Adversary Management worked example.

← Back to course
TLP:GREEN Limited Disclosure · SCORP² community members only
Exported by: verifying identity… Exported at:
Distribution notice. This document is for active SCORP² community members only. Unauthorized distribution will result in revocation of community membership.

Adversary Management · Kestrel Orbital Worked Example

One resilience measure that shrinks the recurring attack surface, plus the adversary profile

Platform anchor. AST : SI : Signal : 00 · telecommand uplink waveform. Objective AST : HW : Hardware : 06.
Threat. AN : THR : Threat : 00 · KO-THR-01. Attack path. AN : ATT : Attack Path : 00. Detection. AN : DET : Detection Signature : 00.

RESEnumerated AN-RES

One concrete resilience measure that shrinks the attack surface on the command path. It drives the "defeat command authentication" step of the upstream attack path toward unsuccessful for this adversary, even when uplink access succeeds.

FieldValue
IdentifierAN : RES : Resilience Measure : 00
DescriptionEnforce cryptographic telecommand authentication on the uplink: a message-authentication-code on every command, verified on-board by the Crypto (Space) service with an anti-replay counter, before C&DH accepts the command. Unauthenticated or replayed commands are rejected before execution. Secondary: a command-inhibit and safe-mode fallback for recovery.
TREAN : RES : Resilience Measure : 00 via TRESVC : CP : Control Plane : 01 (Crypto, Space)
TRE ObjectiveWithstand, with secondary contribution to Recover via command-inhibit and safe-mode fallback.
Removes attack surface fromAN : ATT : Attack Path : 00 step 02 and step 04. Even with uplink transmit access, an unauthenticated command fails on-board verification and is rejected before C&DH accepts it, so it never executes on the on-board computer.
Test resultVerified in resilience test RT-TC-2026-Q2: synthetic unauthenticated command rejected on-board; replayed valid command rejected by the anti-replay counter; command-inhibit and safe-mode fallback restored nominal authenticated commanding.
SourceResilience baseline RES-TC-2026-Q2; design specification doc-tcauth-006.

Two timelines for the measure

Immediate (compensating)Security Operations and Satellite Operations tighten command acceptance to authenticated-only during passes and enable the Link ACA reject-and-alert path, so the detection signature covers the residual risk while the on-board change is in progress. Owner: SOC and SatOps.
Engineering (remediation)Satellite Design & Engineering delivers on-board telecommand authentication with anti-replay in the Crypto (Space) service. The compensating control retires when this lands. Owner: SatDev/Eng.

Annotation criteria for every AN-RES element

FieldRequired?What to capture
LAYER / TAG / LABEL / ORDINALRequiredAlways AN : RES : Resilience Measure : NN.
DESCRIPTIONRequiredWhat the measure does, in plain English. Concrete, not aspirational.
TRERequiredFully-qualified enumerated identifier of the structural element the measure protects. Not TOE or TDM.
TRE OBJECTIVERequiredOne of Anticipate, Withstand, Recover, Adapt (per NIST SP 800-160 v2). Note any secondary contributions.
REMOVES ATTACK SURFACE FROMRequiredThe AN-ATT step or steps the measure addresses. Resilience without a target attack path is gold-plating.
TEST RESULTRequiredHow the measure was validated. A measure with no test does not graduate.
SOURCERequiredResilience baseline document and test report.
Priority is driven by recurrence, not compliance. Build resilience measures against the structural elements that recur across many AN-ATT paths and many AN-THR entries. The command-authentication service recurs because command injection is the crux of the demonstrated path; that recurrence justifies the measure.

PROFILEAdversary profile template

Each enumerated AN-THR element carries a structured adversary profile. Use this template as the field set for any new threat the team catalogues. The example below is filled for AN : THR : Threat : 00. It is a training construct for Kestrel Orbital, not an attribution to any real-world group.

Template fields

FieldWhat to capture
PRIMARY NAMEThe most-recognized name or tracking designation for the adversary.
ALIASESAll known aliases, vendor-tracking codes, and sub-group names.
ATTRIBUTIONState sponsor (if any), tracked unit, public attribution sources. Mark unattributed or training construct when no real attribution exists.
MOTIVATIONEspionage, disruption, financial, hacktivism, mixed; cite evidence.
CAPABILITIES (TTPs)Demonstrated tactics, techniques, and procedures, especially the ones that anchor to the AN-THR's TOE.
TARGETS / SECTORSSectors and target classes the actor has demonstrated against.
KNOWN OPERATIONSReverse-chronological list of named operations, one line each with date and source. Mark training scenarios clearly.
SIGNATURES LEFT BEHINDTooling lineage, technique reuse, infrastructure preferences, IOC families.
CONFIDENCEHigh / medium / low for attribution and capability, with one-line rationale.
SOURCEThe artifacts the profile draws from. Specific enough that someone else can open them.

Filled-in example for AN : THR : Threat : 00

Adversary profile · AN : THR : Threat : 00 · training construct
Primary nameKO-THR-01 (scenario designation "Orbital Specter")
AliasesInternal cluster label only; no public aliases (training construct).
AttributionTraining construct. Assessed in-scenario as a state-sponsored space-threat actor. Not an attribution to any real-world group; do not cite outside the exercise.
MotivationDisruption and denial of satellite command and control; the ability to degrade or seize a vehicle command path during a crisis.
Capabilities (TTPs) - Telecommand link injection on the uplink.
- Command replay against weak or absent anti-replay controls.
- Uplink source spoofing to defeat command-source authentication.
- Exploitation of unauthenticated or weakly authenticated command paths.
Targets / sectorsSatellite command-and-control, space-segment operators, orbital command environments.
Known operations - Kestrel Orbital red-team exercise RT-2026-Q1 (training scenario), telecommand-injection path.
- No real-world operations; this is an illustrative profile.
Signatures left behind - Unauthenticated command frames on the uplink.
- Message-authentication-code verification failures at the Link ACA.
- Out-of-sequence command counters at C&DH.
ConfidenceMedium. Capability class is well documented against satellite uplinks; specific targeting is a scenario assumption.
SourceKestrel Orbital threat assessment KO-INTEL-2026-014; red-team exercise RT-2026-Q1; Space ISAC space-segment bulletin 2026-Q1.
Profile use. The adversary profile is not a separate enumerated element; it is metadata that travels with the AN-THR entry. Store it alongside the AN-THR record in the CTI platform; cite the same SOURCE artifacts. When a peer publishes a profile update through Space ISAC, refresh the local copy and increment a profile revision date; the AN-THR identifier and ordinal stay the same.