Red Teaming Space: Hacking the Final Frontier
Tim Fowler (Founder and CEO · Ethos Labs, RBX Space)
DEF CON 33 · Day 1 · Main Stage
Overview
Tim Fowler, Founder and CEO of Ethos Labs and RBX Space, delivered a compelling talk at DEF CON titled "Red Teaming Space: Hacking the Final Frontier." This presentation illuminated the critical and rapidly evolving landscape of cybersecurity in the burgeoning "new space race." Fowler highlighted how the democratization and commercialization of space have dramatically expanded the attack surface, creating unprecedented security challenges that current methodologies and expertise are ill-equipped to handle.

Key moments
- 0:00 Introduction and the rarity of space red teamers
- 1:30 Democratization of space and expanding attack surface
- 2:40 Defining Space Race 2.0: Privatization and commercialization
- 3:45 "Space is hard": CubeSat failure rates highlight challenges
- 4:30 Space becoming an extension of the internet
- 5:10 GPS dependency: financial transactions and London Stock Exchange
- 6:10 National security and economic impact of space cyberattacks
- 6:50 Analyzing the attack surface: starting with the ground segment
Red Teaming Space: Hacking the Final Frontier
Speakers: Tim Fowler, Founder and CEO, Ethos Labs, RBX Space
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=KjDaPwtYte4
Overview
Tim Fowler, Founder and CEO of Ethos Labs and RBX Space, delivered a compelling talk at DEF CON titled "Red Teaming Space: Hacking the Final Frontier." This presentation illuminated the critical and rapidly evolving landscape of cybersecurity in the burgeoning "new space race." Fowler highlighted how the democratization and commercialization of space have dramatically expanded the attack surface, creating unprecedented security challenges that current methodologies and expertise are ill-equipped to handle.
The talk served as a stark call to action for the cybersecurity community, particularly red teamers, to adapt their skills and methodologies to the unique constraints and complexities of space systems. Fowler emphasized that while the space industry is experiencing exponential growth and innovation, its security posture lags significantly behind, posing substantial risks to national security, economic infrastructure, and daily life. The core message was the urgent need to "defend before orbit" by integrating robust offensive security testing throughout the entire space system lifecycle.
Fowler, drawing on his 13 years of experience in offensive security and his focus on space cybersecurity, underscored the fundamental differences between terrestrial and space-based red teaming. He argued that the physical inaccessibility of satellites, limited communication windows, and the severe consequences of failure necessitate a paradigm shift in how security is approached, tested, and integrated into space missions. This article delves into the intricacies of these challenges, the unique attack vectors, and the proposed solutions for securing humanity's final frontier.
Background
▶ Watch: Introduction and the rarity of space red teamers (0:00)
The space industry has undergone a profound transformation, shifting from a monolithic domain dominated by nation-states like the United States and Russia to what Tim Fowler terms "Space Race 2.0." The original space race, characterized by the launch of Sputnik by the USSR on October 4, 1957, was primarily a geopolitical contest. Today, however, we are witnessing a rapid democratization, privatization, and commercialization of space. This shift is driven by a dramatic reduction in launch costs, exemplified by companies like SpaceX and Rocket Lab, and advancements in technology, making satellite development more accessible.
This new era has led to an exponential growth in the number of space actors. As of the talk, there are over 11,000 commercial satellites in orbit, a figure that excludes government and intelligence assets. The barrier to entry has lowered to such an extent that operators now range from individual YouTubers like Mark Rober, who has launched CubeSats, to major defense contractors such as Lockheed Martin, Boeing, and Raytheon. This diverse ecosystem of operators and the proliferation of interconnected systems mean that space is rapidly becoming an extension of the internet itself.
The critical dependency of modern life on space systems is often underestimated. Fowler provided a compelling example: every financial transaction, from credit card swipes to stock trades, relies on time synchronization derived from space-based GPS systems. A localized GPS jamming attack in 2012 famously brought down the London Stock Exchange, demonstrating the tangible and immediate impact of space system vulnerabilities on terrestrial infrastructure. This highlights the severe national security and economic infrastructure risks posed by cyber attacks on space assets, underscoring the urgency of addressing cybersecurity in this domain.
The inherent difficulty of operating in space further complicates security efforts. As Fowler noted, "space is hard" – 90% of CubeSats launched in 2017 never even turned on. This unforgiving environment means that engineers prioritize mission survival above almost all else. Consequently, cybersecurity is often an afterthought, creating a significant gap between operational requirements and security best practices. The traditional "patch your systems" mentality often doesn't apply when a failed patch could result in the loss of a multi-million or even multi-billion dollar asset. This foundational tension between mission success and security creates a unique set of challenges for offensive and defensive operations in space.
