DET binds by TDM to the element its threat targets and ships in RootA so it crosses to peer operators.

AN-DET ETEN Process

Step 01
Enumerate the LAYER. AN (fixed).
Step 02
Verify the format. The signature must be a complete RootA rule (SOC Prime RootA specification v1.0.0): the mandatory name and detection fields, the optional fields the source supports, and the METEORSTORM anchor block. A bare vendor query (Splunk SPL, KQL, Sigma) with no RootA wrapper is not accepted into the layer. SOURCE is observable or synthetic.
Step 03
Set the TAG to DET. AN:DET.
Step 04
Assign an ORDINAL. Two digits from 00, one per distinct signature.
Step 05
Enumerate the TDM. One enumerated platform element the signature observes, the same element the related AN-THR targets. TDM, not TOE: the element scanned, not the element exploited.
Step 06
Write the DESCRIPTION. The complete RootA rule: every required field (name, detection language and body), the supporting fields (severity, class, mitre-attack, logsource, correlation, references), and the METEORSTORM block anchoring the rule to the target element and its parent chain. See the roota authority for the full field set.
AN-DET anchors · TDM, Target of Detection Method AN:DET:Detection Signature:00 RootA management-push signature TDM SVC:CP:Control Plane:09 AN:DET:Detection Signature:01 RootA out-of-pattern console signature TDM AST:SW:Software:04 AN:DET:Detection Signature:02 RootA noise-floor signature TDM AST:SI:Signal:00 AN:DET:Detection Signature:03 RootA firmware-hash signature TDM AST:FW:Firmware:01
Each AN-DET entry with its one TDM target, the enumerated platform element from its catalogue entry, in the layer colours of the structural ETEN reference.

Examples, field by field (4)

