Contextualized Threat Modeling worked example.

← Back to course
TLP:GREEN Limited Disclosure · SCORP² community members only
Exported by: verifying identity… Exported at:
Distribution notice. This document is for active SCORP² community members only. Unauthorized distribution will result in revocation of community membership.

Contextualized Threat Modeling · Kestrel Orbital Worked Example

Anchors a threat to a real structural element from the Kestrel Orbital decomposition

Contextualized Threat Modeling produces enumerated AN-THR elements, one per threat. Every element names the structural element it actually targets via TOE (Target of Exploitation). This worked example anchors a single threat to the Kestrel Orbital telecommand uplink, using an actor with demonstrated capability to inject unauthenticated commands on a satellite command-and-control uplink. It is the first step of one thread that Functions 03, 04, and 05 carry forward.

Platform anchor (carried through the later functions).
AST : SI : Signal : 00 · Telecommand uplink waveform that carries commands from ground to spacecraft. Parent chain: SVC : CP : Control Plane : 05 (ACA Link) → SEG : LI : Link : 00PCE : OR : Orbital : 00.
Objective element. AST : HW : Hardware : 06 · on-board computer and OBDH bus, reached through SVC : HY : Hybrid : 00 (C&DH). The thread is: inject a telecommand on the uplink, get it past the Link access-control service, and have it executed on the on-board computer.

How to use this document

  1. Threat-modeling worksheet template. Replace the Kestrel Orbital values with your own platform's threats; the field set stays the same.
  2. Threat catalogue appendix. Attach to your threat-modeling procedure as a worked example.
  3. Analyst training. Pair with the structural taxonomy reference; new analysts see how a threat anchors to a real structural element on the platform they operate.

Element identifier format

LAYER : TAG : LABEL : ORDINAL · all four fields required, LABEL written in full. Ordinals scoped to the (LAYER, TAG) pair.

THREnumerated AN-THR

One concrete threat anchored to the orbital command environment via TOE, with the uplink waveform as the element it acts on.

FieldValue
IdentifierAN : THR : Threat : 00
DescriptionA state-sponsored space-threat actor (training designation KO-THR-01) with demonstrated capability to forge and inject unauthenticated telecommands onto a satellite command uplink, defeating weak or absent command-source authentication to reach the vehicle command path. Assessed capable against the Kestrel Orbital orbital command environment.
TOEAN : THR : Threat : 00 via TOEPCE : OR : Orbital : 00, acting on AST : SI : Signal : 00 (telecommand uplink waveform)
SourceKestrel Orbital threat assessment KO-INTEL-2026-014; Space ISAC space-segment threat bulletin 2026-Q1; open reporting on satellite command-link injection and replay techniques.
ConfidenceHigh for the capability class (command-link injection is well documented against satellite uplinks); medium for active targeting of Kestrel Orbital specifically.

Annotation criteria for every AN-THR element

FieldRequired?What to capture
LAYER / TAG / LABEL / ORDINALRequiredAlways AN : THR : Threat : NN with the next ordinal in your AN-THR sequence.
DESCRIPTIONRequiredPlain-English statement of who or what the threat actor is and why this threat matters to your platform. Avoid sales language; cite capability evidence.
TOERequiredFully-qualified enumerated identifier of the structural element the threat actually targets. Multiple TOE references are allowed when the threat applies to several elements.
SOURCERequiredThreat assessment, government brief, ISAC bulletin, vendor advisory, or internal incident report. Specific enough that someone else can open it and verify the claim.
CONFIDENCERecommendedHigh / medium / low, with one-line rationale. Used downstream when the attack-path and detection functions weight the threat.
DRIVESAuto-populatedThe set of AN-ATT elements the attack-path function derives from this threat; populated forward, not during the threat-modeling step.
Validation rules. Before declaring an AN-THR enumerated: TOE points at a real, enumerated structural element from the Kestrel Orbital decomposition (no examples, no placeholders); the source artifact exists and someone else can open it; the description states what the actor has demonstrated, not what they could demonstrate; confidence is recorded.

Why this threat anchors to the orbital command environment

The demonstrated capability is telecommand injection on the uplink, so the threat anchors to the orbital command environment PCE : OR : Orbital : 00 and names the uplink waveform AST : SI : Signal : 00 as the element it acts on. The same actor could have other capabilities (ground-network intrusion, payload-data interception) that would anchor to different structural elements and become separate AN-THR entries with their own TOEs. Contextualized Threat Modeling captures one threat-to-target relationship at a time.