performing-soc-tabletop-exercise

Featured

Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when organizations need to validate IR playbooks, train analysts, or meet compliance requirements for incident response testing.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Performing SOC Tabletop Exercise ## When to Use Use this skill when: - Annual or semi-annual incident response testing is required (NIST, ISO 27001, PCI DSS compliance) - New SOC analysts need exposure to major incident scenarios in a controlled environment - Updated playbooks need validation before next real incident - Cross-functional coordination (SOC, IT, Legal, PR, Executive) needs rehearsal - Post-incident reviews reveal gaps requiring scenario-based training **Do not use** as a replacement for technical purple team exercises — tabletop exercises test processes and decision-making, not technical detection capabilities. ## Prerequisites - Exercise facilitator with incident response experience - Participant list: SOC analysts (Tier 1-3), SOC manager, IT operations, Legal, HR, Communications - Conference room or video call with screen sharing capability - Printed or digital scenario injects with timed release schedule - Evaluation scorecard for assessing participant responses - Existing incident response plan and playbooks for reference during exercise ## Workflow ### Step 1: Design Exercise Scenario Create a realistic multi-phase scenario with escalating complexity: ```yaml tabletop_exercise: title: "Operation Dark Harvest — Ransomware Attack Scenario" exercise_id: TTX-2024-Q1 date: 2024-03-22 duration: 3 hours (09:00-12:00) classification: TLP:AMBER (internal use only) objectives: 1: "Test SOC team's ability to detect and triage ransomware ind...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

performing-ransomware-tabletop-exercise

Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill.

12,642 Updated today
mukul975
AI & Automation Featured

performing-purple-team-exercise

Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.

12,642 Updated today
mukul975
AI & Automation Featured

executing-red-team-exercise

Executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial reconnaissance through objective completion while testing the organization's detection and response capabilities. This differs from penetration testing by focusing on adversary emulation rather than vulnerability identification. Activates for requests involving red team exercise, adversary simulation, adversary emulation, or full-scope offensive security assessment.

12,642 Updated today
mukul975
AI & Automation Featured

building-soc-playbook-for-ransomware

Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formalized response procedures for ransomware incidents aligned to NIST SP 800-61 and MITRE ATT&CK ransomware techniques.

12,642 Updated today
mukul975
AI & Automation Solid

csoc-operations--playbook-automation

SOC alert triage, incident playbook automation, escalation workflows, shift reporting, and SOC KPI tracking

47 Updated today
Masriyan