AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

TabletopExercise

skill-securitytalent-bugskill-ai-tabletopexercise · by SecurityTalent

Comprehensive cybersecurity tabletop exercise design and facilitation framework. USE WHEN designing incident response scenarios, creating executive or technical tabletops, generating atomics for exercise runners, identifying missing SOPs/playbooks, or evaluating organizational preparedness. Includes threat model integration, CISA-aligned methodologies, and automated gap analysis.

No reviews yet
0 installs
12 views
0.0% view→install

Install

$ agentstack add skill-securitytalent-bugskill-ai-tabletopexercise

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-securitytalent-bugskill-ai-tabletopexercise)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
18d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of TabletopExercise? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

TabletopExercise Skill

Purpose

Design, facilitate, and evaluate cybersecurity tabletop exercises (TTX) for technical and executive audiences. Generate realistic scenarios, technical atomics for runners, and identify organizational gaps in incident response capabilities.

When to Use

  • Designing tabletop exercise scenarios for SOC teams or executives
  • Creating technical "atomics" (executable injects) for scenario runners
  • Generating checklists to identify missing SOPs, playbooks, or procedures
  • Evaluating incident response plan effectiveness
  • Building cross-functional coordination exercises
  • Post-exercise gap analysis and improvement planning

Key Capabilities

1. Scenario Generation

  • Executive Scenarios: Business impact focus, decision-making, communication strategies
  • Technical Scenarios: Detailed detection/response, forensics, technical challenges
  • Hybrid Scenarios: Cross-functional coordination exercises
  • AI-Enhanced: Deepfake attacks, automated threat chains, supply chain compromise

2. Technical Atomics for Runners

Exercise facilitators receive executable atomics - specific technical actions to simulate during scenarios:

Example Atomic Set (Ransomware Scenario):

T+0min: Send initial phishing email to participant's test inbox
T+15min: Simulate EDR alert: "Suspicious PowerShell execution on DESKTOP-01"
T+30min: Inject: Backup system shows "Replication failed - destination unreachable"
T+45min: Deliver ransom note via simulated file share
T+60min: Simulate CEO email inquiry: "Why can't I access the sales database?"

3. SOP/Playbook Gap Analysis

Automatically generates checklists identifying missing procedures:

Example Output:

MISSING PLAYBOOKS IDENTIFIED:
□ Ransomware Response Playbook
  - Detected mentions of: encryption, ransom, backup restoration
  - No documented procedure found for: crypto-ransomware containment

□ Executive Communication Protocol
  - Scenario requires CEO notification
  - Missing: Executive notification checklist, approval thresholds

□ Vendor Breach Response
  - Third-party compromise scenario element present
  - Missing: Vendor incident coordination runbook

4. Threat Model Integration

Scenarios built from real-world threat models:

  • OAuth 2.0 attacks (RFC 6819)
  • Kubernetes cluster compromise
  • Supply chain attacks (npm, CDN)
  • Cloud storage misconfiguration (AWS S3, GCS)
  • IoT device exploitation
  • AI/ML workload threats

5. CISA-Aligned Framework

Follows CISA Cybersecurity Tabletop Exercise Package (CTEP) methodology:

  • 100+ pre-built scenario templates
  • Facilitator guides and inject cards
  • After-Action Report templates
  • Objective-based performance analysis

Core Framework: Plan → Engage → Learn

Planning Phase

  1. Define Objectives: 1-3 measurable goals (e.g., "Validate ransomware playbook")
  2. Select Scenario: Match to organizational risk profile and threat landscape
  3. Identify Participants: Cross-functional teams with actual decision authority
  4. Prepare Materials: Scenario brief, injects, facilitator script, evaluation forms

Engaging Phase

  1. Set Ground Rules: Psychological safety, low-pressure learning environment
  2. Present Scenario: Realistic T0 (initial conditions)
  3. Progressive Injects: Timed complications (ransom notes, backup failures, media inquiries)
  4. Facilitate Discussion: Open-ended questions, cross-functional coordination
  5. Document Observations: Real-time data collection by evaluators

