Space & Satellite Intel: Mission Domain Intelligence Guide
A satellite manoeuvred twice in one week and ended up station-keeping four kilometres from another operator’s communications bird. Nothing was announced. The orbital elements said everything.
A satellite manoeuvred twice in one week and ended up station-keeping four kilometres from another operator's communications bird. Nothing was announced. The orbital elements said everything.
What Space & Satellite Intel covers as a mission domain
Space and satellite intelligence covers the monitoring of objects in orbit, the behaviour of their operators, the ground segment that controls them, and the terrestrial effects of interference with space services. Practitioners track orbital elements and manoeuvres, characterise rendezvous and proximity operations, monitor launch activity and site development, assess debris and conjunction risk, and analyse interference with satellite communications and global navigation services. The domain also uses space as a collection medium, applying commercial and open imagery, radar and radiofrequency geolocation to terrestrial intelligence problems.
Sub-areas include space domain awareness and object custody, counterspace and grey-zone behaviour analysis, ground segment and teleport security, launch and spaceport monitoring, and space weather effects on operations. Actor types include national space agencies and militaries, commercial constellation operators whose assets are dual-use in practice, launch service providers, and states or proxies conducting reversible interference such as jamming and dazzle that is difficult to attribute and rarely acknowledged.
Why it matters
Position, navigation and timing from satellite constellations underpins financial timestamping, power grid synchronisation, aviation, maritime navigation and telecommunications. Denial or degradation of those services has immediate terrestrial consequence far beyond the space sector. Orbital congestion is now the operational constraint in low Earth orbit, where a single fragmentation event creates decades of collision risk. Governments, insurers and constellation operators need independent assessment because most authoritative catalogues are national and incomplete by design.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Manoeuvre residuals in successive orbital element sets indicating a burn that was not announced in any published operator plan.
- Repeated close approaches held deliberately rather than resolved, the signature of rendezvous and proximity operations rather than conjunction risk.
- New objects catalogued shortly after a launch that exceed the number of declared payloads, suggesting undeclared deployment or dispensers.
- Sudden orbital plane or inclination changes that consume large amounts of propellant, which reveal mission priority and remaining vehicle life.
- Debris-generating events indicated by a cluster of new catalogue entries sharing a common origin orbit and epoch.
- GNSS interference reports and degraded receiver integrity clustering around a region, visible in aviation and open interference mapping data.
- Construction of new launch pads, integration buildings or large antenna arrays visible in successive optical or radar imagery passes.
- ITU filings and orbital slot coordination activity that do not match the operator's stated commercial mission or timeline.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- Space-Track.org — Official US space surveillance catalogue with two-line element sets, decay predictions and conjunction data messages.
- CelesTrak — Curated element sets, satellite categorisation, supplemental operator ephemerides and analysis tools, freely available.
- ESA Space Debris Office annual report — Authoritative environment statistics on debris population, fragmentation events and compliance with mitigation guidelines.
- ITU Space Network Systems and BR IFIC — Frequency and orbital slot filings, coordination requests and interference reporting mechanisms.
- UNOOSA Register of Objects Launched into Outer Space — State-submitted registration of space objects with function, orbital parameters and launch details.
- Copernicus Sentinel and open commercial imagery archives — Monitoring of launch sites, spaceports, ground stations and large antenna installations over time.
- GPSJAM and aviation interference reporting — Aggregated GNSS interference observations derived from aircraft navigation integrity data by day and region.
- Jonathan McDowell's Space Report and planet4589 catalogues — Independent launch, payload and reentry records with careful historical reconciliation.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Establish object custody — Tie catalogue numbers to launches, operators and declared missions, and maintain the mapping as objects are reassigned or renamed.
- Baseline orbital behaviour — Characterise normal station-keeping cadence and manoeuvre magnitude for each object so an anomaly is measurable rather than impressionistic.
- Detect and classify manoeuvres — Compare successive element sets to identify burns, then classify by purpose: maintenance, collision avoidance, repositioning or approach.
- Assess proximity events — Evaluate close approaches for intent using relative geometry, dwell time and whether either party manoeuvred to create or resolve the encounter.
- Correlate ground and spectrum — Link orbital activity to ground station imagery, ITU filings and reported interference to build a picture the catalogue alone cannot give.
- Model terrestrial consequence — Translate degradation or denial of a service into concrete effects for navigation, timing, communications and imagery-dependent operations.
