Skip to content
Aviation cybersecurity training
Étude de Cas de Sécurité

Operation Grounded Eagle

Milima Cyber Academy in Kampala, Uganda

A 3-day aviation cybersecurity training exercise combining tabletop exercises with a live Security Operations Center lab environment — transitioning airport sysadmins into SOC-capable analysts.

Uganda Civil Aviation Authority
Milima Cyber Academy

Operation Grounded Eagle was designed and delivered in March 2026 through a collaboration between ObsidianCorps and Milima Cyber Academy for an African civil aviation authority. The programme addressed a critical gap: airport IT staff with strong systems administration backgrounds but limited formal cybersecurity training were being asked to defend aviation-critical infrastructure against increasingly sophisticated threats.

3

Training Days

18

Exercise Injects

11

SOC Competencies

22k+

Security Events

13

Docker Containers

À Propos du Client

The Uganda Civil Aviation Authority oversees aviation safety, security, and regulation across the country. Their airport IT teams manage a blend of traditional IT systems, specialised aviation systems, and operational technology — all requiring robust cybersecurity defence capabilities.

Industrie: Aviation & Civil Aviation Authority
Emplacement: Kampala, Uganda
Uganda Civil Aviation Authority Milima Cyber Academy

Le Défi

01

Complex attack surface

Airports operate traditional IT (email, finance, HR), specialised aviation systems (flight information, baggage handling, crew scheduling), and operational technology (ACARS, ADS-B, air traffic management) — each with different risk profiles and regulatory requirements.

02

Skills gap under pressure

IT staff with strong sysadmin backgrounds needed functional SOC capabilities — but the training had to be practical, aviation-specific, and produce measurable competency outcomes within a 3-day window.

03

Realistic training environment

Generic cybersecurity exercises wouldn't suffice. The training needed aviation-specific scenarios with realistic attack data, a live SIEM environment, and a signal-to-noise ratio that mirrors real operations.

Notre Solution

Day 1

Kill Chain & Aircraft Security

Foundational cybersecurity concepts introduced through an aviation lens — making threats immediate and tangible through hands-on reconnaissance against real-world public footprints.

Cyber kill chain mapped to real aviation incidents
MITRE ATT&CK framework applied to airport infrastructure
Aircraft domain separation (ARINC 811) and protocol vulnerabilities
ACARS, ADS-B, ARINC 429/664 security analysis
Hands-on OSINT reconnaissance with Shodan & crt.sh
Simulated LockBit 3.0 ransomware attack on crew scheduling
Forensic triage, containment & crisis communications
Regulatory notification — GDPR, ICAO Annex 19, local data protection law
AI/ML attack vectors & quantum cryptography implications
Drone & UAM security challenges
Day 2

Incident Response & Emerging Technologies

Active incident handling under time pressure — teams responded to a simulated LockBit 3.0 ransomware attack against airport crew scheduling systems.

Day 3

SOC Capstone Assessment

A full-day hands-on exercise on a live Wazuh SIEM environment with over 22,000 pre-loaded security events. Participants hunted for attacker persistence, wrote detection rules, and delivered technical leadership briefings.

KQL queries against live Wazuh security event data
Threat hunting for attacker persistence mechanisms
Sigma detection rule writing with MITRE ATT&CK mappings
Network hardening architecture design
Technical leadership briefings using live dashboards

Technical Infrastructure

A 13-container Docker Compose stack providing complete team isolation across separate network subnets, deployed via a single automated script.

Wazuh

Multi-container SIEM stack per team — manager, indexer, and dashboard

Arkime

Full network packet capture and analysis per team environment

Vuln App

Deliberately vulnerable web application for hands-on security testing

Scenarium

Proprietary exercise platform for inject delivery, scoring, and analytics

11 SOC Competencies Assessed

01

SIEM Query Proficiency

KQL queries against live Wazuh data

02

Threat Hunting

Persistence mechanism identification & IOC reporting

03

Detection Rule Writing

Sigma rules in valid YAML with MITRE mappings

04

SIEM Tuning

Noise analysis and threshold adjustment recommendations

05

Network Security

Firewall gap analysis and hardened rule creation

06

Log Architecture Design

Per-server log source mapping & storage calculations

07

Alert Triage

Signal vs. noise separation under time pressure

08

Incident Investigation

Attack timeline reconstruction with TTP mapping

09

Containment Execution

Specific technical commands and firewall rules

10

Playbook Development

SOC runbooks with SOAR automation opportunities

11

Technical Communication

Evidence-based leadership briefings using live dashboards

Impact et Résultats

Sysadmins to SOC Analysts

Airport IT professionals acquired functional SOC capabilities in a structured 3-day programme.

22,000+ Events Analysed

Participants worked with realistic signal-to-noise ratios in a live SIEM environment.

Aviation-Framed Responses

Participants consistently referenced ICAO frameworks and sector-specific regulations in their work.

Complete Evaluation Report

Per-exercise scoring, skill progression analysis, and prioritised capability building recommendations.

Résultats Clés

3 Days

From sysadmin to SOC-capable analyst

11

SOC competencies assessed and measured

22k+

Security events in live SIEM environment

18

Exercise injects across all training days

Notre Méthodologie

The programme followed a deliberate progression — each day built on the previous one, with Day 3's capstone assessment validating everything taught across all three days. All exercises were delivered through Scenarium with simultaneous live SIEM lab access.

Avis d'Expert

"Operation Grounded Eagle validated that realistic, infrastructure-specific training scenarios produce better outcomes than generic cybersecurity exercises. When airport IT professionals see threats mapped to their own systems — ACARS, crew scheduling, flight displays — the material becomes immediately actionable, not just theoretically relevant."

PP
Philippe Parage

Training Director, ObsidianCorps

Operation Grounded Eagle was designed and delivered through a collaboration between ObsidianCorps and Milima Cyber Academy, specialising in cybersecurity training and capability building for critical infrastructure organisations.

Bridging the gap between IT operations and cybersecurity — one organisation at a time.

Prêt à Sécuriser Votre Entreprise?

Contactez-Nous Aujourd'hui

CONTACTEZ-NOUS

Contactez-nous

Chez Obsidiancorps, nous allions technologie innovante et pratiques de sécurité éprouvées pour créer des solutions sur mesure qui protègent et dynamisent votre entreprise. Contactez-nous pour construire ensemble un avenir plus sûr.

+352 691 165 856

+352 691 165 856

Adresse e-mail

info [at] obsidiancorps.com

Localisation

Differdange, Luxembourg

Nous répondons généralement sous 24 heures

Envoyez-nous un message

Nous serions ravis de vous entendre ! Remplissez le formulaire ci-dessous et notre équipe vous répondra dès que possible.

captcha