Enumerated Taxonomic Element Nomenclature (ETEN) reference
An analytic Enumerated Taxonomic Element Nomenclature (ETEN) names one enrichment element on a platform, in five fields. An enrichment element is an indicator of compromise, an indicator of attack, an attack path, a threat, a detection signature, or a resilience measure, and it enriches the platform's Resilient Cyber Operations context by anchoring to the platform element it concerns.
Resilient Cyber Operations prioritizes real-world information sharing: by default an indicator of compromise, an indicator of attack, an attack path, or a threat is real world, ideally confirmed with a space collective defense community member. The framework also serves exercises and modeling, with one intent: developing real-world detection signatures and resilience measures from simulated activity.
ETEN Example
The enumeration that produces every analytic ETEN is governed by the normative process: the source is confirmed at THE GATE, the taxonomy supplies the tag and label, and the target reference anchors the entry to the platform. Each element walks its own six-step process in its section.
The analytic layer is built across Modules 2 to 5, one function per module, against the Day-1 CONOPS: 4 threats in Module 2, 4 attack paths in Module 3, 4 detection signatures in Module 4, and 4 resilience measures in Module 5, 16 enumerated elements in four chains. The contextualized threat model is the Module 2 output, the threats; each later function builds on it. AN-IOC and AN-IOA are live-incident artifacts recorded during operations, not produced by these functions. The platform elements every entry anchors to are in the structural ETEN reference; the analytic element definitions are in the analytic TEN reference.
Definition: “Known adversarial threat to the platform” (METEORSTORM:AN=THR)
A Threat is the targeted statement: a known adversary capability or campaign directed at the platform or its class of systems. Where an Attack Path records what the platform exposes, a Threat records who or what is likely to exercise that exposure. The two work as a pair: a path with no threat is a hypothetical, and a threat with no path is unmoored from the architecture. Every entry is built on attributed adversary activity: threat-intelligence reporting, government attribution, or a peer-shared adversary profile, so the community reads every threat as evidenced, not assumed.
The three departments, at the table. SCOR runs Function 02, Contextualized Threat Modeling, with all three departments. The Security Operations Center brings the threat intelligence and attribution; the Satellite Operations Center brings the operational picture, what normal commanding and passes look like, so each threat anchors to the right element; Satellite Design and Engineering brings the architecture, confirming which enumerated element a threat can actually reach. The output is the contextualized threat model: every AN-THR anchored by TOE to the platform element it targets.
AN-THR ETEN Process
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | THR |
| LABEL | Threat |
| ORDINAL | 00 |
| SOURCE | observable |
| TOE | SVC:CP:Control Plane:09 |
| DESCRIPTION | State-sponsored actor with demonstrated capability to gain persistent access to SATCOM management networks and abuse the provider-to-customer trust relationship to push malicious modem updates (KA-SAT / AcidRain class). Source: composite OSINT threat assessment read against the peer-reviewed research paper. |
| ETEN | AN:THR:Threat:00:State-sponsored actor targeting the ground ACA management plane to push malicious modem updates. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | THR |
| LABEL | Threat |
| ORDINAL | 01 |
| SOURCE | observable |
| TOE | AST:SW:Software:04 |
| DESCRIPTION | Cleared operator with command authority misuses the commanding console software to issue unauthorized telecommands to the vehicle. Source: insider-threat reporting, MITRE ATT&CK T1078 Valid Accounts. |
| ETEN | AN:THR:Threat:01:Cleared operator misusing the console software to issue unauthorized telecommands. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | THR |
| LABEL | Threat |
| ORDINAL | 02 |
| SOURCE | observable |
| TOE | AST:SI:Signal:00 |
| DESCRIPTION | RF actor sustains noise injection across the uplink and downlink bands to deny command and telemetry to the vehicle. Source: ITU interference reporting, documented SATCOM jamming campaigns. |
| ETEN | AN:THR:Threat:02:RF actor jamming the uplink and downlink waveforms to deny command and telemetry. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | THR |
| LABEL | Threat |
| ORDINAL | 03 |
| SOURCE | observable |
| TOE | AST:FW:Firmware:01 |
| DESCRIPTION | Adversary subverts the flight-software update supply chain and pushes a backdoored firmware image to the on-board computer over the command-and-update path. Source: NIST SP 800-193, SolarWinds supply-chain reporting. |
| ETEN | AN:THR:Threat:03:Adversary pushing a backdoored firmware image to the on-board computer over the update path. |
Definition: “Known attack path for a converged space system” (METEORSTORM:AN=ATT)
An Attack Path is a conditional statement: a documented sequence of adversary actions that could traverse the platform from entry to impact. Attack Paths are exposures, not observations; they record what is reachable given the architecture. Each one is drawn from real-world reporting: a confirmed exposure observed against the platform or a trusted partner, or documented adversary tradecraft, so the community reads every path as grounded, not guessed.