- Report with uncertainty stated — Publish findings with element set epoch, propagation error and confidence, since orbital inference degrades quickly with data age.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Space Intelligence — Orbital Activity, Space Assets, and Counterspace
- Geospatial Intelligence — Intelligence Derived from Place
- Imagery Intelligence — Interpretation of Visual Imagery
- Radio Frequency Intelligence — The Electromagnetic Spectrum as an Intelligence Source
- Technical Intelligence — Technology Capability, Design, and Exploitation
- Measurement & Signature Intel — Signatures, Measurements, and Physical Phenomena
- Signals Intelligence — Intelligence from Intercepted Communications and Emissions
Worked in these data points
- Satellite Imagery — Overhead imagery of an area of interest, used for change detection and site analysis.
- Radio Callsign — A licensed radio identifier for a station, vessel, aircraft, or operator.
- GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
- Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
Adjacent mission domains
- Military & Defense
- RF & Signals Intel
- Critical Infrastructure
- Nation State
- Aviation Security
- Emerging Technology & AI Security
Inside the platform: where Space & Satellite Intel lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
domain.php?d=space— Space & Satellite Intel dashboardtheater.php?d=space— Threat theater viewsearch.php— Company / Organization profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Space & Satellite Intel:
- APT Intrusion Analysis — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Establish object custody is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Detect and classify manoeuvres turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Report with uncertainty stated feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Space & Satellite Intel
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence space analysts maintain custody of objects of interest, characterise manoeuvres and proximity operations, and assess the resilience of space services that terrestrial forces depend on: navigation, communications, missile warning and imagery. Products support space domain awareness reporting, protection of friendly assets, conjunction and collision risk management, and assessment of grey-zone behaviour that falls below any threshold of attack. Analysis is defensive and custodial in orientation: establishing what is where, whose it is, and what changed. Constraints include the legal framework governing outer space activities, the difficulty of attributing reversible interference, and the requirement to route findings on civil systems to operators and regulators.
🕵 National intelligence
National intelligence requirements cover launch programme development, spaceport construction, satellite capability characterisation, ground segment locations and ownership, and behaviour indicating counterspace intent such as repeated close approaches. Fusion combines open orbital catalogues and radio observation with imagery of launch and ground sites, corporate ownership research and liaison reporting. Because the orbital element data is largely open and the analytic community is small, maintaining an unclassified layer is straightforward and valuable for coordination with civil operators. Judgments should distinguish clearly between observed manoeuvre and inferred intent, which the data rarely supports directly.
👮 Law enforcement
Law enforcement engagement is limited but real: export control and technology transfer offences involving space hardware, fraud in satellite services and spectrum licensing, unauthorised transmission and interference offences enforced by communications regulators, and theft or sabotage at ground segment facilities. Evidence includes licensing records, procurement and shipping documentation, spectrum monitoring records from the regulator, and standard digital forensic material. Interference enforcement is normally a regulatory function with criminal escalation, requiring the regulator's own measurement records rather than third-party observation to sustain a prosecution.
🔍 Private investigation and corporate security
Corporate security and due diligence practitioners in the space sector use this for supplier and partner screening, export control compliance, insurance and continuity assessment, and ground segment physical security. Work includes verifying corporate ownership and state linkage of constellation operators and launch providers, assessing single points of failure in teleport and gateway dependency, and screening technology transfer risk in partnerships. Private actors must not attempt to command, interrogate or interfere with any spacecraft or ground system, must respect export control law absolutely, and should route interference observations to the operator and regulator.
📰 Journalism and OSINT media
Space reporting rewards precision because the underlying data is public and specialists will check it. Verification requires using the orbital catalogue correctly, understanding that element sets are fitted approximations with known error growth, and distinguishing an observed manoeuvre from an inferred purpose. Imagery of launch sites needs proper dating and geolocation. Sources inside operators and agencies face contractual and sometimes export control exposure, so protect them carefully. Give operators a genuine right of reply, and avoid publishing ground segment security detail that would assist an attacker against civilian communications infrastructure.
🌍 NGO, humanitarian and human rights
Civil society engagement covers space sustainability and debris advocacy, transparency in orbital activity, the humanitarian consequences of interference with navigation and communications services used by aid operations, and documentation where satellite services supporting civilian populations are disrupted. Practice centres on open, verifiable analysis published with methodology so it can be independently checked. Do-no-harm includes avoiding publication of ground station vulnerabilities and being careful with imagery that could endanger people at a site. Duty of care applies to field staff dependent on satellite communications in areas where interference is active.
