Moonlight Defender : Purple Teaming in Space!
Ben Hawkins (Senior Research Engineer · Aerospace Corporation)
DEF CON 33 · Day 1 · Main Stage
Overview
This talk, "Moonlight Defender: Purple Teaming in Space!", delivered by Ben Hawkins, a Senior Research Engineer at Aerospace Corporation, delves into a critical initiative aimed at bridging the significant gap in cyber operator training and realistic cyber exercises within the U.S. Space Force. Hawkins highlights that while the Space Force focuses heavily on space operations, cyber security aspects are often neglected in training scenarios, leading to an unrealistic operational picture where space operators may be unaware of or unprepared for cyber effects. The Moonlight Defender program directly addresses this by integrating robust cyber red teaming and blue teaming into space-focused exercises.

Key moments
- 0:00 Introduction: Cyber gap in Space Force training
- 1:00 Moonlight Defender 1 and Moonlighter satellite
- 4:00 Moonlight Defender exercise range architecture
- 5:18 Red Team's mission plan and objectives
- 6:20 Unique satellite kill chain challenges: contact windows
- 7:00 Blue Team's mission, challenges, and response tools
- 8:00 Mapping to MITRE ATT&CK and Aerospace Sparta
Moonlight Defender: Purple Teaming in Space!
Speakers: Ben Hawkins, Senior Research Engineer, Aerospace Corporation
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=NHvvrhFU6XQ
Overview
This talk, "Moonlight Defender: Purple Teaming in Space!", delivered by Ben Hawkins, a Senior Research Engineer at Aerospace Corporation, delves into a critical initiative aimed at bridging the significant gap in cyber operator training and realistic cyber exercises within the U.S. Space Force. Hawkins highlights that while the Space Force focuses heavily on space operations, cyber security aspects are often neglected in training scenarios, leading to an unrealistic operational picture where space operators may be unaware of or unprepared for cyber effects. The Moonlight Defender program directly addresses this by integrating robust cyber red teaming and blue teaming into space-focused exercises.
The program's core objective is to provide accurate, relevant, and scalable cyber training that aligns with Space Force Defensive Cyber Operations (DCO) requirements. It leverages a purple teaming methodology, fostering collaborative learning between red (aggressor) and blue (defender) teams, who are often at similar nascent skill levels in the space cyber domain. By utilizing both live satellite assets and advanced simulation environments, Moonlight Defender creates dynamic, low-cost, and modular training ranges that expose operators to the unique challenges of space cyber, including contact windows, ICS/OT integration, and the physical consequences of cyber attacks on space systems.
Background
▶ Watch: Introduction: Cyber gap in Space Force training (0:00)
The problem addressed by Moonlight Defender stems from a fundamental disconnect: Space Force operations, by their very nature, are highly technical and critical, yet the integration of cyber warfare into their training and exercises has historically lagged. This creates a significant vulnerability, as cyber attacks can have profound effects on satellite functionality, ground systems, and mission success. When cyber effects are not accurately represented in training, operators develop a false sense of security, believing their systems are invulnerable or that attacks will have minimal impact. The lack of realistic cyber integration means that cyber operators are not adequately prepared to defend these complex, geographically dispersed, and often bespoke systems.
The genesis of Moonlight Defender lies in the momentum generated by Hackasat, an earlier initiative loosely affiliated with the Aerospace Corporation. Hackasat featured the Moonlighter vehicle, a 3U CubeSat launched into low Earth orbit (LEO) specifically for cyber testing and exercises. Developed through a collaboration between Aerospace, MITRE, AFL, and the Space Force, Moonlighter served as a real-world cyber testbed. After Moonlighter's operational lifespan, the collective sought to continue leveraging this unique capability for Space Force training. This led to the creation of Moonlight Defender, an exercise series designed to use actual satellite assets (initially Moonlighter) to provide compelling and accurate training data for Space Force personnel. The program was specifically designed as a purple team exercise, where both aggressor and defender teams could learn from each other in short, focused "effects windows," followed by joint debriefs to identify issues, attribute actions, and improve skills. Critically, these exercises were aligned with existing Space Force training requirements, ensuring direct relevance and contribution to operator qualifications and task development.
Key Findings
▶ Watch: Moonlight Defender exercise range architecture (4:00)
The Moonlight Defender program, through its two iterations (MD1 and MD2), yielded several key findings regarding space cyber training and operations:
Moonlight Defender 1 (MD1):
- Novelty for Red Teams: The aggressor teams, including Chromulants (builders of the Hackasat game environment) and Aerospace red team SMEs, were relatively new to the intricacies of space systems. Their mission plan focused on disrupting imaging operations, exfiltrating mission information, disrupting ground systems, and creating confusion for blue.