The three departments, converged. SCOR runs Function 03, Converged Detection Engineering, across the same three. The Security Operations Center traces how an adversary moves to realize each threat; the Satellite Operations Center confirms which moves are visible in operations; Satellite Design and Engineering names the data and signal sources on each element. The output is the AN-ATT attack paths, each anchored to the same element as the threat it realizes, with the pivot in its description.
AN-ATT ETEN Process
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | ATT |
| LABEL | Attack Path |
| ORDINAL | 00 |
| SOURCE | observable |
| TOE | SVC:CP:Control Plane:09 |
| DESCRIPTION | Anchored to the ground ACA management plane, SVC:CP:Control Plane:09. Pivot: entry through the external VPN appliance into the management network, abuse of the ground ACA (SVC:CP:Control Plane:09), through the ACA software (AST:SW:Software:02) and credential store (AST:DA:Data:01) onto the patch path (SVC:CP:Control Plane:12), objective a wiper pushed as a firmware update, modems bricked. Source: Space ISAC advisory, KA-SAT / AcidRain reporting. |
| ETEN | AN:ATT:Attack Path:00:Management-plane entry pivoting through the ground ACA onto the patch path to push a wiper as a firmware update. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | ATT |
| LABEL | Attack Path |
| ORDINAL | 01 |
| SOURCE | observable |
| TOE | AST:SW:Software:04 |
| DESCRIPTION | Anchored to the console operator software, AST:SW:Software:04. Pivot: authenticated operator on the console software issues unauthorized telecommands through the satellite console service (SVC:CP:Control Plane:13), bypassing single-operator review at the ground ACA (SVC:CP:Control Plane:09), objective an out-of-profile command to the vehicle. Source: insider-threat reporting. |
| ETEN | AN:ATT:Attack Path:01:Authenticated operator issuing unauthorized telecommands from the console, bypassing single-operator review. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | ATT |
| LABEL | Attack Path |
| ORDINAL | 02 |
| SOURCE | observable |
| TOE | AST:SI:Signal:00 |
| DESCRIPTION | Anchored to the uplink and downlink waveforms, AST:SI:Signal:00. Pivot: RF actor injects sustained noise onto the waveforms, overwhelming forward-error correction (SVC:HY:Hybrid:01) and tracking and telemetry (SVC:HY:Hybrid:02), objective denial of command and telemetry. May be paired with timing knowledge of overhead passes. Source: documented jamming campaigns. |
| ETEN | AN:ATT:Attack Path:02:Sustained RF noise on the waveforms overwhelming FEC and tracking to deny command and telemetry. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | ATT |
| LABEL | Attack Path |
| ORDINAL | 03 |
| SOURCE | observable |
| TOE | AST:FW:Firmware:01 |
| DESCRIPTION | Anchored to the on-board computer boot firmware, AST:FW:Firmware:01. Pivot: backdoored image staged in the patch pipeline (AST:SW:Software:03), pushed over the command-and-update path (SVC:CP:Control Plane:12), booted by the on-board computer, objective persistent control of the OBC. Source: NIST SP 800-193. |
| ETEN | AN:ATT:Attack Path:03:Backdoored image staged in the patch pipeline and booted by the on-board computer for persistent control. |
Definition: “Pattern, signal, or logic that triggers on contextualized threat behavior, expressed in RootA format” (METEORSTORM:AN=DET)
A Detection Signature is the coverage statement: the written commitment to see a specific behavior when it produces observable activity. A threat or attack path with no matching signature is a detection gap, and the gap is itself an enumerable analytic product. Every entry is a complete RootA rule (SOC Prime RootA specification v1.0.0), the open, vendor-neutral wrapper over the native query language it was authored in, extended with a METEORSTORM block that anchors the rule to its enumerated platform element, so a signature written by one operator deploys and routes in another operator’s stack without translation. In the ontology, AN-DET binds through TDM, Target of Detection Method: the element the signature observes, which may differ from the elements it protects.