Learning Phase

  1. Hot Wash: 20-30 min immediate debrief
  2. After-Action Report: Strengths, gaps, recommendations
  3. Action Items: Assigned owners, deadlines, tracking
  4. Implementation: Update IR plans, develop missing SOPs, schedule training
  5. Follow-Up Exercise: Test improvements in 6-12 months

Scenario Types (Based on Threat Models)

1. Ransomware Attack

  • Initial Vector: Phishing, RDP compromise, vulnerable service
  • Progression: Lateral movement, backup encryption, ransom demand
  • Key Decisions: Containment strategy, backup restoration, ransom payment consideration, law enforcement notification
  • Atomics: EDR alerts, file encryption simulation, backup system failures, ransom note delivery

2. Business Email Compromise (BEC)

  • Initial Vector: Executive account takeover (OAuth token theft, password spray)
  • Progression: Fraudulent wire transfer request, financial approval bypass
  • Key Decisions: Transaction verification, account suspension, fraud investigation
  • Atomics: Spoofed email delivery, banking system access attempts, approval workflow bypass

3. Supply Chain Breach

  • Initial Vector: Compromised vendor, malicious npm package, CDN compromise
  • Progression: Backdoored dependencies, data exfiltration, customer impact
  • Key Decisions: Vendor communication, customer notification, incident disclosure
  • Atomics: Dependency scan alerts, network traffic to unknown IPs, customer data access logs

4. Kubernetes Cluster Compromise

  • Initial Vector: Exposed API server, vulnerable container image, RBAC misconfiguration
  • Progression: Container escape, privilege escalation, cryptomining deployment
  • Key Decisions: Pod isolation, cluster rebuilding, service continuity
  • Atomics: kubectl alerts, resource utilization spikes, container logs

5. Cloud Storage Misconfiguration

  • Initial Vector: Public S3 bucket, misconfigured GCS permissions, leaked credentials
  • Progression: Data discovery by attacker, exfiltration, public disclosure
  • Key Decisions: Access revocation, data breach notification, regulatory reporting
  • Atomics: CloudTrail anomalies, data access logs, security researcher notification

6. Deepfake Social Engineering (AI-Enhanced)

  • Initial Vector: Deepfake CEO voice call, AI-generated phishing content
  • Progression: Fraudulent authorization, sensitive data disclosure, financial fraud
  • Key Decisions: Out-of-band verification protocols, AI detection strategies
  • Atomics: Voice call simulation, urgent request for credentials/payments

7. Insider Threat

  • Initial Vector: Disgruntled employee, compromised insider account, privilege abuse
  • Progression: Data exfiltration, system sabotage, unauthorized access
  • Key Decisions: Investigation protocols, legal coordination, termination procedures
  • Atomics: DLP alerts, unusual data transfers, off-hours access logs

8. DDoS Attack

  • Initial Vector: Botnet attack, amplification attack, application-layer DDoS
  • Progression: Service degradation, customer impact, mitigation coordination
  • Key Decisions: CDN activation, rate limiting, customer communication
  • Atomics: Traffic spike simulation, service health dashboards, customer complaints

Technical vs Executive Audience

Executive Tabletop (Non-Technical)

Duration: 60-90 minutes Participants: C-suite, Board, Executive Directors, Business Unit heads Focus:

  • Business impact and continuity decisions
  • External communication and PR strategy
  • Regulatory compliance and legal considerations
  • Financial impact and insurance coordination
  • Stakeholder management

Language: Non-technical, succinct, business-focused Outcomes: Improved alignment between leadership and technical teams, clarified executive roles during crises

Technical Tabletop (Operational)

Duration: 90-120 minutes Participants: SOC analysts, incident responders, IT Ops, Security Engineers Focus:

  • Detection and containment procedures
  • Forensic analysis and evidence collection
  • Technical tool usage (SIEM, EDR, forensics platforms)
  • System recovery and backup restoration
  • Threat intelligence and IOC extraction

