Home/Catalogue/Real-World Incidents
Exercise domain

Real-World Incidents

5 drills · 2 playable free, no sign-up

Each of these is modelled on a real, publicly reported attack, rebuilt as a scenario with a fictional company so the focus stays on the decision that mattered. Your team lives the moment it turned, then sees what the responders did next.

MITRE ATT&CKNIST CSFVerizon DBIR patterns
Play the full track 2 drills back to back, or pick one below
Play now

The help desk that reset the wrong account

Modelled on a 2023 casino-sector breach: a caller talks a service desk into a password reset. See how one polite call became a full intrusion.

ATT&CK T1078ATT&CK T1598
Play exerciseCore · 9 min
Play now

The invoice attachment

Based on the wave of malicious document attachments: a routine-looking invoice arrives with a payload one click away. Handle it the safe way.

ATT&CK T1566.001ATT&CK T1204
Play exerciseCore · 8 min
In build

The open storage bucket

Modelled on repeated cloud exposures: a storage bucket set to public spills customer records. Trace how it happened and how it is found.

ATT&CK T1530CIS 3
In buildAdvanced · 8 min
In build

The payroll diversion

A composite of business email compromise cases: an employee’s salary is redirected by a single convincing email to HR. Catch it in time.

ATT&CK T1566.002NIST PR.AT
In buildCore · 8 min
In build

The third party that let them in

Drawn from supply-chain intrusions: access came through a trusted supplier, not the front door. See why vendor access is your attack surface.

ATT&CK T1195ISO A.5.19
In buildAdvanced · 9 min
How to play these. Each drill with a Play exercise link opens straight into that scenario in the 3D sim: finish it, then come back and pick another, or hit Play the full track to run them back to back. Drills marked In the program ship with the guided rollout. Book a demo for the full library.