LC-1 · Kinematic Threat Briefs
Kinematic Threat Brief
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# Kinematic Threat Brief **LRRK Watch / Open-Source Intelligence** — Five current signals across systems that sense, move, and act. | Field | Value | | --- | --- | | Collection cutoff | 30 September 2010 | | Platform | Quiet Systems | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Image rights require separate verification before publication. | ## Executive read ### BLUF September put three Control Fabrics on the same calendar: IAEA published Natanz centrifuge counts, the FAA and DoD testified that unmanned aircraft cannot yet share national airspace as routine traffic, and Symantec released a comprehensive Stuxnet analysis that treats PLC sabotage as the worm’s purpose. ### Key judgments 1. **[Assessment — high confidence]** GOV/2010/46 (6 September, derestricted 15 September) is the authoritative public physical ledger of Iranian enrichment at cutoff. 2. **[Assessment — high confidence]** The 13 September Grand Forks hearing records that FAA will not expedite full UAS integration and that DoD/FAA still lack routine NAS access for public UAS. 3. **[Inference — moderate confidence]** Symantec’s 30 September comprehensive analysis will become the default public technical picture of Stuxnet as cyber-to-physical Act, even while IAEA has not attributed centrifuge behavior to malware. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. IAEA GOV/2010/46: Natanz still enriching *Event / publication dates: 6 September 2010; derestricted 15 September 2010* **Verified record — [Fact — A1]** The Director General reported that Iran had not suspended enrichment. On 28 August 2010, FEP was feeding UF6 into 17 cascades of Unit A24 and 6 of Unit A26; other cascades were installed but not fed; all installed machines were IR-1, 164 per cascade; of 8,856 installed, 3,772 were being fed. Iran estimated 995 kg additional low-enriched UF6 between 23 November 2009 and 6 August 2010, for 2,803 kg since February 2007. PFEP was producing UF6 enriched up to 20% U-235 in interconnected cascades. FFEP construction near Qom continued with no centrifuges introduced as of 18 August. Iran had not implemented modified Code 3.1 or the Additional Protocol. Fetched: https://www.iaea.org/sites/default/files/documents/gov2010-46.pdf **Threat landscape.** Physical Sense-Move-Act at an enrichment plant under incomplete safeguards access. The report is about nuclear material, not malware. **Intelligence assessment.** [Assessment — high confidence] Enrichment and 20% work continue. [Inference — low confidence] The installed-versus-fed gap is not, in this document, a Stuxnet finding. [Uncertainty] Seal-break incidents at FEP are noted; safeguards consequences await the next PIV. **Opportunity.** An IAEA sentence on unusual centrifuge replacement rates would have been the physical-anomaly hook; GOV/2010/46 does not provide one labeled as sabotage. **LRRK relevance.** Watch / Sense-Move-Act. This is the September physical baseline against which later Stuxnet-Natanz papers must be compared. **Confidence.** High on the IAEA figures; high that malware is outside the report’s frame. ## 02. Grand Forks hearing: UAS and the National Airspace System *Event / publication dates: 13 September 2010* **Verified record — [Fact — A1]** The Senate Commerce Aviation Subcommittee held a field hearing in Grand Forks, North Dakota. FAA’s Hank Krakowski testified that limited safety data do not support expedited or full UAS integration; public operators use Certificates of Authorization; civil operators need a Special Airworthiness Certificate—Experimental Category; commercial UAS operations in the U.S. are not permitted; an ExCom (DoD, FAA, DHS, NASA) exists under the FY2009 NDAA. He said FAA then had 251 COAs, 140 of them DoD-related, and had not rejected any DoD COA in 2010; CBP already flew operational missions from Grand Forks. David Ahern (OSD) said a NAS Access Plan and DoD Site Transition Plan were due to Congress in October. Maj. Gen. Marke Gibson said RPA technology had over 1 million hours of operations and that 35 percent of Air Force aircraft acquisition over the next five years was programmed to be unmanned; he worried January 2012 Predator bed-down at Grand Forks could outrun restricted-airspace rulemaking. Fetched: https://irp.fas.org/congress/2010_hr/uas.html **Threat landscape.** The trust failure is lost-link and see-and-avoid in mixed airspace. The physical consequence of getting this wrong is a mid-air; the political consequence is delayed training for combat RPA crews. **Intelligence assessment.** [Assessment — high confidence] FAA’s public position is deliberate, incremental access — not a 2010 civil market. [Inference — moderate confidence] DoD training demand will keep colliding with restricted-airspace timelines. [Uncertainty] The October NAS Access Plan is not yet public at this cutoff. **Opportunity.** Delivery of the October plan on time would be the next Control Fabric artifact. **LRRK relevance.** Control Fabric / Campaign / Watch. Passport: ExCom membership, COA-only civil path, Grand Forks as a named bed-down/training fight. No COTS quadcopter market is implied. **Confidence.