Language: Deep technical content, command-line operations, log analysis Outcomes: Validated technical playbooks, identified tool gaps, improved technical coordination

Atomics Generation Framework

When generating atomics for exercise runners, provide:

1. Pre-Exercise Setup Atomics

# Example: Ransomware scenario setup
# T-60min: Prepare test environment
- Create isolated test VM (VICTIM-01)
- Deploy test file share with sample data
- Configure email server for phishing simulation
- Prepare EDR console access for runner
- Stage ransom note template in runner directory

2. Timed Inject Atomics

## T+0 (Initial Compromise)
**Atomic ID**: PHISH-001
**Action**: Send phishing email to participant John Doe
**Email Template**: /exercises/ransomware-2024/templates/phish.eml
**Expected Response**: Participant reports email to security team within 15 minutes
**If No Response**: Proceed to T+15 inject regardless

## T+15 (EDR Alert)
**Atomic ID**: EDR-ALERT-001
**Action**: Display EDR alert on SOC dashboard
**Alert Details**:
  - Host: DESKTOP-01
  - User: jdoe
  - Process: powershell.exe -enc 
  - Severity: HIGH
**Expected Response**: SOC analyst triages alert, escalates to IR team
**Facilitator Note**: If asked about base64 content, provide: "Downloads and executes secondary payload"

## T+30 (Backup Failure)
**Atomic ID**: BACKUP-FAIL-001
**Action**: Update backup system dashboard
**Status Change**: Replication status → "Failed - destination unreachable"
**Error Message**: "Cannot connect to backup-server-02.internal"
**Expected Response**: IT team investigates backup system, discovers encrypted files on backup target

3. Variable Response Atomics

## Conditional Inject: If Participants Ask to Check Logs
**Atomic ID**: LOG-RESPONSE-001
**Trigger**: Participant requests "Check firewall logs for outbound connections"
**Response**: Provide log excerpt showing:
  - Multiple connections to 203.0.113.42:8443 (C2 server)
  - Data exfiltration: 2.3 GB transferred over 4 hours
  - TLS encrypted traffic, no payload inspection available
**Facilitator Script**: "Your firewall logs show persistent connections to this IP over the last 4 hours. WHOIS shows it's registered in [Country]. What's your next step?"

4. Escalation Atomics

## T+60 (Executive Pressure)
**Atomic ID**: EXEC-EMAIL-001
**Action**: Simulate email from CEO to CTO (delivered via runner to participant)
**Subject**: "RE: Sales Database Access Issue - URGENT"
**Body**:
"I'm getting reports from the sales team that they can't access Salesforce. This is costing us deals. What's the status? Do we need to involve the board?"
**Expected Response**: CTO briefs CEO on incident status, provides estimated recovery timeline
**Facilitator Note**: If participants haven't identified ransomware yet, this pressure should accelerate investigation

SOP/Playbook Gap Analysis Checklist Generator

The skill automatically generates gap analysis checklists by:

  1. Scenario Decomposition: Identifies all decision points and required actions
  2. Playbook Mapping: Checks for documented procedures covering each action
  3. Gap Identification: Flags missing or inadequate procedures
  4. Priority Scoring: Ranks gaps by criticality and likelihood

Example Gap Analysis Output

# SOP/Playbook Gap Analysis
**Scenario**: Ransomware Attack with Backup Failure
**Date**: 2026-02-06
**Participants**: SOC Team, IT Operations, Executive Leadership

---

## CRITICAL GAPS (Immediate Action Required)

### 1. Ransomware Containment Playbook - MISSING
**Scenario Trigger**: Multiple hosts showing file encryption behavior
**Required Decisions**:
  - [ ] Network segmentation procedures
  - [ ] Host isolation criteria and process
  - [ ] Active Directory credential reset procedures
  - [ ] Encrypted file preservation for forensics

**Impact if Missing**: Delayed containment, lateral spread to additional systems
**Recommendation**: Develop comprehensive ransomware response playbook covering:
  - Detection indicators (behavioral, file system, network)
  - Containment decision tree (isolate vs observe)
  - Credential rotation procedures
  - Backup verification and restoration process
  - Ransom payment decision framework (if organization policy allows consideration)