- Unique Attack Vector Challenges: The primary attack vector involved a buffer overflow on the satellite. However, the inherent challenge of contact windows (limited periods when a satellite is accessible) meant the attack had to be broken into stages, with long waits between sending exploit code, payloads, and receiving confirmation of success or access. This added significant stress and complexity for the red team.
- Blue Team Familiarity Gap: While blue team operators were essentially SOC analysts familiar with monitoring consoles, they lacked specific familiarity with the Moonlighter system and the unique terrain of space operations. Their objectives included mapping key terrain, gaining tool familiarity, building dashboards, and monitoring the ground RF link and space vehicle.
- Robust TTP Mapping: To maintain rigor, all activities were mapped to MITRE ATT&CK and Aerospace SPARTA. SPARTA, a research-focused framework, addresses the scarcity of real-world space attack data, providing a structured approach to identifying and proving out space-specific Tactics, Techniques, and Procedures (TTPs).
Moonlight Defender 2 (MD2):
- Scalability and Modularity: MD2 demonstrated the ability to scale the exercise, integrate more participants (e.g., Space ISAC Watch Center, cyber intelligence analysts), and adopt a more military-structured approach for eventual handoff to the Space Force. The emphasis was on using existing, low-cost resources to create a modular range adaptable to various space systems.
- Simulation vs. Live Assets: With Moonlighter no longer available, MD2 utilized NASA NOS3 (NOS cubed), a spacecraft simulation software running in virtual machines. This allowed for the exploration of the "delta" between live asset operations and simulated environments, proving the value of simulations for cost-effective, continuous training, while identifying gaps that still need to be bridged for full realism.
- Heavy ICS/OT Focus: A significant addition in MD2 was the emphasis on Industrial Control Systems/Operational Technology (ICS/OT), integrating virtual PLCs and HMIs. This addressed the critical infrastructure elements of Space Force architecture, a new and challenging domain for many operators.
- Red Team Mentorship and Noise: Red teams were integrated directly with experienced Aerospace core corps personnel, providing shoulder-to-shoulder mentorship. While they didn't achieve spacecraft compromise in this iteration (possibly due to range issues), their heavy engagement in the ICS/OT environment provided immense training value. The red team was encouraged to be "noisy enough to be seen," ensuring blue teams had actionable events to respond to.
- Blue Team Preparedness and Challenges: Blue teams engaged with a Crimes CTF that aligned with the scenario (a pre-compromised twin satellite providing IOCs). The ICS/OT environment proved to be a significant learning curve, with Brandon Baylor providing on-the-spot training. Operators, including one straight out of high school, struggled initially with defending the factory environment, highlighting a critical training gap.
- Custom Tooling: The development and use of custom tools like Rand is a Space Invader, an attack platform for space systems (acting as a rogue ground station, capable of sending erroneous traffic or even ransomware), demonstrated the power of open-source software and automation in space cyber attacks.
Technical Deep Dive
▶ Watch: Red Team's mission plan and objectives (5:18)
The Moonlight Defender exercises provided a rich technical environment for both red and blue teams, evolving from live satellite interaction to sophisticated simulation and ICS/OT integration.
In Moonlight Defender 1, the primary target was the Moonlighter CubeSat. This 3U satellite featured separate flight control and a cyber payload accessible via APIs. The operational range was built across multiple AWS VPCs, distinguishing between a "gaming environment" for cyber operations and an "out of scope" VPC for actual flight control. Connectivity extended to the MITRE Defensive Cyber Operations Lab, which housed blue team tools, and the MITRE Dark Sky range, a dynamic "wild west" environment for prototyping and testing against space-related ICS/OT and enterprise systems. The core red team attack involved a buffer overflow vulnerability on the Moonlighter. This was technically challenging due to contact windows, meaning the exploit delivery (sending the initial exploit, then the payload, then checking for access) had to be meticulously timed and executed across intermittent communication periods. This introduced real-world operational constraints into the cyber attack lifecycle. Blue teams, while familiar with SOC analyst duties, had to rapidly adapt to monitoring the unique telemetry and command traffic traversing the ground RF link and space vehicle. The rigorous mapping of TTPs to MITRE ATT&CK and the specialized Aerospace SPARTA framework ensured that the observed behaviors and defensive actions were grounded in deep research, addressing the scarcity of public data on space cyber attacks.
