METEORSTORM
One data model for the platform, the adversary and the response.
MISP taxonomy v2
d2teamcorp.org
meteorstorm · Multiple Environment Threat Evaluation of Resources Space Threats and Operational Risk to Missions: a taxonomy for modeling space, cyber, and multi-domain threats and resilience across five layers. Published in the MISP taxonomy repository, version 2, October 2025.
The METEORSTORM data model: taxonomic elements in four structural layers
1Five functions, run in order
| F01 | Concept of Operations | Decompose the platform tailored to your requirements. | PCE SEG SVC AST |
| F02 | Contextualized Threat Modeling | Anchor every threat to the platform you just decomposed. | AN-THR |
| F03 | Converged Detection Engineering | Enumerate attack paths and the data and signals needed to detect each step. | AN-ATT |
| F04 | Incident Response Preparation | Write the detection signatures and the response playbooks. | AN-DET |
| F05 | Adversary Management | Shrink the attack surface the threats keep using. | AN-RES |
2One model, every environment
METEORSTORM covers the ground, user, link, and space segments, and also the aquatic, aerial, and deep space environments. When a merger, an acquisition, or a new market strategy takes your organization toward cislunar, maritime, or drone operations, your staff and your data model come with you: no expensive re-upskilling, no framework migration.
And you do not have to choose METEORSTORM over other frameworks: the analytic layer normalizes past, present, and future frameworks into the same standardized taxonomy and ontology, without building a new taxonomy for each. The reverse shows the layer and the frameworks it normalizes today.