🎓 University and research
Space research benefits from genuinely open catalogues and observation networks, and the standard methodological failures are treating public element sets as precise ephemerides and over-interpreting manoeuvre detection. State the source and epoch of every element set, propagate with an appropriate model, and quantify positional uncertainty rather than presenting point positions. Ethics review is rarely required but export control review frequently is, particularly for propagation and orbit determination software. Publish code and observation data where licences permit, cite catalogue snapshots by date because element sets are continuously updated, and acknowledge the limits of amateur observation networks.
Playbook: working Space & Satellite Intel end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the custody question
State precisely what you are tracking and why: a specific object, an operator's fleet, activity in a defined orbital regime, launch programme development, or interference affecting a service. Space analysis becomes unmanageable without scope, because the catalogue contains tens of thousands of objects. A good output is a tasking that names the objects or regimes of interest, the observables that matter and the reporting cadence. Stop when the object set is bounded and the reason for each inclusion is written down.
Phase 2 — Establish object identity and provenance
For each object, record catalogue number, international designator, launch date and vehicle, declared operator and mission, orbital regime and any registry entry filed with the relevant international body. Cross-check declared purpose against orbital behaviour, since the two often diverge. Objects are frequently misattributed in secondary sources, so anchor on the catalogue and the registry. A good output is an object record with sourced identity and registration status. Stop when identity is confirmed or the ambiguity is documented explicitly.
Phase 3 — Baseline orbital behaviour
Build the normal behaviour profile: nominal orbit, station-keeping pattern, typical manoeuvre frequency and magnitude, and the operational rhythm of the mission type. Communications satellites in geostationary orbit, imaging satellites in sun-synchronous orbit and constellation members all behave differently, and anomaly detection without a class baseline generates constant false positives. A good output is a per-object behavioural profile with the normal manoeuvre envelope quantified. Stop when a routine station-keeping burn is no longer flagged as an event.
Phase 4 — Detect and characterise manoeuvres
Identify manoeuvres from changes in orbital elements across successive updates, characterising magnitude, direction and resulting orbit change. Distinguish routine station-keeping and drag make-up from deliberate repositioning, phasing changes and orbit raising. Note that element set update cadence limits your temporal resolution, so a manoeuvre is detected within a window rather than at an instant. A good output is a manoeuvre log with magnitude, inferred purpose and confidence. Stop before asserting intent that the orbital data alone cannot support.
Phase 5 — Assess proximity and rendezvous behaviour
Where objects approach each other, compute closest approach distances and relative geometry with explicit uncertainty, since public element sets carry error that grows with propagation time. Distinguish natural conjunctions arising from orbital mechanics from deliberate co-orbital positioning, which shows repeated intentional matching. A good output is a proximity assessment with distance, uncertainty and a judgment on whether the geometry was maintained deliberately. Stop when the uncertainty is stated alongside every distance figure.
Phase 6 — Monitor launch and spaceport activity
Track launch schedules, notices to airmen and mariners, and imagery of pad, assembly and propellant infrastructure to characterise launch cadence and programme development. Construction sequences at new sites are visible over months and reveal capability direction well before any launch. A good output is a site development timeline with dated imagery and inferred capability milestones. Stop at observed construction and stated capability rather than speculating about specific payloads.
Phase 7 — Map the ground segment
Identify ground stations, teleports, gateways and control centres serving the operators of interest, along with ownership and hosting arrangements. The ground segment is usually the weakest link and the most consequential dependency, and much of it is commercially shared. Assessment is protective: identifying dependency concentration and where redundancy is thin. A good output is a ground segment dependency map with concentration risk identified. Stop before documenting site-specific security weaknesses in any distributable product.
Phase 8 — Correlate interference reports
Where satellite communications or navigation interference is reported, correlate aggregated aircraft and vessel navigation integrity data, operator reports, regulator filings and community observation to establish geographic extent, duration and affected services. Distinguish uplink interference, downlink interference and terrestrial navigation jamming, which have entirely different causes. A good output is an interference picture with extent, timing and affected service classes. Stop at characterisation and route findings to operators and the spectrum regulator.