Moonlight Defender 2 shifted focus to a simulation-heavy environment, leveraging NASA NOS3 (NOS cubed), a spacecraft simulation software running in VMs. This allowed for continuous operation without the constraints and costs of a live satellite. The network diagram, while simplified from MD1, placed a heavy emphasis on ICS/OT systems. This included virtual PLCs (Programmable Logic Controllers) and HMIs (Human-Machine Interfaces), representing the critical infrastructure elements often found in ground stations and satellite manufacturing facilities. The scenario involved a simulated satellite factory utilizing Fact IO, a software platform that visually represents factory automation driven by PLCs. An exploit demonstrated in the talk caused pallets to fly erratically within this simulated factory, vividly illustrating the physical consequences of cyber attacks on industrial control systems. For satellite visualization, 42, a component of NOS3, displayed the satellite's state, driven by data and telemetry from NASA Core Flight Software (CFS) and an OpenC3 Cosmos ground instance. The red team's objective included causing the simulated satellite to spin uncontrollably, creating a high-pressure visual indicator of compromise for the blue team.
A notable custom red team tool developed by an Aerospace engineer, named Rand is a Space Invader, was highlighted. This attack platform for space systems is designed to act as a rogue ground station, capable of sending erroneous traffic or even executing ransomware on a satellite. Its power lies in its ability to load protocol libraries, allowing it to mimic legitimate ground station communications using readily available open-source software and leveraging automation. The Cosmos dashboard served as the primary interface for space operators on the blue side, displaying telemetry packets and command responses from the simulated satellite. Further bridging the gap between simulation and tangible hardware, the team developed Argus, a 3D-printed Raspberry Pi-based satellite model. This model runs custom CFS applications and communicates wirelessly to a Raspberry Pi ground station also running Cosmos, providing a representative, breakable, and low-cost physical artifact for hands-on training and demonstration, complete with an old web app for interaction. The entire range infrastructure for Moonlight Defender 2 was noted to be running on vSphere 67, underscoring the program's commitment to using existing, accessible technology rather than requiring bespoke, cutting-edge systems.
Demo / Proof of Concept
▶ Watch: Blue Team's mission, challenges, and response tools (7:00)
While the talk itself was a presentation, Ben Hawkins described several demonstrations and proof-of-concept elements integrated into the Moonlight Defender exercises, vividly illustrating the impact of cyber attacks on space systems:
- Moonlighter CubeSat Operations (MD1): The initial iteration of Moonlight Defender directly utilized the Moonlighter 3U CubeSat. Although its orbit decayed earlier than expected, its use provided a tangible, real-world target for cyber exercises, demonstrating the feasibility of hacking an actual satellite. The buffer overflow attack, executed across intermittent contact windows, served as a live proof of concept for exploiting on-orbit assets under realistic communication constraints.
- Factory IO Industrial Control System Simulation (MD2): A key demonstration in Moonlight Defender 2 involved Fact IO, a factory simulation environment. This was driven by a virtual PLC, showcasing how a cyber attack could manifest in the physical world. Hawkins described pallets "flying" erratically within the simulated factory, a direct consequence of the red team's exploit. This visual demonstration powerfully conveyed the dangers of cyber-physical attacks to operators whose primary focus is often on orbital systems.
- 42 Satellite Visualization Anomalies (MD2): The 42 software, part of the NOS3 simulation suite, provided a visual representation of the simulated satellite. During the exercise, the red team's objective was to make this satellite start "spinning," a clear and alarming visual indicator of compromise for the blue team. This real-time, dynamic visualization of an anomalous satellite state heightened the realism and pressure for the defending operators.
- Rand is a Space Invader Tool Capabilities: Hawkins detailed the capabilities of this custom-built red team tool. While not a live, in-talk demonstration, the description of its function as a rogue ground station capable of sending erroneous traffic or even performing ransomware on a satellite, effectively served as a proof of concept for potent, open-source-driven attack capabilities against space systems. The ability to load protocol libraries allows it to quickly adapt to various satellite communication standards.
- Argus Physical Satellite Model: For hands-on interaction and to provide a "coolness factor" when live satellites weren't available, the team developed Argus. This 3D-printed, Raspberry Pi-based model runs Core Flight Software (CFS) and communicates wirelessly with a Raspberry Pi ground station running Cosmos. Hawkins mentioned it has an "old web app up" that can be broken into, serving as a tangible, low-cost, and easily reset target for demonstrating attacks and defensive techniques in a physical, albeit ground-bound, context.
Defensive Implications
▶ Watch: Mapping to MITRE ATT&CK and Aerospace Sparta (8:00)
The Moonlight Defender program offers profound defensive implications for the Space Force and the broader space industry, emphasizing the need for a paradigm shift in cyber security posture:
Firstly, the program underscores the critical need for integrated cyber-physical training for space operators. Traditional space exercises often neglect cyber, creating a dangerous gap. Defenders must be trained to recognize, respond to, and recover from cyber attacks that can directly impact satellite functionality, ground control, and critical infrastructure. This demands a holistic understanding of both space operations and cyber security principles.