FieldValue
LAYERAN
TAGDET
LABELDetection Signature
ORDINAL00
SOURCEobservable
TDMSVC:CP:Control Plane:09
DESCRIPTIONFull RootA rule, base fields plus the METEORSTORM anchor block:name: KO-DET-ACA-MGMT-PUSH-000 title: Firmware push from ground ACA management interface outside maintenance window severity: high type: query class: behavioral date: 2026-07-26 mitre-attack: - t1195.002 detection: language: splunk-spl-query body: index=ground_aca sourcetype=mgmt action=firmware_push | where in_maintenance_window=false OR vpn_auth_anomaly=true logsource: product: ground-aca service: management-plane references: - AN:ATT:Attack Path:00 - AN:THR:Threat:00 tags: KO-DET-ACA-MGMT-PUSH-000, acidrain, ground-aca license: DRL 1.1 version: 1 uuid: a1b2c3d4-0000-4a00-8a00-000000000000 meteorstorm: pce: PCE:TE:Terrestrial:00 seg: SEG:GR:Ground:00 svc: SVC:CP:Control Plane:09 an: eten: AN:DET:Detection Signature:00 tdm: SVC:CP:Control Plane:09Covers AN:ATT:Attack Path:00 and AN:THR:Threat:00. Source: SOC detection engineering.
ETENAN:DET:Detection Signature:00:RootA signature for the chain-00 behavior on SVC:CP:Control Plane:09.
FieldValue
LAYERAN
TAGDET
LABELDetection Signature
ORDINAL01
SOURCEobservable
TDMAST:SW:Software:04
DESCRIPTIONFull RootA rule, base fields plus the METEORSTORM anchor block:name: KO-DET-CONSOLE-OOP-001 title: Out-of-pattern commanding from the operator console severity: high type: query class: behavioral date: 2026-07-26 mitre-attack: - t1078 detection: language: splunk-spl-query body: index=console sourcetype=command | where hour_of_day NOT IN (operator_shift) OR peer_review_tag=null OR off_mission_profile=true logsource: product: console-ops service: command-audit references: - AN:ATT:Attack Path:01 - AN:THR:Threat:01 tags: KO-DET-CONSOLE-OOP-001, insider, console license: DRL 1.1 version: 1 uuid: a1b2c3d4-0001-4a00-8a00-000000000000 meteorstorm: pce: PCE:TE:Terrestrial:00 seg: SEG:GR:Ground:00 svc: SVC:CP:Control Plane:13 ast: AST:SW:Software:04 an: eten: AN:DET:Detection Signature:01 tdm: AST:SW:Software:04Covers AN:ATT:Attack Path:01 and AN:THR:Threat:01. Source: SOC detection engineering.
ETENAN:DET:Detection Signature:01:RootA signature for the chain-01 behavior on AST:SW:Software:04.
FieldValue
LAYERAN
TAGDET
LABELDetection Signature
ORDINAL02
SOURCEobservable
TDMAST:SI:Signal:00
DESCRIPTIONFull RootA rule, base fields plus the METEORSTORM anchor block:name: KO-DET-RF-NOISE-002 title: Sustained noise-floor anomaly on the uplink and downlink bands severity: high type: query class: behavioral date: 2026-07-26 detection: language: splunk-spl-query body: index=rf_metrics | stats avg(noise_floor_db) as nf by band, _time span=5m | where nf > env_threshold_db AND sustained_minutes > 10 logsource: product: rf-frontend service: snr-telemetry references: - AN:ATT:Attack Path:02 - AN:THR:Threat:02 tags: KO-DET-RF-NOISE-002, jamming, rf license: DRL 1.1 version: 1 uuid: a1b2c3d4-0002-4a00-8a00-000000000000 meteorstorm: pce: PCE:TE:Terrestrial:01 seg: SEG:LI:Link:00 svc: SVC:HY:Hybrid:02 ast: AST:SI:Signal:00 an: eten: AN:DET:Detection Signature:02 tdm: AST:SI:Signal:00Covers AN:ATT:Attack Path:02 and AN:THR:Threat:02. Source: SOC detection engineering.
ETENAN:DET:Detection Signature:02:RootA signature for the chain-02 behavior on AST:SI:Signal:00.
FieldValue
LAYERAN
TAGDET
LABELDetection Signature
ORDINAL03
SOURCEobservable
TDMAST:FW:Firmware:01
DESCRIPTIONFull RootA rule, base fields plus the METEORSTORM anchor block:name: KO-DET-FW-HASH-003 title: Firmware hash mismatch at boot on the on-board computer severity: high type: query class: behavioral date: 2026-07-26 mitre-attack: - t1542 detection: language: splunk-spl-query body: index=obc_boot sourcetype=attestation | where measured_hash != signed_expected_hash logsource: product: obc service: boot-attestation references: - AN:ATT:Attack Path:03 - AN:THR:Threat:03 tags: KO-DET-FW-HASH-003, supply-chain, firmware license: DRL 1.1 version: 1 uuid: a1b2c3d4-0003-4a00-8a00-000000000000 meteorstorm: pce: PCE:OR:Orbital:00 seg: SEG:SP:Space:00 svc: SVC:HY:Hybrid:00 ast: AST:FW:Firmware:01 an: eten: AN:DET:Detection Signature:03 tdm: AST:FW:Firmware:01Covers AN:ATT:Attack Path:03 and AN:THR:Threat:03. Source: SOC detection engineering.
ETENAN:DET:Detection Signature:03:RootA signature for the chain-03 behavior on AST:FW:Firmware:01.

L5AN-RES · Resilience Measures (4)

Definition: “Protective capability ensuring resistance or recovery from threats, for either immediate implementation or as feedback for future platform engineering efforts” (METEORSTORM:AN=RES)

A Resilience Measure is the forward-looking statement: what the organization changes to alter its posture. Each entry serves one of the four cyber-resiliency goals of NIST SP 800-160 Volume 2: Anticipate, Withstand, Recover, Adapt. Measures are enumerated prospectively, before they are exercised, which makes completeness auditable: a reviewer walks the attack paths and checks that each has a corresponding measure or a consciously accepted residual risk. Accessible technologies apply the measure in place at the cadence they support; for a vehicle on orbit, the same entry becomes input to the next generation of platform design. In the ontology, AN-RES binds through TRE, Target of Resilience Enhancement: the element the measure protects.