The three departments, engineering coverage. SCOR runs Function 04, Incident Response Preparation, as a joint product. The Security Operations Center authors the RootA signature; the Satellite Operations Center validates it against real telemetry so it fires without drowning operations in false positives; Satellite Design and Engineering confirms the source is instrumented on the element. Each AN-DET binds by TDM to the element its threat targets and ships in RootA so it crosses to peer operators.
AN-DET ETEN Process
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | DET |
| LABEL | Detection Signature |
| ORDINAL | 00 |
| SOURCE | observable |
| TDM | SVC:CP:Control Plane:09 |
| DESCRIPTION | Full RootA rule, base fields plus the METEORSTORM anchor block:name: KO-DET-ACA-MGMT-PUSH-000
title: Firmware push from ground ACA management interface outside maintenance window
severity: high
type: query
class: behavioral
date: 2026-07-26
mitre-attack:
- t1195.002
detection:
language: splunk-spl-query
body: index=ground_aca sourcetype=mgmt action=firmware_push | where in_maintenance_window=false OR vpn_auth_anomaly=true
logsource:
product: ground-aca
service: management-plane
references:
- AN:ATT:Attack Path:00
- AN:THR:Threat:00
tags: KO-DET-ACA-MGMT-PUSH-000, acidrain, ground-aca
license: DRL 1.1
version: 1
uuid: a1b2c3d4-0000-4a00-8a00-000000000000
meteorstorm:
pce: PCE:TE:Terrestrial:00
seg: SEG:GR:Ground:00
svc: SVC:CP:Control Plane:09
an:
eten: AN:DET:Detection Signature:00
tdm: SVC:CP:Control Plane:09Covers AN:ATT:Attack Path:00 and AN:THR:Threat:00. Source: SOC detection engineering. |
| ETEN | AN:DET:Detection Signature:00:RootA signature for the chain-00 behavior on SVC:CP:Control Plane:09. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | DET |
| LABEL | Detection Signature |
| ORDINAL | 01 |
| SOURCE | observable |
| TDM | AST:SW:Software:04 |
| DESCRIPTION | Full RootA rule, base fields plus the METEORSTORM anchor block:name: KO-DET-CONSOLE-OOP-001
title: Out-of-pattern commanding from the operator console
severity: high
type: query
class: behavioral
date: 2026-07-26
mitre-attack:
- t1078
detection:
language: splunk-spl-query
body: index=console sourcetype=command | where hour_of_day NOT IN (operator_shift) OR peer_review_tag=null OR off_mission_profile=true
logsource:
product: console-ops
service: command-audit
references:
- AN:ATT:Attack Path:01
- AN:THR:Threat:01
tags: KO-DET-CONSOLE-OOP-001, insider, console
license: DRL 1.1
version: 1
uuid: a1b2c3d4-0001-4a00-8a00-000000000000
meteorstorm:
pce: PCE:TE:Terrestrial:00
seg: SEG:GR:Ground:00
svc: SVC:CP:Control Plane:13
ast: AST:SW:Software:04
an:
eten: AN:DET:Detection Signature:01
tdm: AST:SW:Software:04Covers AN:ATT:Attack Path:01 and AN:THR:Threat:01. Source: SOC detection engineering. |
| ETEN | AN:DET:Detection Signature:01:RootA signature for the chain-01 behavior on AST:SW:Software:04. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | DET |
| LABEL | Detection Signature |
| ORDINAL | 02 |
| SOURCE | observable |
| TDM | AST:SI:Signal:00 |
| DESCRIPTION | Full RootA rule, base fields plus the METEORSTORM anchor block:name: KO-DET-RF-NOISE-002
title: Sustained noise-floor anomaly on the uplink and downlink bands
severity: high
type: query