Secondly, blue teams require familiarity with diverse systems and terrains, particularly ICS/OT environments within ground segments and satellite manufacturing. As demonstrated by the MD2 exercise, operators often lack experience with PLCs and HMIs, which are increasingly targeted. Training must extend beyond enterprise IT to encompass these specialized operational technologies, including understanding their unique vulnerabilities and defensive strategies. Defenders should prioritize mapping key terrain, not just in orbit but across the entire space ecosystem, and developing custom dashboards for comprehensive monitoring.
Thirdly, the purple teaming methodology is invaluable for accelerated learning and skill development. By bringing red and blue teams together for joint debriefs, defenders gain immediate insight into adversary TTPs, range limitations, and the effectiveness of their own defenses. This collaborative approach fosters a continuous learning cycle, allowing operators to quickly adapt and refine their defensive strategies against evolving threats.
Fourthly, the adoption of rigorous frameworks like MITRE ATT&CK and Aerospace SPARTA is essential for developing and assessing defensive capabilities. SPARTA, in particular, helps categorize and understand space-specific TTPs, enabling defenders to proactively build defenses against known and emerging attack vectors unique to the space domain.
Fifthly, the program highlights the importance of leveraging simulation environments like NASA NOS3 for cost-effective and scalable training. While live assets offer unparalleled realism, simulations provide a continuous, repeatable, and safe environment to practice responses to complex cyber scenarios, including those with physical impacts. Defenders should understand how to interpret simulated data and translate those lessons to real-world operations, while also analyzing the "delta" between simulated and live environments.
Finally, defenders must recognize the potential for custom, open-source tooling (e.g., Rand is a Space Invader) to be weaponized against space systems. This necessitates a proactive approach to threat intelligence, understanding common protocols, potential vulnerabilities in ground station software, and the ease with which readily available components can be repurposed for malicious intent. Equipping blue teams with powerful response tools, while necessary, also demands robust training and governance to prevent unintended consequences, as seen with young operators having root access.
Key Takeaways
- Integrated Cyber-Space Training is Critical: Traditional space exercises often overlook cyber, creating a dangerous gap in operator readiness. Realistic, integrated cyber-physical training is essential for Space Force DCO operators.
- Purple Teaming Accelerates Learning: Collaborative purple team exercises, with small effects windows and joint debriefs, are highly effective for rapid skill development and understanding for both aggressor and defender teams in novel domains like space cyber.
- Scalable, Low-Cost Ranges are Achievable: Cyber ranges for space systems can be built using existing, open-source software and virtualization platforms (e.g., vSphere 67), making them modular, scalable, and cost-efficient for widespread training.
- Simulations Bridge the Gap: When live satellite assets are impractical, advanced simulation software like NASA NOS3 (NOS cubed) provides invaluable, continuous training environments, though understanding the "delta" between simulated and live operations remains important.
- ICS/OT is a Growing Focus: The integration of ICS/OT systems (PLCs, HMIs) into space range architectures highlights the increasing importance of securing critical infrastructure elements within ground segments and manufacturing, requiring specialized training for defenders.
- Custom Tools Empower Adversaries: The development of custom, open-source tools like "Rand is a Space Invader" demonstrates how readily available technology can be leveraged to create potent attack platforms against space systems, emphasizing the need for proactive threat intelligence and defense development.
About the Speaker(s)
Ben Hawkins is a Senior Research Engineer with the Aerospace Corporation. His work focuses on addressing critical problems within the Space Force, particularly in the areas of operator training development and the creation of accurate cyber exercises. Hawkins is a driving force behind the Moonlight Defender program, aiming to integrate robust cyber security aspects into space operations training, ensuring that Space Force personnel are adequately prepared to defend against sophisticated cyber threats in the unique domain of space. He advocates for leveraging existing resources and collaborative approaches to build scalable and modular cyber ranges.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Hawkins is doing genuinely novel work in a domain where almost nobody has real operational data: cyber exercises against actual on-orbit assets and space-adjacent ICS/OT infrastructure. The program architecture — live CubeSat in MD1, NOS3 simulation with virtual PLCs in MD2, custom rogue ground station tooling — is specific, honest about its own gaps, and directly tied to real Space Force training requirements. Not a research talk in the CVE-drop sense, but a credible case study with enough technical texture to earn its DEF CON slot.
Heather Calloway (CISO) — SOLID
Moonlight Defender is a well-grounded program doing real work on a real problem — the absence of integrated cyber training in Space Force operations. Hawkins is credible and the content is technically honest, but this talk is an operator briefing, not a strategic briefing, and it stays in that lane without apology.