Phase 9 — Assess conjunction and debris risk
For operational concerns, track debris-generating events, fragment catalogue growth and conjunction warnings affecting assets of interest. Assess whether an operator is manoeuvring in response, which indicates both awareness and propellant expenditure that shortens mission life. A good output is a risk picture for the assets of concern with the propellant cost of avoidance noted. Stop when the assessment reaches the operator in time to inform an actual manoeuvre decision.
Phase 10 — Report with uncertainty and route protectively
Publish assessments that separate observation, computation and inference, state element set epoch and propagation uncertainty, and avoid intent claims the data cannot carry. Route anything touching ground segment or operator vulnerability to the operator, national CERT and regulator rather than into public products. A good output is an assessment a specialist can reproduce from the stated sources plus a documented protective disclosure trail. Stop when nothing published would assist interference with a space service.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| Space-Track | Registration | Official catalogue of orbital element sets, decay predictions, conjunction data messages and satellite catalogue metadata. | The authoritative element set source for custody, manoeuvre detection and conjunction assessment. |
| CelesTrak | Open | Curated orbital data, satellite catalogues by mission type, supplemental operator ephemerides and analysis tooling documentation. | Convenient grouped catalogues and supplemental data that improve accuracy over general perturbation element sets alone. |
| UNOOSA Register of Objects Launched into Outer Space | Open | State-filed registration of launched objects with declared function, orbital parameters and launching state. | Establishes declared purpose and registering state, which can be compared with observed orbital behaviour. |
| ITU space network systems and filings | Open | Frequency assignment filings, orbital slot coordination and international frequency information circular publications for space services. | Identifies the frequencies, orbital positions and administrations behind a satellite service and any interference case. |
| ESA Space Environment Report | Open | Annual assessment of the orbital environment including object population, debris generation, compliance with mitigation guidelines. | Authoritative reference for debris population trends and mitigation compliance in analysis and briefings. |
| Jonathan McDowell space reports and catalogues | Open | Independently maintained launch logs, object catalogues and analysis with meticulous documentation of catalogue anomalies. | Cross-checks official catalogue entries and resolves identity ambiguities that other sources leave unexplained. |
| Copernicus Data Space Ecosystem | Registration | Free Sentinel optical and radar imagery with frequent revisit suitable for monitoring large infrastructure change. | Tracks spaceport construction, pad activity and ground station development over time at no cost. |
| GPSJAM | Open | Aggregated daily maps of aircraft-reported navigation integrity degradation, derived from broadcast position quality indicators. | Establishes geographic extent and persistence of navigation interference affecting aviation and other users. |
| SatNOGS network | Open | Global network of amateur ground stations recording satellite radio observations with open data and scheduling. | Independent confirmation that a satellite is transmitting and on what frequency, useful for status verification. |
| NOAA Space Weather Prediction Center | Open | Solar activity, geomagnetic storm and radiation environment forecasts and alerts affecting satellite and radio operations. | Provides the natural explanation set that must be excluded before attributing anomalies to interference. |
| FCC and national regulator space and earth station licensing | Open | Licensing records for satellite systems and earth stations including technical parameters, locations and ownership. | Identifies ground station locations, operators and technical characteristics from public licensing records. |
| Union of Concerned Scientists satellite database | Open | Curated database of operational satellites with operator, purpose, orbit, launch details and country of registry. | Fast orbit and operator characterisation for large object sets before detailed catalogue work. |
| Secure World Foundation counterspace assessments | Open | Annual open-source assessment of global counterspace capabilities and activities with sourcing and methodology stated. | Benchmarks capability assessments and supplies documented precedent for characterising behaviour that other sources describe only vaguely. |
| Notices to airmen and maritime navigational warnings | Open | Official hazard area notices published ahead of launches, tests and reentry events with times and coordinates. | Provides advance indication of launch and test activity and the areas affected. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Space & Satellite Intel. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Python with Skyfield or similar propagation libraries — Propagates element sets and computes passes, conjunctions and geometry. Accuracy is limited by the element set, not the library, and users routinely forget that.
- CelesTrak analysis pages and supplemental data — Grouped catalogues, conjunction summaries and operator-supplied ephemerides. Coverage of supplemental data varies by operator willingness to publish.
- GMAT or open orbit determination tools — Higher fidelity mission analysis and manoeuvre reconstruction. Substantial learning curve and heavy dependence on quality input data.
