From your first orbital calculation to commandeering a spacecraft over an RF link. Nine challenges. Very Easy to Hard. Built with VisionSpace.
Last year we entered the world of SATCOM cybersecurity with Operation Titan Link, our satellite security CTF event. It dropped teams into a geopolitical standoff over the orbital "High-Road to Mars" and asked them to intercept signals, decode telemetry, reverse firmware, and take operational control of satellite infrastructure before the other side did.
The event was hugely popular and proved there is substantial industry interest in space security content, and almost nowhere to get it outside of a once-a-year competition.
So we partnered with VisionSpace to build the always-on curriculum.
The HTB Satellite Exploitation Track is a 9-challenge series, live across HTB Labs and Enterprise Platform. It launches a dedicated Satellite category on Labs, and it takes you from zero satellite security knowledge to running a full telecommand and telemetry exchange over a simulated radio link. The protocols are the real ones, which means you get the same frame structures, the same failure modes, and the same "why won't this CRC validate" moments that show up in the real thing.
The SATCOM pack was an event. Great for a team offsite, a competition weekend, a one-off assessment. But event-based content has a ceiling: you get a burst of exposure, then it's over, and there's no path from "that was interesting" to "I can actually do this."
The Satellite Exploitation Track closes that gap:
The early challenges are approachable, and the difficulty climbs steadily from there.
The nine challenges form a single continuous skill curve, and by the end you're not reading about satellite security. You're the one running the pass.
Commercial and defense operators are putting constellations in orbit faster than anyone is training people to secure them. Satellites underpin global comms, navigation, and defense, yet almost no security training exists for them. Red teams are increasingly being handed space and OT assets to assess, with no realistic way to prepare first.
VisionSpace didn't build this content as a marketing exercise. They built it because AI is getting fast at clearing the basics, and it's still nowhere close to reasoning about the intersection of hardware, protocol, and physical mission consequence that space systems demand. That gap is where human specialists earn their keep. It's what our own research on AI and human teams found: anyone can clear the basics with AI, but the people who succeeded at the top end brought cyber expertise and specialist domain knowledge with them.
"Ten years ago satellite security was a conference talk. Today there are constellations overhead carrying the navigation, communications and defense traffic that everything else runs on, and space has become contested territory, with jamming and spoofing now ordinary features of modern conflict. The number of people who can properly test these systems would still fit in one room. Being the platform with the deeply technical, industry specific, highest quality content has been our winning formula for the last decade, and we build that content with practitioners who do the job for real. The hardest problems in security are moving toward systems where you have to understand the context as well as the systems and the technology, and that plays to people, not tools. We'd rather build the place where they learn it than wait for someone else to," said Christine Bartlett, CMO at Hack The Box.
There's a second thing worth saying plainly: ground segments are OT. Strip away the orbital mechanics and what's left is a fixed-format protocol stack, a web interface sitting in front of privileged commands, and embedded hardware that talks over I2C. Same bones as any industrial control system. VisionSpace put it directly: AI struggles in the OT world and the satellite world for the same reason, because it has to hold the physical process and the software in view at once, and that gets too complex fast. As true in a factory as it is on a spacecraft.
Which means the skills transfer. If you've ever pivoted from a dashboard bug into an operational command in a SCADA environment, Groundstation Breach will feel familiar. If you've pulled firmware off a PLC, Scalped Platform will too. This track earns its place for OT/ICS practitioners, not just the space-curious.
Hack The Box builds the hands-on content security practitioners actually train on, authored by people doing the work rather than writing about it. We hold new categories to that same bar, which is why we didn't build a space track on our own.
VisionSpace has spent fifteen years building space systems software for European space agencies and governments. Their engineers operate spacecraft and ground stations on customer premises. Their security division runs penetration testing, vulnerability assessment, and critical infrastructure R&D for the European Space Agency and the European Commission. They co-organize the Aerospace Village CTF at DEF CON, and two of them have a book on spacecraft hacking coming out with No Starch Press.
They're a space company doing real security testing, not a security vendor with a space vertical bolted on. That combination is rare, and it's the reason this track holds up: every challenge is authored by people who fly the hardware for a living.
"If you want to sink your teeth into satellite technology, this is where to start and level up. For most people, these challenges will be a genuinely tough learning curve, and that's the point. What we'd say is that the rabbit hole goes a lot deeper. These systems are all custom-built. You can't look up an open-source vulnerability and expect to find it on a spacecraft. They have to be tested by people who understand how they actually work. We operate satellites, so we know how to keep them alive, which is also how we know how to disable them. Getting access to a spacecraft is not the same as understanding the impact. This track is where that understanding starts," said Milenko, Head of Cybersecurity at VisionSpace.
The track is available on Enterprise Platform alongside a set of EP-exclusive orbital mechanics challenges covering Cartesian to Keplerian conversion, Hohmann transfers, plane changes, and escape trajectory planning. If you run security for a space program, a satellite operator, a defense agency, or a manufacturer supplying either, this is a way to build and measure capability against content authored by working space security practitioners.
It also does double duty as OT content. The skills in this track are not confined to orbit. Fixed-format protocol analysis, RF interception and demodulation, firmware extraction over a hardware bus, and pivoting from a web interface into a privileged operational command are the same competencies your team needs against a substation, a plant floor, a rail network, or a water treatment site. Space happens to be an unusually good place to train them, because the systems are custom-built, the protocols are unforgiving, and the mission consequences are unambiguous.
If your team owns OT or critical national infrastructure alongside space assets, or instead of them, the training still counts.