The key concepts, structural data model, five framework functions, and three entry points from the METEORSTORM overview deck, in one printable reference for ongoing use after the course.
METEORSTORM publishes a controlled, machine-readable vocabulary that every operator, vendor, and peer can read without translation. The vocabulary covers four structural layers (what the platform is) plus a fifth analytic layer (what defenders observe and build). Every analytic finding attaches back to a real structural element on the platform.
| Code | Layer | Names |
|---|---|---|
| PCE | Primary Capability Environment | Where the platform operates (Terrestrial, Aquatic, Aerial, Orbital, Deep Space). |
| SEG | Segment | Operational role of each enclave (Launch, Link, Ground, User, Aquatic, Low/High/Near Altitude, Space, Deep Space). |
| SVC | Service | Functional plane the service runs on (Control Plane, Data Plane, Hybrid). |
| AST | Asset | Concrete element class (Hardware, Firmware, Software, Data, Signal, Hybrid). |
| Code | What it enumerates |
|---|---|
| AN-IOC | Indicator of Compromise. Confirmed indication that a converged space system has been compromised. |
| AN-IOA | Indicator of Attack. Confirmed indication that a converged space system has been attacked. |
| AN-ATT | Attack Path. Confirmed attack path for a converged space system. |
| AN-THR | Threat. Confirmed and active threat against a converged space system. |
| AN-DET | Detection Signature. Validated, operational pattern, signal, or logic that triggers on contextualized threat behavior. |
| AN-RES | Resilience Measure. Validated, operational protective capability ensuring resistance to or recovery from confirmed threats. |
LAYER : TAG : LABEL : ORDINAL
All four fields are required. Ordinals are scoped to the (LAYER, TAG) pair, so SEG : SP : Space : 00 and SEG : GR : Ground : 00 are distinct entries even though both end in 00.
| Field | Used by | What it names |
|---|---|---|
| TOE | AN-IOC, AN-IOA, AN-ATT, AN-THR | Target of Exploitation. The structural elements observed on or targeted by the analytic entry. |
| TDM | AN-DET | Target of Detection Method. The structural element the signature observes. |
| TRE | AN-RES | Target of Remediation. The structural element the measure protects. |
meteorstorm taxonomy publishes the complete tag set with stable UUIDs. Companion PDF: Element Taxonomy & Ontology, Layer 1 to Layer 4.
Walked twice in the overview deck. The first pass is the Integrate deep-dive carousel; the second pass gives each function a dedicated page with the problem it solves and how the framework solves it. The cards below consolidate both passes.
AN-THR elements where every entry's TOE points back at a real piece of your design.AN-THR binds via TOE to specific structural elements; threats anchor or they stay out of the catalog.Five organizational mastery areas where investment provably imposes adversary cost. Each area is exercised by one of the five framework functions. Detect, disrupt, and deter become measurable outcomes instead of slogans.
| # | Mastery area | The adversary suffers when… |
|---|---|---|
| 01 | Master Decomposition | …you know your platform better than they ever can. |
| 02 | Master Contextualized Threat Modeling | …every strike they imagine is already prepared for. |
| 03 | Master Converged Detection Engineering | …they cannot hide, and every move is seen. |
| 04 | Master Exposure Management | …every path they take ends in a trap. |
| 05 | Master Adversary Management | …their plans are known, broken, and turned against them. |
No two organizations sit at the same starting capability. Pick the entry point that matches your current state.
| Entry point | Best fit | What you do first |
|---|---|---|
| Activate | Ops already run; shared vocabulary does not. | Adopt the shared vocabulary inside your existing Threat Intel Platform so every confirmed finding reads the same way for every analyst, vendor, and partner. Federating with Space ISAC peers is a recommended next step, not a prerequisite. |
| Integrate | Platform being designed or rebuilt. | Align Security Operations, Satellite Operations, and Satellite Design & Engineering on the five-function process while the platform is being designed, so each team runs the framework as part of daily work rather than alongside it. |
| Engage | The three teams need to build production work product together. | Run exercises in an environment fully separate from production with SOC, SatOps, and SatDev/Eng, using synthetic adversary data, so the detection signatures, response playbooks, and resilience measures the three teams build during the exercise graduate straight into production the moment it closes. |
Each worked example is a self-contained printable companion based on the publicly documented 2022 Viasat KA-SAT incident. Pull them alongside this workbook when you want to see what a full, anchored analytic entry looks like.
| Reference | What it demonstrates |
|---|---|
| Element Taxonomy & Ontology | The full four-layer structural decomposition with element enumeration process and annotation criteria. |
| Contextualized Threat Modeling | One concrete AN-THR anchored via TOE to the SurfBeam2 modem firmware element, with full annotation criteria and the rationale for why this threat anchors to firmware specifically. |
| Converged Detection Engineering | One concrete AN-ATT covering the VPN-compromise-through-firmware-overwrite chain, with the data and signal source inventory aligned to each step. |
| Incident Response Preparation | One enumerated AN-DET in RootA YAML covering the unauthorized firmware push, with TDM attachment and back-references to the upstream attack path. |
| Adversary Management + Adversary Profile | One enumerated AN-RES for hardened boot + a complete adversary-profile template for the Sandworm actor that carried out the operation. |
This document is the overview workbook. The full course also includes five module workbooks, one per framework function, each structured the same way as this one (title page, classification banner, key concepts, worked examples, references).
AN-THR enumeration with the actor / capability / intel-source pattern, anchored against the platform from Module 01.AN-ATT enumeration plus the data and signal source inventory per attack path.AN-DET authoring in RootA plus the paired response playbook for each signature.AN-RES enumeration mapped to the four TRE objectives plus the adversary-profile template.meteorstorm taxonomy (machinetag.json) when you onboard new analysts.