Incident Response Simulator
Pick Your Crisis Each scenario is a branching tabletop you work from three seats as it escalates. Your decisions compound, the intel is incomplete, and the clock never stops. Choose one to begin.
Insider Threat
Notice Period A departing engineer is moving data he should not be. Catch it, prove it, and survive the politics.
Insider Threat DFIR Disclosure
Start scenario Ransomware
Blast Radius Double-extortion ransomware detonates on a Saturday night. Contain it, recover it, and decide whether to pay.
Ransomware DFIR Recovery Ransom & OFAC
Start scenario Business Email Compromise
Pending Wire A $1.8M payment just left on a forged banking change. The mailbox has been read for two weeks. Get the money, evict the ghost, and decide what to disclose.
BEC Wire Fraud Email Security Insurance
Start scenario Supply Chain Compromise
Trust Anchor A trusted monitoring vendor shipped a signed backdoor to 412 of your systems. You cannot patch their code. Decide how hard to assume the worst, and how much to trust them next.
Supply Chain Third-Party Risk Threat Hunting Vendor Trust
Start scenario DDoS Extortion
Peak Hour A multi-vector flood hits your store on its biggest sale day, then the ransom note arrives. Keep the lights on, call the bluff, and decide what the world gets told.
DDoS Extortion Disclosure
Start scenario OT Intrusion
Safe State Someone is on the plant floor and on the OT network of a water utility, and they left something behind. Keep the process safe, find the implant, and decide what the town is told.
OT/ICS Physical Critical Infrastructure
Start scenario Lost Device
Last Seen A CFO's laptop is gone in a foreign city and her account is lighting up from the same place. Close the right hole, prove what you can, and decide who to tell.
Lost Device Identity Disclosure
Start scenario Web Application Breach
Open Door A researcher emails you a sample of your own customer database, pulled through a flaw in your portal. The bug is still live and the clock on disclosure has already started.
Web Breach SQLi DFIR Disclosure
Start scenario Edge Device Zero-Day
Hold the Line An actively-exploited zero-day hits the VPN appliance that is your company's front door. There is no patch yet, the vendor is slow, and pulling it offline locks everyone out.
Zero-Day Threat Hunting Perimeter Vendor Trust
Start scenario Cloud Credential Leak
Key to the Kingdom An engineer pushed admin AWS keys to public GitHub at 2am. Bots found them in minutes. Now something is mining crypto on your dime and reaching for your customer data.
Cloud IAM Credential Leak Disclosure
Start scenario Deepfake Executive Fraud
The Voice on the Line A flawless AI clone of the CFO's voice calls in an urgent $4M wire and an MFA reset on her account. There is no malware here. The attack is trust, and your process is the target.
Deepfake Vishing Wire Fraud Social Engineering
Start scenario Destructive Wiper
Scorched Earth Systems are bricking across the estate and no ransom note ever comes, because the goal is destruction, not money. There is no decryptor to buy, only a recovery to earn and a theft to find under the ash.
Wiper Destruction DFIR Recovery
Start scenario More scenarios in development. Each plays differently and grades differently.