** High on the hearing record; high that commercial UAS operations are not permitted. ## 03. Symantec’s comprehensive Stuxnet analysis *Event / publication dates: 30 September 2010 (Virus Bulletin presentation / comprehensive analysis per Symantec timeline)* **Verified record — [Fact — A1]** Symantec’s dossier timeline states that on 30 September 2010 Symantec presented at Virus Bulletin and released comprehensive analysis of Stuxnet. The same document’s executive summary states Stuxnet targets a specific industrial control system likely in Iran, that its goal is to sabotage a facility by reprogramming PLCs, that it was discovered in July but existed at least a year prior, that a majority of infections were in Iran, and that it includes a Windows rootkit and a PLC rootkit. Infection-statistics pages in the November 1.3 text say that as of 29 September 2010 Symantec’s C&C monitoring had shown approximately 100,000 infected hosts and that looking at percentage of infected hosts by country, approximately 60% were in Iran. This brief does not describe exploits or PLC-attack procedures. Fetched: https://www.cs.unh.edu/~it666/reading_list/ZeroDay/w32_stuxnet_dossier.pdf **Threat landscape.** Public technical consensus now treats Stuxnet as intentional industrial sabotage via controller reprogramming — cyber-to-physical Act — geographically concentrated in Iran. IAEA has not said so. **Intelligence assessment.** [Assessment — high confidence] Symantec’s 30 September analysis is the month’s technical primary. [Inference — moderate confidence] Iran-as-target is now the leading open-source hypothesis, not a proven state attribution. [Uncertainty] Plant identity (enrichment versus other ICS) is still not an IAEA Fact. **Opportunity.** An Iranian official admission or an IAEA malware-related note would have been the physical-effect primary. **LRRK relevance.** Lab / Sense-Move-Act / Kestrel. File the 30 September analysis as the public PLC-Act paper; keep IAEA and Symantec on separate ledgers. **Confidence.** High on Symantec’s own dates and infection geography as Symantec measured C&C; moderate on target identification. ## 04. Additional Windows patches around Stuxnet’s other propagation paths *Event / publication dates: 14 September 2010 (MS10-061 per Symantec timeline)* **Verified record — [Fact — A1]** Symantec’s timeline states that on 14 September 2010 Microsoft released MS10-061 to patch the Printer Spooler vulnerability identified by Symantec in August, and that Microsoft reported two other privilege-escalation vulnerabilities identified by Symantec in August. Fetched: https://www.cs.unh.edu/~it666/reading_list/ZeroDay/w32_stuxnet_dossier.pdf **Threat landscape.** Platform-security Control Fabric is catching up to a worm that used multiple Windows defects. Patching Windows does not restore trust in a PLC that may already have hidden logic. **Intelligence assessment.** [Assessment — high confidence] September’s Microsoft releases are part of the Stuxnet-period patch cycle. [Inference — moderate confidence] ICS networks that delay patches remain the residual host path. [Uncertainty] This brief does not independently verify Microsoft bulletin text beyond Symantec’s timeline. **Opportunity.** Microsoft’s own bulletin pages would have been a second A1; they were not separately fetched. **LRRK relevance.** Lab. Record bulletin IDs and dates only. **Confidence.** High on Symantec’s dated claim; moderate pending Microsoft-page fetch. ## 05. Extra-theater UAV Act and the unanswered legal FOIA *Event / publication dates: continuing; ACLU request 13 January 2010* **Verified record — [Fact — B2]** No September official U.S. legal memorandum on Predator targeted killings was fetched. The ACLU January FOIA remains the public demand. The January C2 snapshot (Virginia satellite control, Pakistani launch base) remains the last detailed official-adjacent description in this collection. Fetched: https://www.aclu.org/press-releases/aclu-requests-information-predator-drone-program ; https://www.nbcnews.com/id/wbna35027603 **Threat landscape.** Three September Control Fabrics — IAEA, FAA/NAS, Symantec/ICS — still leave the CIA/DoD kill-chain legal theory unpublished. **Intelligence assessment.** [Assessment — moderate confidence] Continuity of the unacknowledged Act program. [Uncertainty] September strike-level Facts not fetched. **Opportunity.** Any September FOIA production or Glomar would have been the legal signal. **LRRK relevance.** Control Fabric / Kestrel. Keep the FOIA open beside the new Stuxnet and airspace files. **Confidence.** Moderate on continuity. ## Forward indicators Ranked watchlist as of the collection cutoff (what a 2001–2011 Watch desk would have monitored next). 1. October NAS Access Plan / DoD Site Transition Plan promised to Congress. 2. Next IAEA Iran report — any unexplained centrifuge-removal language. 3. Siemens or asset-owner confirmation of PLC modification in a named plant. 4. Next WikiLeaks tranche. 5. Fire Scout return-to-flight after the August lost-link. > **Collection integrity.** IAEA from GOV/2010/46 PDF. Hearing from the official printed record at FAS. Stuxnet September items from Symantec’s dossier (including 29 September infection statistics as Symantec’s own C&C measurement). No exploit recipe. No claim that IAEA endorsed Symantec’s Iran-target hypothesis. CRS RS21698 is July, not re-used as a September event. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C1</span></p>