class: behavioral
date: 2026-07-26
detection:
language: splunk-spl-query
body: index=rf_metrics | stats avg(noise_floor_db) as nf by band, _time span=5m | where nf > env_threshold_db AND sustained_minutes > 10
logsource:
product: rf-frontend
service: snr-telemetry
references:
- AN:ATT:Attack Path:02
- AN:THR:Threat:02
tags: KO-DET-RF-NOISE-002, jamming, rf
license: DRL 1.1
version: 1
uuid: a1b2c3d4-0002-4a00-8a00-000000000000
meteorstorm:
pce: PCE:TE:Terrestrial:01
seg: SEG:LI:Link:00
svc: SVC:HY:Hybrid:02
ast: AST:SI:Signal:00
an:
eten: AN:DET:Detection Signature:02
tdm: AST:SI:Signal:00Covers AN:ATT:Attack Path:02 and AN:THR:Threat:02. Source: SOC detection engineering. |
| ETEN | AN:DET:Detection Signature:02:RootA signature for the chain-02 behavior on AST:SI:Signal:00. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | DET |
| LABEL | Detection Signature |
| ORDINAL | 03 |
| SOURCE | observable |
| TDM | AST:FW:Firmware:01 |
| DESCRIPTION | Full RootA rule, base fields plus the METEORSTORM anchor block:name: KO-DET-FW-HASH-003
title: Firmware hash mismatch at boot on the on-board computer
severity: high
type: query
class: behavioral
date: 2026-07-26
mitre-attack:
- t1542
detection:
language: splunk-spl-query
body: index=obc_boot sourcetype=attestation | where measured_hash != signed_expected_hash
logsource:
product: obc
service: boot-attestation
references:
- AN:ATT:Attack Path:03
- AN:THR:Threat:03
tags: KO-DET-FW-HASH-003, supply-chain, firmware
license: DRL 1.1
version: 1
uuid: a1b2c3d4-0003-4a00-8a00-000000000000
meteorstorm:
pce: PCE:OR:Orbital:00
seg: SEG:SP:Space:00
svc: SVC:HY:Hybrid:00
ast: AST:FW:Firmware:01
an:
eten: AN:DET:Detection Signature:03
tdm: AST:FW:Firmware:01Covers AN:ATT:Attack Path:03 and AN:THR:Threat:03. Source: SOC detection engineering. |
| ETEN | AN:DET:Detection Signature:03:RootA signature for the chain-03 behavior on AST:FW:Firmware:01. |
Definition: “Protective capability ensuring resistance or recovery from threats, for either immediate implementation or as feedback for future platform engineering efforts” (METEORSTORM:AN=RES)
A Resilience Measure is the forward-looking statement: what the organization changes to alter its posture. Each entry serves one of the four cyber-resiliency goals of NIST SP 800-160 Volume 2: Anticipate, Withstand, Recover, Adapt. Measures are enumerated prospectively, before they are exercised, which makes completeness auditable: a reviewer walks the attack paths and checks that each has a corresponding measure or a consciously accepted residual risk. Accessible technologies apply the measure in place at the cadence they support; for a vehicle on orbit, the same entry becomes input to the next generation of platform design. In the ontology, AN-RES binds through TRE, Target of Resilience Enhancement: the element the measure protects.
The three departments, hardening the platform. SCOR runs Function 05, Adversary Management, across the three. The Security Operations Center names the elements that recur across many threats and paths; Satellite Design and Engineering builds or specifies the measure; the Satellite Operations Center runs it at the cadence the platform supports. Each AN-RES binds by TRE to the element its threat targets, with one resiliency goal.
