Anchors a threat to a real structural element from the Kestrel Orbital decomposition
Contextualized Threat Modeling produces enumerated AN-THR elements, one per threat. Every element names the structural element it actually targets via TOE (Target of Exploitation). This worked example anchors a single threat to the Kestrel Orbital telecommand uplink, using an actor with demonstrated capability to inject unauthenticated commands on a satellite command-and-control uplink. It is the first step of one thread that Functions 03, 04, and 05 carry forward.
AST : SI : Signal : 00 · Telecommand uplink waveform that carries commands from ground to spacecraft. Parent chain: SVC : CP : Control Plane : 05 (ACA Link) → SEG : LI : Link : 00 → PCE : OR : Orbital : 00.AST : HW : Hardware : 06 · on-board computer and OBDH bus, reached through SVC : HY : Hybrid : 00 (C&DH). The thread is: inject a telecommand on the uplink, get it past the Link access-control service, and have it executed on the on-board computer.
LAYER : TAG : LABEL : ORDINAL · all four fields required, LABEL written in full. Ordinals scoped to the (LAYER, TAG) pair.
One concrete threat anchored to the orbital command environment via TOE, with the uplink waveform as the element it acts on.
| Field | Value |
|---|---|
| Identifier | AN : THR : Threat : 00 |
| Description | A state-sponsored space-threat actor (training designation KO-THR-01) with demonstrated capability to forge and inject unauthenticated telecommands onto a satellite command uplink, defeating weak or absent command-source authentication to reach the vehicle command path. Assessed capable against the Kestrel Orbital orbital command environment. |
| TOE | AN : THR : Threat : 00 via TOE → PCE : OR : Orbital : 00, acting on AST : SI : Signal : 00 (telecommand uplink waveform) |
| Source | Kestrel Orbital threat assessment KO-INTEL-2026-014; Space ISAC space-segment threat bulletin 2026-Q1; open reporting on satellite command-link injection and replay techniques. |
| Confidence | High for the capability class (command-link injection is well documented against satellite uplinks); medium for active targeting of Kestrel Orbital specifically. |
| Field | Required? | What to capture |
|---|---|---|
| LAYER / TAG / LABEL / ORDINAL | Required | Always AN : THR : Threat : NN with the next ordinal in your AN-THR sequence. |
| DESCRIPTION | Required | Plain-English statement of who or what the threat actor is and why this threat matters to your platform. Avoid sales language; cite capability evidence. |
| TOE | Required | Fully-qualified enumerated identifier of the structural element the threat actually targets. Multiple TOE references are allowed when the threat applies to several elements. |
| SOURCE | Required | Threat assessment, government brief, ISAC bulletin, vendor advisory, or internal incident report. Specific enough that someone else can open it and verify the claim. |
| CONFIDENCE | Recommended | High / medium / low, with one-line rationale. Used downstream when the attack-path and detection functions weight the threat. |
| DRIVES | Auto-populated | The set of AN-ATT elements the attack-path function derives from this threat; populated forward, not during the threat-modeling step. |
The demonstrated capability is telecommand injection on the uplink, so the threat anchors to the orbital command environment PCE : OR : Orbital : 00 and names the uplink waveform AST : SI : Signal : 00 as the element it acts on. The same actor could have other capabilities (ground-network intrusion, payload-data interception) that would anchor to different structural elements and become separate AN-THR entries with their own TOEs. Contextualized Threat Modeling captures one threat-to-target relationship at a time.