Skip to content
Aviation cybersecurity training
Security Case Study

Operation Grounded Eagle

Milima Cyber Academy in Kampala, Uganda

A 3-day aviation cybersecurity training exercise combining tabletop exercises with a live Security Operations Center lab environment — transitioning airport sysadmins into SOC-capable analysts.

Uganda Civil Aviation Authority
Milima Cyber Academy

Operation Grounded Eagle was designed and delivered in March 2026 through a collaboration between ObsidianCorps and Milima Cyber Academy for an African civil aviation authority. The programme addressed a critical gap: airport IT staff with strong systems administration backgrounds but limited formal cybersecurity training were being asked to defend aviation-critical infrastructure against increasingly sophisticated threats.

3

Training Days

18

Exercise Injects

11

SOC Competencies

22k+

Security Events

13

Docker Containers

About the Client

The Uganda Civil Aviation Authority oversees aviation safety, security, and regulation across the country. Their airport IT teams manage a blend of traditional IT systems, specialised aviation systems, and operational technology — all requiring robust cybersecurity defence capabilities.

Industry: Aviation & Civil Aviation Authority
Location: Kampala, Uganda
Uganda Civil Aviation Authority Milima Cyber Academy

The Challenge

01

Complex attack surface

Airports operate traditional IT (email, finance, HR), specialised aviation systems (flight information, baggage handling, crew scheduling), and operational technology (ACARS, ADS-B, air traffic management) — each with different risk profiles and regulatory requirements.

02

Skills gap under pressure

IT staff with strong sysadmin backgrounds needed functional SOC capabilities — but the training had to be practical, aviation-specific, and produce measurable competency outcomes within a 3-day window.

03

Realistic training environment

Generic cybersecurity exercises wouldn't suffice. The training needed aviation-specific scenarios with realistic attack data, a live SIEM environment, and a signal-to-noise ratio that mirrors real operations.

Our Solution

Day 1

Kill Chain & Aircraft Security

Foundational cybersecurity concepts introduced through an aviation lens — making threats immediate and tangible through hands-on reconnaissance against real-world public footprints.

Cyber kill chain mapped to real aviation incidents
MITRE ATT&CK framework applied to airport infrastructure
Aircraft domain separation (ARINC 811) and protocol vulnerabilities
ACARS, ADS-B, ARINC 429/664 security analysis
Hands-on OSINT reconnaissance with Shodan & crt.sh
Simulated LockBit 3.0 ransomware attack on crew scheduling
Forensic triage, containment & crisis communications
Regulatory notification — GDPR, ICAO Annex 19, local data protection law
AI/ML attack vectors & quantum cryptography implications
Drone & UAM security challenges
Day 2

Incident Response & Emerging Technologies

Active incident handling under time pressure — teams responded to a simulated LockBit 3.0 ransomware attack against airport crew scheduling systems.

Day 3

SOC Capstone Assessment

A full-day hands-on exercise on a live Wazuh SIEM environment with over 22,000 pre-loaded security events. Participants hunted for attacker persistence, wrote detection rules, and delivered technical leadership briefings.

KQL queries against live Wazuh security event data
Threat hunting for attacker persistence mechanisms
Sigma detection rule writing with MITRE ATT&CK mappings
Network hardening architecture design
Technical leadership briefings using live dashboards

Technical Infrastructure

A 13-container Docker Compose stack providing complete team isolation across separate network subnets, deployed via a single automated script.

Wazuh

Multi-container SIEM stack per team — manager, indexer, and dashboard

Arkime

Full network packet capture and analysis per team environment

Vuln App

Deliberately vulnerable web application for hands-on security testing

Scenarium

Proprietary exercise platform for inject delivery, scoring, and analytics

11 SOC Competencies Assessed

01

SIEM Query Proficiency

KQL queries against live Wazuh data

02

Threat Hunting

Persistence mechanism identification & IOC reporting

03

Detection Rule Writing

Sigma rules in valid YAML with MITRE mappings

04

SIEM Tuning

Noise analysis and threshold adjustment recommendations

05

Network Security

Firewall gap analysis and hardened rule creation

06

Log Architecture Design

Per-server log source mapping & storage calculations

07

Alert Triage

Signal vs. noise separation under time pressure

08

Incident Investigation

Attack timeline reconstruction with TTP mapping

09

Containment Execution

Specific technical commands and firewall rules

10

Playbook Development

SOC runbooks with SOAR automation opportunities

11

Technical Communication

Evidence-based leadership briefings using live dashboards

Impact & Results

Sysadmins to SOC Analysts

Airport IT professionals acquired functional SOC capabilities in a structured 3-day programme.

22,000+ Events Analysed

Participants worked with realistic signal-to-noise ratios in a live SIEM environment.

Aviation-Framed Responses

Participants consistently referenced ICAO frameworks and sector-specific regulations in their work.

Complete Evaluation Report

Per-exercise scoring, skill progression analysis, and prioritised capability building recommendations.

Key Results

3 Days

From sysadmin to SOC-capable analyst

11

SOC competencies assessed and measured

22k+

Security events in live SIEM environment

18

Exercise injects across all training days

Our Methodology

The programme followed a deliberate progression — each day built on the previous one, with Day 3's capstone assessment validating everything taught across all three days. All exercises were delivered through Scenarium with simultaneous live SIEM lab access.

Expert Insight

"Operation Grounded Eagle validated that realistic, infrastructure-specific training scenarios produce better outcomes than generic cybersecurity exercises. When airport IT professionals see threats mapped to their own systems — ACARS, crew scheduling, flight displays — the material becomes immediately actionable, not just theoretically relevant."

PP
Philippe Parage

Training Director, ObsidianCorps

Operation Grounded Eagle was designed and delivered through a collaboration between ObsidianCorps and Milima Cyber Academy, specialising in cybersecurity training and capability building for critical infrastructure organisations.

Bridging the gap between IT operations and cybersecurity — one organisation at a time.

Ready to Secure Your Business?

Contact Us Today

CONTACT US

Get in Touch with Us

At Obsidiancorps, we fuse innovative technology with trusted security practices to create tailored solutions that protect and elevate your business. Reach out and let's secure a brighter future together.

Phone Number

+352 691 165 856

Email Address

info [at] obsidiancorps.com

Location

Differdange, Luxembourg

We typically respond within 24 hours

Send Us a Message

We'd love to hear from you! Fill out the form below and our team will get back to you as soon as possible.

captcha