🛡️ Cyber Defense & SOC · Detection & Purple Team
Facilitate ransomware tabletops that find truth
Scenario injects probing decision boundaries, revealing plan gaps without blame theater.
intermediate~40 minSOC AnalystsDetection EngineersThreat Hunters
Steps
- 1Pick scenario targeting THIS org's crown jewels, not generic templates
- 2Script escalating injects with decision points and time pressure
- 3Assign roles including uncomfortable ones (legal, comms, CEO availability)
- 4Capture decision log verbatim; gaps speak louder than slides
- 5Debrief into ranked remediations with owners and deadlines
- 6Retest failed injects in the next exercise cycle
Common Pitfalls
- ▲Scenarios so fictional everyone plays along harmlessly
- ▲Action items dying between exercises year after year
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill detection-purple-tabletop-facilitationInstall globally
$ npx skills add aniruddhaadak80/skills --skill detection-purple-tabletop-facilitation -gTags
#tabletop#incident-response#exercises#cyber-defense-ops#detection-purple