One resilience measure that shrinks the recurring attack surface, plus the adversary profile
AST : SI : Signal : 00 · telecommand uplink waveform. Objective AST : HW : Hardware : 06.AN : THR : Threat : 00 · KO-THR-01. Attack path. AN : ATT : Attack Path : 00. Detection. AN : DET : Detection Signature : 00.
One concrete resilience measure that shrinks the attack surface on the command path. It drives the "defeat command authentication" step of the upstream attack path toward unsuccessful for this adversary, even when uplink access succeeds.
| Field | Value |
|---|---|
| Identifier | AN : RES : Resilience Measure : 00 |
| Description | Enforce cryptographic telecommand authentication on the uplink: a message-authentication-code on every command, verified on-board by the Crypto (Space) service with an anti-replay counter, before C&DH accepts the command. Unauthenticated or replayed commands are rejected before execution. Secondary: a command-inhibit and safe-mode fallback for recovery. |
| TRE | AN : RES : Resilience Measure : 00 via TRE → SVC : CP : Control Plane : 01 (Crypto, Space) |
| TRE Objective | Withstand, with secondary contribution to Recover via command-inhibit and safe-mode fallback. |
| Removes attack surface from | AN : ATT : Attack Path : 00 step 02 and step 04. Even with uplink transmit access, an unauthenticated command fails on-board verification and is rejected before C&DH accepts it, so it never executes on the on-board computer. |
| Test result | Verified in resilience test RT-TC-2026-Q2: synthetic unauthenticated command rejected on-board; replayed valid command rejected by the anti-replay counter; command-inhibit and safe-mode fallback restored nominal authenticated commanding. |
| Source | Resilience baseline RES-TC-2026-Q2; design specification doc-tcauth-006. |
| Immediate (compensating) | Security Operations and Satellite Operations tighten command acceptance to authenticated-only during passes and enable the Link ACA reject-and-alert path, so the detection signature covers the residual risk while the on-board change is in progress. Owner: SOC and SatOps. |
| Engineering (remediation) | Satellite Design & Engineering delivers on-board telecommand authentication with anti-replay in the Crypto (Space) service. The compensating control retires when this lands. Owner: SatDev/Eng. |
| Field | Required? | What to capture |
|---|---|---|
| LAYER / TAG / LABEL / ORDINAL | Required | Always AN : RES : Resilience Measure : NN. |
| DESCRIPTION | Required | What the measure does, in plain English. Concrete, not aspirational. |
| TRE | Required | Fully-qualified enumerated identifier of the structural element the measure protects. Not TOE or TDM. |
| TRE OBJECTIVE | Required | One of Anticipate, Withstand, Recover, Adapt (per NIST SP 800-160 v2). Note any secondary contributions. |
| REMOVES ATTACK SURFACE FROM | Required | The AN-ATT step or steps the measure addresses. Resilience without a target attack path is gold-plating. |
| TEST RESULT | Required | How the measure was validated. A measure with no test does not graduate. |
| SOURCE | Required | Resilience baseline document and test report. |
AN-ATT paths and many AN-THR entries. The command-authentication service recurs because command injection is the crux of the demonstrated path; that recurrence justifies the measure.
Each enumerated AN-THR element carries a structured adversary profile. Use this template as the field set for any new threat the team catalogues. The example below is filled for AN : THR : Threat : 00. It is a training construct for Kestrel Orbital, not an attribution to any real-world group.
| Field | What to capture |
|---|---|
| PRIMARY NAME | The most-recognized name or tracking designation for the adversary. |
| ALIASES | All known aliases, vendor-tracking codes, and sub-group names. |
| ATTRIBUTION | State sponsor (if any), tracked unit, public attribution sources. Mark unattributed or training construct when no real attribution exists. |
| MOTIVATION | Espionage, disruption, financial, hacktivism, mixed; cite evidence. |
| CAPABILITIES (TTPs) | Demonstrated tactics, techniques, and procedures, especially the ones that anchor to the AN-THR's TOE. |
| TARGETS / SECTORS | Sectors and target classes the actor has demonstrated against. |
| KNOWN OPERATIONS | Reverse-chronological list of named operations, one line each with date and source. Mark training scenarios clearly. |
| SIGNATURES LEFT BEHIND | Tooling lineage, technique reuse, infrastructure preferences, IOC families. |
| CONFIDENCE | High / medium / low for attribution and capability, with one-line rationale. |
| SOURCE | The artifacts the profile draws from. Specific enough that someone else can open them. |
| Primary name | KO-THR-01 (scenario designation "Orbital Specter") |
|---|---|
| Aliases | Internal cluster label only; no public aliases (training construct). |
| Attribution | Training construct. Assessed in-scenario as a state-sponsored space-threat actor. Not an attribution to any real-world group; do not cite outside the exercise. |
| Motivation | Disruption and denial of satellite command and control; the ability to degrade or seize a vehicle command path during a crisis. |
| Capabilities (TTPs) |
- Telecommand link injection on the uplink. - Command replay against weak or absent anti-replay controls. - Uplink source spoofing to defeat command-source authentication. - Exploitation of unauthenticated or weakly authenticated command paths. |
| Targets / sectors | Satellite command-and-control, space-segment operators, orbital command environments. |
| Known operations |
- Kestrel Orbital red-team exercise RT-2026-Q1 (training scenario), telecommand-injection path. - No real-world operations; this is an illustrative profile. |
| Signatures left behind |
- Unauthenticated command frames on the uplink. - Message-authentication-code verification failures at the Link ACA. - Out-of-sequence command counters at C&DH. |
| Confidence | Medium. Capability class is well documented against satellite uplinks; specific targeting is a scenario assumption. |
| Source | Kestrel Orbital threat assessment KO-INTEL-2026-014; red-team exercise RT-2026-Q1; Space ISAC space-segment bulletin 2026-Q1. |
AN-THR entry. Store it alongside the AN-THR record in the CTI platform; cite the same SOURCE artifacts. When a peer publishes a profile update through Space ISAC, refresh the local copy and increment a profile revision date; the AN-THR identifier and ordinal stay the same.