Key Findings
▶ Watch: Defining Space Race 2.0: Privatization and commercialization (2:40)
The most striking finding presented by Tim Fowler is the profound immaturity and scarcity of space-specific red teaming capabilities. When asked how many in the audience had conducted a red team engagement on a space system, only "four or five people" raised their hands, and even fewer had worked on an on-orbit bird. This anecdotal evidence underscores a critical skills gap and a pervasive lack of practical experience in offensive security for space.
A pivotal revelation was that the first known commercial on-orbit red team exercise was only conducted very recently, in May/June 2023, by SixGen, Capella Space, and CT3. This groundbreaking exercise, nearly 65 years after the first satellite launch, highlights the extreme difficulty and perceived risk associated with offensive testing of live space assets. Fowler revealed that this particular exercise was only feasible because the satellite was nearing the end of its mission and degrading rapidly, providing a narrow, six-day window before contact would be lost permanently. This scenario illustrates the severe liability and risk involved, making operators hesitant to perform security tests that could jeopardize an active mission.
Fowler identified several unique challenges that distinguish space red teaming from traditional terrestrial engagements:
- Physical Inaccessibility: Once a satellite is integrated into a rocket and launched, direct physical access is impossible. Unlike on Earth, a technician cannot simply be sent to reset or repair a system in orbit.
- Limited Attack Windows: Communication with satellites is often constrained by orbital mechanics, resulting in infrequent and short contact windows (e.g., 10 minutes every 4 hours with limited bandwidth). This drastically alters the operational tempo and planning required for red team engagements.
- "Mission Operations vs. Cyber Security" Dilemma: Space operators prioritize mission uptime and data collection. If faced with a choice between an insecure but functional system and a potentially secure but non-operational one (e.g., due to a failed patch), the mission will almost always take precedence. This means patching is rare and often avoided if it carries any risk of mission failure.
- Lack of Specialized Tools and Environments: There is no "Metasploit for space." The unique protocols (e.g., CCSDS alongside custom ones), hardware, and operating environments necessitate highly customized tools and adequate simulation environments (e.g., digital twins, flat sats) that are often unavailable or underdeveloped.
- Expertise Gap: A significant divide exists between space engineers (who understand orbital mechanics, hardware constraints, and mission operations) and cybersecurity professionals (who understand vulnerabilities, exploitation, and adversarial tactics). Bridging this gap through collaboration and specialized training is crucial.
- Multi-domain Attack Vectors: Threats span terrestrial ground systems, communication links (uplink, downlink, crosslink), and onboard satellite systems, requiring a holistic approach that considers cross-domain attack chaining (terrestrial-to-space, space-to-ground, space-to-space).
These findings collectively paint a picture of a critical infrastructure domain that is rapidly expanding in scope and importance but remains largely unaddressed by mature offensive security practices, leaving it highly vulnerable to sophisticated adversaries.
Technical Deep Dive
▶ Watch: Space becoming an extension of the internet (4:30)
The technical intricacies of red teaming space systems extend across multiple segments, each presenting unique challenges and attack vectors. Fowler meticulously broke down the expanded attack surface and the specialized considerations required for offensive operations.
The ground segment represents the primary and most vulnerable entry point. This includes Telemetry, Tracking, and Control (TTNC) systems, mission software, and associated infrastructure. Fowler emphasized that while vulnerabilities exist, misconfigurations are often the more prevalent target for red teams. The hacker mentality, as he described, is not to care "what you designed it to do," but "what I can make it do." This involves exploring unintended functionalities and interactions within the ground control environment.
Communication links form another critical area. These comprise uplinks (ground to satellite), downlinks (satellite to ground), and increasingly, crosslinks (satellite to satellite). With the rise of interconnected constellations and mega-constellations like Starlink, the space domain is effectively becoming an extension of the internet. The ability to route an IP packet across multiple nodes in space significantly expands the lateral attack surface. Analyzing RF signals for custom protocols (alongside standards like CCSDS) is paramount for understanding and potentially manipulating these links.
Onboard systems present the most challenging targets due to their inaccessibility and unique operational constraints. These include firmware, buses, and various sensors**. Patching satellites on orbit is exceptionally rare, primarily due to the high risk. Fowler illustrated this with a stark dilemma: if a vulnerability is found on orbit, patching it carries the risk of mission failure if unsuccessful. Leaving it unpatched also risks mission failure if exploited. Given the immense financial stakes (hundreds of millions, potentially billions of dollars), operators almost invariably choose to forgo patching to maintain mission operations, hoping the vulnerability remains unexploited. This highlights the "mission operations versus cyber security" conflict, where business continuity often outweighs security posture.