The three departments, hardening the platform. SCOR runs Function 05, Adversary Management, across the three. The Security Operations Center names the elements that recur across many threats and paths; Satellite Design and Engineering builds or specifies the measure; the Satellite Operations Center runs it at the cadence the platform supports. Each AN-RES binds by TRE to the element its threat targets, with one resiliency goal.

AN-RES ETEN Process

Step 01
Enumerate the LAYER. AN (fixed).
Step 02
Identify the resiliency goal. One of Anticipate, Withstand, Recover, or Adapt, per NIST SP 800-160 Volume 2. SOURCE is observable or synthetic.
Step 03
Set the TAG to RES. AN:RES.
Step 04
Assign an ORDINAL. Two digits from 00, one per distinct measure.
Step 05
Enumerate the TRE. One enumerated platform element: the element the measure protects, the same element the related AN-THR targets. TRE, not TOE or TDM: the element made more resilient.
Step 06
Write the DESCRIPTION. The measure, the resiliency goal it serves, the AN-ATT or AN-THR entries it counters, plus the source citation: internal engineering, control-framework guidance, peer-shared pattern, or post-incident lesson.
AN-RES anchors · TRE, Target of Resilience Enhancement AN:RES:Resilience Measure:00 ground ACA zero-trust segmentation TRE SVC:CP:Control Plane:09 AN:RES:Resilience Measure:01 dual-control commanding TRE AST:SW:Software:04 AN:RES:Resilience Measure:02 frequency-agile link TRE AST:SI:Signal:00 AN:RES:Resilience Measure:03 measured-boot attestation TRE AST:FW:Firmware:01
Each AN-RES entry with its one TRE target, the enumerated platform element from its catalogue entry, in the layer colours of the structural ETEN reference.

Examples, field by field (4)

FieldValue
LAYERAN
TAGRES
LABELResilience Measure
ORDINAL00
SOURCEobservable
TRESVC:CP:Control Plane:09
DESCRIPTIONZero-trust segmentation of the ground ACA management plane from external networks, with hardware-rooted attestation and dual-approval on every management-plane action. Protects SVC:CP:Control Plane:09. Goal: Withstand. Counters AN:ATT:Attack Path:00 and AN:THR:Threat:00. Source: internal engineering, KA-SAT / AcidRain lesson.
ETENAN:RES:Resilience Measure:00:Zero-trust segmentation and dual-approval on the ground ACA management plane.
FieldValue
LAYERAN
TAGRES
LABELResilience Measure
ORDINAL01
SOURCEobservable
TREAST:SW:Software:04
DESCRIPTIONDual-control commanding for high-impact actions, a second operator approving before transmission, with per-operator behavior baselines and pre-pass briefings enforced in the console software. Protects AST:SW:Software:04. Goal: Withstand. Counters AN:ATT:Attack Path:01 and AN:THR:Threat:01. Source: internal engineering.
ETENAN:RES:Resilience Measure:01:Dual-control commanding and per-operator baselines in the console software.
FieldValue
LAYERAN
TAGRES
LABELResilience Measure
ORDINAL02
SOURCEobservable
TREAST:SI:Signal:00
DESCRIPTIONFrequency-agile, spread-spectrum link operation with a pre-arranged backup band; Satellite Operations switches bands automatically when the noise floor exceeds threshold; Satellite Design and Engineering owns the agility waveform. Protects AST:SI:Signal:00. Goal: Withstand. Counters AN:ATT:Attack Path:02 and AN:THR:Threat:02. Source: internal engineering.
ETENAN:RES:Resilience Measure:02:Frequency-agile spread-spectrum link with automatic band switch on noise threshold.
FieldValue
LAYERAN
TAGRES
LABELResilience Measure
ORDINAL03
SOURCEobservable
TREAST:FW:Firmware:01
DESCRIPTIONMeasured-boot firmware attestation with a signed-vendor manifest, supply-chain provenance verification at integration, and quarantine of any image whose hash does not match the signed expected value. Protects AST:FW:Firmware:01. Goal: Anticipate. Counters AN:ATT:Attack Path:03 and AN:THR:Threat:03. Source: internal engineering, NIST SP 800-193.
ETENAN:RES:Resilience Measure:03:Measured-boot attestation with signed-vendor manifest and hash-mismatch quarantine.

