IR Playbook Lab
In an incident, knowing what to do is easy. Knowing what order to do it in β and which tempting moves will destroy your evidence or reinfect your network β is what separates a clean recovery from a disaster. Sequence the response to a live ransomware case, respect the constraints a real incident imposes, and get a debrief that names every misstep. An AI incident commander runs the bridge with you.
Incident brief
At 02:14 a file server begins encrypting shares. Endpoint tooling flags a known ransomware family. The box holds customer PII. Backups exist but are 24h old. Build the response plan in the right order.
Goal
Contain, preserve evidence, eradicate, then recover β with the forensic image captured before anything is wiped, credentials rotated before restore (so you do not restore into a compromised identity), legal notified early, and no forbidden moves.
Available actions (click to add β some are traps)
Your response plan (0 steps)
Add actions above to build the ordered plan.
After-action score
Sequence the plan, then run it.
War room
live incidentbridge openingβ¦
What this lab is
- A free incident-response lab: given a live incident brief, assemble the response plan by sequencing actions across the NIST/SANS lifecycle.
- Order matters β the lab enforces real constraints: capture a forensic image before you wipe, rotate credentials before you restore, notify legal before the clock runs out.
- Some available actions are traps (pay the ransom, email the attacker, clear the logs) and are scored as critical failures.
- Running the plan produces an after-action score and a debrief that names every out-of-order step, missing mandatory action and forbidden move.
- A live war-room arena shows an AI incident commander and responders executing alongside you while the adversary tries to move.
Frequently asked questions
What is the IR Playbook Lab?
A free, in-browser incident-response exercise. You read an incident brief, then build an ordered response plan from a palette of actions spanning identify, contain, eradicate, recover and lessons-learned. The lab evaluates your sequence against the dependencies and obligations a real incident imposes and scores the run.
Why does the order matter so much?
Because the costliest IR mistakes are ordering mistakes. Wipe a host before you image it and the forensic evidence is gone forever. Restore from backup before you eradicate the malware and rotate credentials, and you reinfect the clean system or restore into a compromised identity. Notify the regulator late and you miss a statutory breach deadline. The lab models these as hard constraints, not opinions.
What are the trap actions?
Paying the ransom, emailing the attacker to negotiate, immediately wiping before imaging, and clearing the logs to "clean up" are all included in the palette and all scored as critical failures β they fund crime, tip off the adversary, or destroy the evidence and audit trail you and the regulator need. Recognising and avoiding them is part of the exercise.
Is the incident real?
No. The incident, the actions and the live participants are a self-contained simulation inside the page, built to teach the lifecycle and its ordering constraints. Nothing here touches a real system or network.