Tabletop exercises for security & IR teams

Run the incident before it runs you.

TTX puts your team through realistic, facilitated incident-response drills — ransomware, breaches, insider threats — while an AI facilitator keeps the exercise moving: drafting injects, reading how your team responds, and calling when it's time to wrap.

Built by Stratus Studios. In active development.

Ransomware on Prod · Live
09:14

Facilitator (AI): New inject — backup snapshots from the last 6 hours are also encrypted.

09:15

Incident Commander: Isolate the backup network segment and confirm blast radius before we touch prod.

09:15

Facilitator (AI): Logged. Objective "Contain spread" — evaluated: strong.

Objectives covered
4/7

How it works

From scenario to after-action report.

  1. 01

    Pick a scenario, or build your own

    Start from the scenario library or write a custom one. Either way, the exercise is grounded in a NIST-based incident-response playbook your team can follow along with.

  2. 02

    Invite your team

    Participants join by email — a magic-link invite, no account to create. Anyone can be added to the room before the exercise starts.

  3. 03

    Run it live

    The AI facilitator drafts injects, evaluates each action as your team takes it, and suggests when to steer the exercise or bring it to a close.

  4. 04

    Review what happened

    Objective coverage and per-action evaluation roll straight into a generated after-action report your team can review and share.

Scenarios

A library of incidents your team will actually see.

Ransomware on production

Encryption hits production systems mid-shift. Contain the spread, decide on isolation, and work out what's actually recoverable.

Cloud data exfiltration

Data is leaving a cloud environment your team didn't provision for it. Trace the path, cut it off, and scope what got out.

Credential compromise & lateral movement

A credential is compromised and starts moving through the environment. Find the foothold before it becomes a takeover.

Cloud misconfiguration exploited

A misconfigured resource gets found and used. Work out what's exposed, how it was reached, and what to lock down first.

Insider threat & access revocation

An internal account is behaving like it shouldn't. Decide when to revoke access — and how to do it without tipping your hand.

Vendor / supply-chain compromise

A vendor you depend on is compromised. Work out what that vendor could touch in your environment, and act on it.

DDoS with customer impact

Traffic spikes past anything normal, and customers notice. Decide what to shed, what to protect, and who to tell.

Device loss with customer data

A device carrying customer data goes missing. Work through containment, disclosure, and what has to happen next.

AI facilitation

An AI facilitator that runs the room, not just the slides.

TTX's agent harness is built for live facilitation: it drafts the injects that move a scenario forward, evaluates what participants do as they do it, and suggests when to steer the exercise or bring it to a close. Every exercise runs against a NIST-based incident-response playbook, so the facilitation stays grounded in a real response framework instead of improvising.

  • Dynamic injects

    New information drops into the exercise based on how participants are actually responding, not a fixed script.

  • Per-action evaluation

    Each participant action is assessed against the scenario's objectives as it happens.

  • Steering suggestions

    The harness flags when an exercise is drifting and suggests a course correction.

  • Termination calls

    It tells you when the objectives are covered and the exercise is ready to wrap.

  • NIST-based playbooks

    Facilitation is grounded in NIST incident-response playbooks, not an improvised script.

Features

Built for teams who actually have to run this stuff.

Organizations, not just users

TTX is multi-tenant from the ground up — every organization's scenarios, exercises, and reports stay scoped to that organization.

Magic-link invites

Participants join from an email invite — no account, no password, no setup. Click the link and you're in the room.

Objective-coverage tracking

Every exercise is built around a set of objectives, and TTX tracks which ones get covered as the exercise runs.

After-action reports

When an exercise wraps, TTX generates an after-action report from the objective coverage and action evaluation — ready to review with the team.

A growing scenario library

Ransomware, exfiltration, lateral movement, insider threat, supply-chain compromise, and more — pick a starting point instead of a blank page.

Organizer controls

Organizers create and run exercises, control who's in the room, and decide when a scenario is ready to launch.

See TTX before everyone else does.

TTX is in active development. If your team runs — or wants to start running — tabletop exercises, we'd like to hear from you.