The operational constraints for red teamers are equally severe. Unlike terrestrial engagements where an operator might set Cobalt Strike sleep timers for minutes, space red teams might only get a 10-minute window every four hours to communicate with a satellite, with severely limited bandwidth. This necessitates meticulous planning, staging, and an asymmetric approach to operations. The analogy to ICS/OT on steroids is apt, as space systems share characteristics of critical infrastructure—remote, often legacy, and with high consequences for disruption—but amplified by the physical distance and environmental harshness.
A significant hurdle is the lack of customized, specialized tools. There is no "Metasploit for space" because the domain is highly specialized, with unique hardware, operating systems, and communication protocols. This demands the development of bespoke tools and a deep understanding of orbital mechanics to predict satellite passes and plan attack windows. Furthermore, adequate simulation environments are often missing. Fowler stressed the importance of digital twins and flat sats for testing throughout the development lifecycle, arguing that security must be integrated "before launch."
The expertise gap is a central theme. Space engineers make decisions based on specific operational constraints and physics; red teamers must understand this logic to identify exploitable nuances. For example, the need to debug everything, including the debugger, in space systems creates potential access points for adversaries if these interfaces are not secured.
Finally, cross-domain attack chaining is a critical consideration. An attack might start on a terrestrial network, pivot to the ground segment, then affect the satellite (terrestrial-to-space), or vice-versa (space-to-ground). The emerging threat of space-to-space attacks, where one compromised satellite could affect others in a constellation, or even entire rogue constellations (as illustrated by the hypothetical "Timco" CubeSat scenario), poses unprecedented risks to the entire space ecosystem. Building expertise through collaboration between space engineers and red teamers is therefore not just beneficial but essential to address these complex, multi-faceted threats. Tools like NASA's NOS3 (NASA Operational Simulator for Small Satellites) offer valuable testbeds for developing this understanding.
Demo / Proof of Concept
▶ Watch: GPS dependency: financial transactions and London Stock Exchange (5:10)
Given the extreme difficulty and high stakes of conducting live offensive operations on space systems, Tim Fowler's talk did not feature a live technical demonstration or "proof of concept" in the traditional sense. This absence is, in itself, a testament to the core challenges he outlined: the physical inaccessibility of targets, the immense financial liability, and the limited windows for interaction.
However, Fowler did reference the first known commercial on-orbit red team exercise conducted in May/June 2023 by SixGen, Capella Space, and CT3. While not a live demo for the audience, this real-world operation serves as the closest equivalent to a proof of concept for space red teaming. He provided insight into its unique circumstances, noting it was only possible because the target satellite was at the end of its mission and degrading, allowing for a limited, high-risk window of opportunity before its permanent loss. This scenario underscores the practical barriers to such engagements, where even a successful "demo" relies on fortuitous circumstances rather than routine operational practice.
Fowler also mentioned his work developing hardware CubeSats for hands-on training. These physical platforms allow students to gain practical experience with space system fundamentals and cybersecurity challenges in a controlled environment, effectively acting as a training-focused "proof of concept" for developing necessary skills without the risks associated with live orbital assets. The speaker's emphasis was less on demonstrating a specific exploit and more on highlighting the methodology and challenges of space red teaming, advocating for the development of robust simulation environments like digital twins and flat sats as the primary means of testing and validating security before orbit.
Defensive Implications
▶ Watch: Analyzing the attack surface: starting with the ground segment (6:50)
The insights from "Red Teaming Space: Hacking the Final Frontier" offer critical guidance for defenders operating in the space domain. The overarching defensive implication is the urgent need for a paradigm shift from reactive security measures to proactive, integrated security strategies that begin at the earliest stages of design and development.
- Defend Before Orbit: This is the most crucial takeaway. Security must be designed into space systems from the ground up, not bolted on as an afterthought. This means incorporating offensive security testing throughout the entire development lifecycle, utilizing digital twins and flat sats to simulate real-world attacks in controlled environments before any hardware is launched. Planning for scenarios like patching, vulnerability management, and incident response must occur at the design phase.
- Bridge the Expertise Gap: Space engineers and cybersecurity professionals must collaborate closely. Defenders need to understand the unique operational constraints, orbital mechanics, and hardware decisions made by engineers, while engineers need to grasp adversarial mindsets and common attack vectors. Companies like Ethos Labs are working to facilitate this interdisciplinary understanding through specialized training.