- QGIS — Maps ground stations, interference extent and site imagery against geography. No orbital capability of its own without exported track data.
- Sentinel Hub EO Browser — Rapid inspection of launch site and ground station construction over time. Ten metre resolution limits identification of smaller equipment.
- SDR receiver networks and SatNOGS observations — Confirms transmission activity and frequencies independently. Coverage depends on volunteer station distribution, which is uneven globally.
- Conjunction assessment services — Screens for close approaches involving assets of interest. Public element set uncertainty means results are indicative rather than operationally decisive.
- Version-controlled catalogue snapshots — Preserves element sets by date so analysis is reproducible. Unglamorous, but without it no manoeuvre finding can be re-derived later.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Public element sets are fitted approximations with error that grows as you propagate them. Any close approach distance quoted without an uncertainty figure is a number pretending to be a measurement.
- Detect manoeuvres from changes across successive element set updates, and remember the update cadence bounds your temporal resolution. You know a burn happened within a window, not at a moment.
- Build a per-class behavioural baseline first. Station-keeping, drag make-up and constellation phasing are routine, and an alerting rule without a class baseline drowns the analyst in normal operations.
- Compare declared function in the registration filing against observed orbital behaviour. Divergence between the two is one of the few genuinely informative open indicators available in this domain.
- Exclude space weather before attributing any anomaly to interference. Geomagnetic storms and solar radio bursts produce effects that look like deliberate action to an analyst who has not checked.
- The ground segment is the consequential dependency and the weakest link, and much of it is commercially shared between operators who do not know they share it. Map concentration rather than assuming redundancy.
- Reversible interference is designed to be deniable. Attribution requires geolocation of the emitter by parties with the equipment and authority to do it, so characterise effects and route to the regulator rather than naming a culprit.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Space & Satellite Intel is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of objects of interest with maintained custody, meaning identity, registration status and current behavioural baseline all documented.
- Time from an element set update indicating a manoeuvre to a characterised manoeuvre report reaching the customer.
- Share of proximity assessments published with an explicit uncertainty figure alongside the closest approach distance.
- False positive rate in manoeuvre alerting before and after the introduction of per-class behavioural baselines.
- Number of interference observations routed to operators and spectrum regulators with formal acknowledgement of receipt recorded.
- Proportion of intent claims in published products that were supported by at least one non-orbital evidence stream.
- Reproducibility rate: the share of published findings that can be re-derived from archived catalogue snapshots by another analyst.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Two-line element sets carry meaningful position error that grows with propagation time, so precise conclusions from stale elements are unsound.
- Public catalogues are curated and incomplete; sensitive objects are withheld or delayed, so absence from the catalogue proves nothing.
- Proximity does not equal hostility. Inspection, servicing, debris avoidance and pure orbital mechanics all produce close approaches.
- GNSS interference is hard to attribute because sources are terrestrial, mobile and often deliberately intermittent.
- Commercial constellations are dual-use in practice, so labelling an operator as military misstates a much more layered reality.
- Space weather causes anomalies and drag changes that are frequently misread as deliberate manoeuvre or hostile action.
Legal and ethical considerations
Space activity is governed by the Outer Space Treaty and national licensing regimes, and states remain responsible for objects they register regardless of who operates them. Claims of hostile counterspace action carry escalation risk and demand a high evidentiary standard. Commercial imagery and ephemeris data are licensed with redistribution restrictions and sometimes resolution or shutter constraints. Publishing precise ground station or launch infrastructure analysis can be dual-use, so frame at the level that supports protective decisions.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Space & Satellite Intel, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 intelligence disciplines, 6 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
How accurate are public orbital element sets?
Adequate for custody, pass prediction and manoeuvre detection; inadequate for precise conjunction distances. They are fitted approximations produced for a specific analytic model, and error grows as you propagate away from the epoch, typically to kilometres within days for objects in low orbit. Using them to state that two objects passed within a few hundred metres, without an uncertainty figure, misrepresents the data badly. Where precision matters, use operator-supplied ephemerides where published, state the epoch and propagation model used, and always publish an uncertainty alongside any distance figure.
Can you tell what a satellite is doing from its orbit?