**Owner**: ___________ **Due Date**: ___________

---

### 2. Executive Communication During Active Incident - INADEQUATE
**Scenario Trigger**: CEO requests status update during ongoing incident
**Current Documentation**: Generic "incident notification template"
**Missing Elements**:
  - [ ] Executive briefing format and content requirements
  - [ ] Update frequency expectations during active incidents
  - [ ] Escalation thresholds requiring executive notification
  - [ ] Technical-to-business impact translation guide
  - [ ] Executive decision authority matrix (who approves what)

**Impact if Missing**: Inconsistent executive communication, business decision delays
**Recommendation**: Create executive incident communication playbook with:
  - Situation Report (SITREP) template
  - Update cadence by severity (Critical: hourly, High: every 4 hours)
  - Decision points requiring executive approval
  - Business impact assessment framework

**Owner**: ___________ **Due Date**: ___________

---

## HIGH-PRIORITY GAPS

### 3. Backup System Failure Response - PARTIAL
**Scenario Trigger**: Backup replication shows failed status
**Current Documentation**: IT runbook covers "routine backup monitoring"
**Missing Elements**:
  - [ ] Backup system compromise response procedures
  - [ ] Alternate backup verification methods (offline, immutable copies)
  - [ ] Backup restoration priority matrix (which systems first)
  - [ ] Backup integrity testing procedures

**Impact if Missing**: Extended recovery time, potential data loss
**Recommendation**: Enhance backup procedures with incident-specific guidance
**Owner**: ___________ **Due Date**: ___________

---

### 4. Third-Party Vendor Notification - MISSING
**Scenario Trigger**: Incident may impact vendor systems or data
**Required Decisions**:
  - [ ] When to notify vendors (timing, thresholds)
  - [ ] Who has authority to communicate with vendors
  - [ ] What information to share (technical details, IOCs)
  - [ ] Vendor incident coordination protocols

**Impact if Missing**: Contractual violations, delayed coordinated response
**Recommendation**: Develop vendor incident coordination framework
**Owner**: ___________ **Due Date**: ___________

---

## MEDIUM-PRIORITY GAPS

### 5. Forensic Evidence Collection - PARTIAL
**Scenario Trigger**: Need to preserve evidence for investigation/legal action
**Current Documentation**: "Incident handling basics" mentions "save logs"
**Missing Elements**:
  - [ ] Chain of custody procedures
  - [ ] Forensic image acquisition tools and methods
  - [ ] Evidence storage and retention policies
  - [ ] Legal hold procedures

**Impact if Missing**: Compromised evidence, inability to pursue legal action
**Recommendation**: Develop forensic evidence handling SOP
**Owner**: ___________ **Due Date**: ___________

---

## LOW-PRIORITY GAPS

### 6. Post-Incident Customer Communication - MISSING
**Scenario Trigger**: Ransomware impacts customer-facing services
**Missing Elements**:
  - [ ] Customer notification templates
  - [ ] Communication approval workflow
  - [ ] Regulatory notification requirements (GDPR, state breach laws)
  - [ ] Customer support escalation procedures

**Impact if Missing**: Regulatory non-compliance, customer trust damage
**Recommendation**: Create customer breach notification playbook
**Owner**: ___________ **Due Date**: ___________

---

## PROCESS GAPS

### Communication Channels
**Observed During Exercise**:
- Confusion about which Slack channel for incident coordination
- Some participants didn't have access to #incident-response
- Email used for time-sensitive updates (slow, unreliable)

**Recommendation**:
  - [ ] Establish dedicated incident communication platform
  - [ ] Pre-provision access for all IR team members
  - [ ] Document escalation procedures (when to page, when to email)

…

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [SecurityTalent](https://github.com/SecurityTalent)
- **Source:** [SecurityTalent/bugskill-ai](https://github.com/SecurityTalent/bugskill-ai)
- **License:** MIT
- **Homepage:** https://securitytalent.net

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.