- Prioritize Ground Segment Security: As the most accessible attack surface, the ground segment (TTNC systems, mission software) requires rigorous security. Defenders should focus not only on known vulnerabilities but also on identifying and mitigating misconfigurations and unintended functionalities that an attacker could abuse. Standard cybersecurity hygiene, while often overlooked in space, is paramount here.
- Secure Communication Links: The increasing interconnectedness of space systems makes uplinks, downlinks, and crosslinks prime targets. Defenders must implement robust encryption, authentication, and integrity checks for all data transmissions. RF analysis capabilities are essential for monitoring for unauthorized signals, identifying custom protocols, and detecting potential jamming or spoofing attempts.
- Re-evaluate Patching Strategies: While the speaker acknowledged the extreme difficulty of patching on-orbit satellites, defenders must still plan for it. This means designing systems that are capable of receiving patches securely and efficiently, even if infrequently. It also necessitates a robust risk assessment framework to weigh the risks of an unpatched vulnerability against the risks of a failed patch operation.
- Develop Space-Specific Incident Response: The limited communication windows and physical inaccessibility of satellites demand unique incident response plans. These plans must account for delayed telemetry, limited remote diagnostic capabilities, and the inability to physically intervene. Contingency plans for compromised onboard systems or rogue constellations (as highlighted by the "Timco" example) are essential.
- Address Cross-Domain Threats: Defenders must adopt a holistic view of the attack surface, recognizing that an attack might originate in terrestrial networks and propagate to space, or vice-versa. This requires integrated threat intelligence, coordinated defense strategies across different domains, and an understanding of cross-domain attack chaining.
- Adhere to Legal and Ethical Frameworks: Particularly on the RF side, defenders (and red teamers) must ensure all activities are conducted legally, with proper licensing and coordination with regulatory bodies. Responsible disclosure of vulnerabilities is crucial to foster a secure and collaborative space ecosystem.
By proactively addressing these defensive implications, the space industry can move towards a more secure future, mitigating the significant risks posed by an expanding attack surface and increasingly sophisticated adversaries.
Key Takeaways
- The "New Space Race" has dramatically expanded the attack surface: Democratization and commercialization of space, with over 11,000 commercial satellites, have created a vast and interconnected domain that is increasingly vulnerable.
- Space cybersecurity is severely underdeveloped and faces unique challenges: Traditional red teaming methods are insufficient due to physical inaccessibility, limited communication windows, the "mission vs. security" dilemma, and a lack of specialized tools and expertise.
- Proactive security "before orbit" is paramount: Security must be designed and rigorously tested into space systems from the earliest stages using tools like digital twins and flat sats, rather than attempting to patch or secure systems once they are already in orbit.
- A critical expertise gap exists between space engineers and cybersecurity professionals: Bridging this divide through collaboration and specialized, interdisciplinary training is essential to build effective defensive and offensive capabilities.
- The first commercial on-orbit red team exercise only occurred in 2023: This highlights the extreme risk aversion, immaturity, and difficulty associated with offensive security testing of live space assets, underscoring the urgent need for more practical engagement.
- The consequences of space system compromise are far-reaching: Attacks on space infrastructure can have severe national security, economic, and societal impacts, affecting critical services like financial transactions (e.g., London Stock Exchange GPS jamming in 2012).
About the Speaker(s)
Tim Fowler is the Founder and CEO of Ethos Labs and RBX Space, two companies dedicated to space cybersecurity training and consulting. With a distinguished career spanning 13 years in offensive security, Fowler has extensive experience in red teaming and penetration testing for a diverse range of clients, from Fortune 100 financial institutions to working with renowned firms like Parameter Security and Black Hills Information Security. He specializes in developing hands-on, practical training, including the creation of hardware CubeSats, to bridge the knowledge gap between traditional cybersecurity and the unique demands of space systems. Fowler is a passionate advocate for advancing offensive security capabilities in the space domain, emphasizing the need for expertise and proactive defense in this critical frontier.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Fowler correctly identifies a real and underserved problem — offensive security for space systems is genuinely immature, the first commercial on-orbit red team only happened in 2023, and the expertise gap between space engineers and security practitioners is a legitimate crisis. But the talk reads more like an excellent orientation briefing than a technical research contribution: it maps the problem space with clarity and credibility, without delivering the depth, tooling, or novel attack primitives that would make this a must-see at DEF CON.
Heather Calloway (CISO) — WEAK
Fowler correctly identifies a real and underaddressed risk domain, and the framing around 'defend before orbit' is sound. But the talk stops at problem statement — it delivers urgency without accountability, and awareness without a usable decision path for the operators, executives, or policymakers who actually need to act.