You can tell a great deal about capability and a limited amount about intent. Orbit regime, inclination, revisit pattern and manoeuvre behaviour constrain what a satellite can plausibly do, and repeated deliberate positioning relative to another object is genuinely informative. What orbital data cannot establish is purpose, tasking or the content of any transmission. The professional discipline is to report the observed behaviour precisely, note where it diverges from the declared function in the registration filing, and mark any statement about intent as an inference with its supporting and contradicting evidence.
What counts as a proximity operation worth reporting?
Sustained, deliberate relative positioning rather than a single close pass. Natural conjunctions happen constantly because orbits intersect, and in the geostationary belt objects share a narrow band by design. What is notable is repeated matching of orbit to another object, station-keeping at a fixed relative position, or a sequence of manoeuvres that closes distance and then maintains it. Report the manoeuvre sequence, the maintained geometry and the duration, each with uncertainty, and resist the temptation to characterise the purpose beyond what the sequence itself demonstrates.
How should navigation interference be handled?
Characterise the effect, exclude natural causes, and route the finding. Aggregated aircraft navigation integrity data shows geographic extent and persistence well, and vessel reporting adds a maritime layer. Before attributing, exclude space weather, receiver and equipment issues, and known testing notified through official channels. Distinguish jamming, which denies the signal, from spoofing, which supplies a false one, because the operational consequences and mitigations differ entirely. Geolocation of an emitter requires equipment and legal authority that belong to spectrum regulators and national authorities, so send characterised findings there rather than publishing attribution.
Is analysing satellites legal?
Observing objects in orbit and analysing published catalogues is lawful and is done openly by researchers, journalists and companies worldwide. What is constrained sits elsewhere: export control law applies to certain software, technical data and hardware; unauthorised transmission to a spacecraft is an offence in essentially every jurisdiction; and interfering with any space system is both criminal and dangerous. Receiving and decoding some transmissions may be restricted depending on jurisdiction and signal type. Keep the work observational and analytical, take export control advice where propagation or determination software is involved, and never transmit.
Why does the ground segment matter more than the satellite?
Because it is easier to reach and often more concentrated than anyone assumes. Spacecraft are hard to affect; teleports, gateways, control centres and their network connections are terrestrial facilities with conventional physical and cyber exposure, and commercial sharing means several operators may depend on the same site or the same upstream network without knowing it. Continuity assessment should therefore map dependency concentration, hosting arrangements and network paths rather than focusing on the orbital asset. Any specific weakness identified belongs with the operator, the national CERT and the regulator, never in a public product.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- Outer Space Treaty, which establishes state responsibility for national activities in space including those of non-governmental entities.
- Registration Convention, which requires states to register launched objects and declare their general function.
- Liability Convention, which governs liability for damage caused by space objects and frames debris and collision consequences.
- ITU Radio Regulations, which govern frequency assignment, orbital slot coordination and the handling of harmful interference cases.
- IADC space debris mitigation guidelines and UN COPUOS long-term sustainability guidelines, which define expected disposal and mitigation practice.
- National export control regimes including ITAR and dual-use regulations, which constrain technical data, software and hardware transfer.
- Coordinated vulnerability disclosure under ISO 29147 and ISO 30111, applied to ground segment and operator systems.
- ICD 203 analytic standards, which govern how uncertainty and inference are expressed when orbital observation supports intelligence judgments.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Space-Track catalogue and conjunction services — US Space Command and 18th Space Defense Squadron. Official orbital element sets, decay and conjunction data
- CelesTrak orbital data and analysis — CelesTrak. Curated catalogues, supplemental ephemerides and analysis documentation
- Register of Objects Launched into Outer Space — UN Office for Outer Space Affairs. State-filed registration data including declared object function
- Space network systems and frequency filings — International Telecommunication Union. Frequency assignment, slot coordination and interference procedures
- Space Environment Report — European Space Agency. Annual assessment of orbital population, debris and mitigation compliance
- Global Counterspace Capabilities report — Secure World Foundation. Open-source annual assessment of counterspace capabilities and activity
- Satellite Database — Union of Concerned Scientists. Curated database of operational satellites with operator and orbit attributes
- Space report and launch catalogues — Jonathan McDowell. Independently maintained launch and object catalogues with anomaly documentation
- Space weather alerts and forecasts — NOAA Space Weather Prediction Center. Solar and geomagnetic activity products used to exclude natural causes
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: orbital custody, manoeuvre and proximity detection correlated with ground segment and interference reporting. Explore the platform, or browse the rest of the library by following any tag above.