AN-RES ETEN Process
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | RES |
| LABEL | Resilience Measure |
| ORDINAL | 00 |
| SOURCE | observable |
| TRE | SVC:CP:Control Plane:09 |
| DESCRIPTION | Zero-trust segmentation of the ground ACA management plane from external networks, with hardware-rooted attestation and dual-approval on every management-plane action. Protects SVC:CP:Control Plane:09. Goal: Withstand. Counters AN:ATT:Attack Path:00 and AN:THR:Threat:00. Source: internal engineering, KA-SAT / AcidRain lesson. |
| ETEN | AN:RES:Resilience Measure:00:Zero-trust segmentation and dual-approval on the ground ACA management plane. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | RES |
| LABEL | Resilience Measure |
| ORDINAL | 01 |
| SOURCE | observable |
| TRE | AST:SW:Software:04 |
| DESCRIPTION | Dual-control commanding for high-impact actions, a second operator approving before transmission, with per-operator behavior baselines and pre-pass briefings enforced in the console software. Protects AST:SW:Software:04. Goal: Withstand. Counters AN:ATT:Attack Path:01 and AN:THR:Threat:01. Source: internal engineering. |
| ETEN | AN:RES:Resilience Measure:01:Dual-control commanding and per-operator baselines in the console software. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | RES |
| LABEL | Resilience Measure |
| ORDINAL | 02 |
| SOURCE | observable |
| TRE | AST:SI:Signal:00 |
| DESCRIPTION | Frequency-agile, spread-spectrum link operation with a pre-arranged backup band; Satellite Operations switches bands automatically when the noise floor exceeds threshold; Satellite Design and Engineering owns the agility waveform. Protects AST:SI:Signal:00. Goal: Withstand. Counters AN:ATT:Attack Path:02 and AN:THR:Threat:02. Source: internal engineering. |
| ETEN | AN:RES:Resilience Measure:02:Frequency-agile spread-spectrum link with automatic band switch on noise threshold. |
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | RES |
| LABEL | Resilience Measure |
| ORDINAL | 03 |
| SOURCE | observable |
| TRE | AST:FW:Firmware:01 |
| DESCRIPTION | Measured-boot firmware attestation with a signed-vendor manifest, supply-chain provenance verification at integration, and quarantine of any image whose hash does not match the signed expected value. Protects AST:FW:Firmware:01. Goal: Anticipate. Counters AN:ATT:Attack Path:03 and AN:THR:Threat:03. Source: internal engineering, NIST SP 800-193. |
| ETEN | AN:RES:Resilience Measure:03:Measured-boot attestation with signed-vendor manifest and hash-mismatch quarantine. |
Indicators of compromise and indicators of attack are live-incident artifacts, recorded during operations, not produced by the five-function build. They were not the primary focus of this course, which teaches the enumeration of threats, attack paths, detection signatures, and resilience measures across Modules 2 to 5. Their processes and worked examples are kept here in full for completeness.
Definition: “Verifiable indication that the platform has been compromised” (METEORSTORM:AN=IOC)
An Indicator of Compromise is backward-looking evidence anchored to a real-world observation: a file hash recovered from a host, a command-and-control domain reached by a beacon, a registry key left behind by a known tool. It answers the first question of any unfolding situation: has something already happened here?
AN-IOC is the highest priority analytic element. It indicates a confirmed platform breach, and every entry is traceable to an actual incident or live operator telemetry. That confirmation is what a peer operator acts on immediately, without further analysis.
AN-IOC ETEN Process
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | IOC |
| LABEL | Indicator of Compromise |
| ORDINAL | 00 |
| SOURCE | observable |
| TOE | AST:SW:Software:02 |
| DESCRIPTION | Wiper binary hash 4f8e…c21a recovered from the ground ACA software host. Source: incident report KO-IR-2026-003. |
| ETEN | AN:IOC:Indicator of Compromise:00:Wiper binary hash recovered from the ground ACA software host. |
Definition: “Verifiable indication that the platform has been targeted” (METEORSTORM:AN=IOA)
An Indicator of Attack is present-tense evidence that adversary activity is in progress: a reconnaissance pattern against a public interface, a credential-spraying sequence against an authentication service, an anomalous command pattern arriving at a control plane. Where AN-IOC establishes that a breach has occurred, AN-IOA establishes that the attempt is live. The compromise may or may not have completed; the response window is open.
The framework keeps the past and the present as separate analytic elements so the analyst answers two questions independently: did something already happen, and is something happening right now. Two questions, two elements, two decision paths.
AN-IOA ETEN Process
| Field | Value |
|---|---|
| LAYER | AN |
| TAG | IOA |
| LABEL | Indicator of Attack |
| ORDINAL | 00 |
| SOURCE | observable |
| TOE | SVC:CP:Control Plane:09 |
| DESCRIPTION | Credential-spraying sequence against the ground ACA authentication interface, sustained at one attempt per 30 seconds across 40 accounts, ongoing in live SOC telemetry. Source: SOC alert KO-AL-2026-117. |
| ETEN | AN:IOA:Indicator of Attack:00:Credential-spraying sequence in progress against the ground ACA authentication interface. |