L5Indicators · AN-IOC and AN-IOA (0)

Indicators of compromise and indicators of attack are live-incident artifacts, recorded during operations, not produced by the five-function build. They were not the primary focus of this course, which teaches the enumeration of threats, attack paths, detection signatures, and resilience measures across Modules 2 to 5. Their processes and worked examples are kept here in full for completeness.

Show the AN-IOC and AN-IOA processes and examples

L5AN-IOC · Indicator of Compromise

Definition: “Verifiable indication that the platform has been compromised” (METEORSTORM:AN=IOC)

An Indicator of Compromise is backward-looking evidence anchored to a real-world observation: a file hash recovered from a host, a command-and-control domain reached by a beacon, a registry key left behind by a known tool. It answers the first question of any unfolding situation: has something already happened here?

AN-IOC is the highest priority analytic element. It indicates a confirmed platform breach, and every entry is traceable to an actual incident or live operator telemetry. That confirmation is what a peer operator acts on immediately, without further analysis.

AN-IOC ETEN Process

Step 01
Enumerate the LAYER. AN (fixed).
Step 02
Confirm the source. The incident report, telemetry stream, or partner report the observation is drawn from. The source defines the TOE. SOURCE is observable or synthetic.
Step 03
Set the TAG to IOC. AN:IOC.
Step 04
Assign an ORDINAL. Two digits from 00, one per distinct indicator.
Step 05
Enumerate the TOE. One enumerated platform element (PCE, SEG, SVC, or AST) the source states the indicator was observed on. Lowest layer the source resolves.
Step 06
Write the DESCRIPTION. The observable (hash, domain, IP, registry key), plus the source citation. The line a peer operator or peer machine acts on.

Example, field by field

FieldValue
LAYERAN
TAGIOC
LABELIndicator of Compromise
ORDINAL00
SOURCEobservable
TOEAST:SW:Software:02
DESCRIPTIONWiper binary hash 4f8e…c21a recovered from the ground ACA software host. Source: incident report KO-IR-2026-003.
ETENAN:IOC:Indicator of Compromise:00:Wiper binary hash recovered from the ground ACA software host.

L5AN-IOA · Indicator of Attack

Definition: “Verifiable indication that the platform has been targeted” (METEORSTORM:AN=IOA)

An Indicator of Attack is present-tense evidence that adversary activity is in progress: a reconnaissance pattern against a public interface, a credential-spraying sequence against an authentication service, an anomalous command pattern arriving at a control plane. Where AN-IOC establishes that a breach has occurred, AN-IOA establishes that the attempt is live. The compromise may or may not have completed; the response window is open.

The framework keeps the past and the present as separate analytic elements so the analyst answers two questions independently: did something already happen, and is something happening right now. Two questions, two elements, two decision paths.

AN-IOA ETEN Process

Step 01
Enumerate the LAYER. AN (fixed).
Step 02
Confirm the source. The live telemetry pattern, confirmed alert, or partner incident report the activity is drawn from. The source defines the TOE. SOURCE is observable or synthetic.
Step 03
Set the TAG to IOA. AN:IOA.
Step 04
Assign an ORDINAL. Two digits from 00, one per distinct indicator.
Step 05
Enumerate the TOE. One enumerated platform element (PCE, SEG, SVC, or AST) the source states is under the in-progress activity. Lowest layer the source resolves.
Step 06
Write the DESCRIPTION. The in-progress activity (the pattern, the cadence, the origin where applicable), plus the source citation. The line a peer operator or peer machine acts on.

Example, field by field

FieldValue
LAYERAN
TAGIOA
LABELIndicator of Attack
ORDINAL00
SOURCEobservable
TOESVC:CP:Control Plane:09
DESCRIPTIONCredential-spraying sequence against the ground ACA authentication interface, sustained at one attempt per 30 seconds across 40 accounts, ongoing in live SOC telemetry. Source: SOC alert KO-AL-2026-117.
ETENAN:IOA:Indicator of Attack:00:Credential-spraying sequence in progress against the ground ACA authentication interface.