performing-soc-tabletop-exercise

Designs and facilitates discussion-based SOC tabletop exercises simulating security incidents to validate incident response procedures.

954|172|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/xalgord/xalgorix --skill performing-soc-tabletop-exercise
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: performing-soc-tabletop-exercise
Source: https://github.com/xalgord/xalgorix/tree/main/internal/tools/skills/data/soc-operations/performing-soc-tabletop-exercise
Command: npx skills add https://github.com/xalgord/xalgorix --skill performing-soc-tabletop-exercise

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security teams often have incident response plans that have never been tested, leaving gaps in escalation procedures, cross-functional communication, and recovery readiness undiscovered until a real breach occurs. This Skill guides the design, facilitation, and evaluation of discussion-based tabletop exercises that test IR playbooks and decision-making without touching production systems.

Core Features & Use Cases

  • Scenario and Inject Design: Builds multi-phase scenarios (ransomware, data breach, insider threat, BEC, supply chain) with timed injects that escalate complexity and force real decision-making under pressure.
  • Facilitation and Evaluation Framework: Provides facilitator protocols, role-based discussion questions, and scoring criteria across detection, containment, communication, and recovery dimensions.
  • After-Action Reporting and Remediation Tracking: Generates structured AARs with scored objectives, gap findings, and assigned action items, plus a Splunk query for tracking remediation due dates.
  • Use Case: A SOC manager needs to satisfy NIST and PCI DSS incident response testing requirements before an audit. Use this Skill to run a 3-hour ransomware tabletop exercise with SOC, Legal, PR, and executives, then produce a scored after-action report with owned remediation items.

Quick Start

Design a ransomware tabletop exercise for my SOC team with timed injects, evaluation scorecards, and an after-action report template.

Frequently Asked Questions about performing-soc-tabletop-exercise

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a SOC tabletop exercise for incident response testing?

Define measurable objectives, build a multi-phase scenario with timed injects, and facilitate role-based discussion with SOC, IT, Legal, and Communications participants. Score responses against detection, containment, communication, and recovery criteria, then produce an after-action report with owned action items.

What scenarios work best for security tabletop exercises?

Common scenarios include ransomware attacks, customer data breaches, supply chain compromise, insider threats, and business email compromise. Each should escalate across phases covering initial detection, containment decisions, business pressure, forensic discovery, and recovery.

Does a tabletop exercise satisfy NIST or PCI DSS compliance requirements?

Yes, tabletop exercises are a recognized method for annual or semi-annual incident response testing required by NIST, ISO 27001, and PCI DSS. The exercise must produce documented evidence such as an after-action report with scored objectives and tracked remediation items.

What is the difference between a tabletop exercise and a purple team exercise?

Tabletop exercises are discussion-based simulations that test processes, communication, and decision-making without touching systems. Purple team exercises are technical validations of detection and response capabilities against live attack techniques, so tabletop exercises should not replace them.

Why do tabletop exercises fail to improve incident response?

The most common failure is no follow-through: findings are logged but action items lack owners, due dates, or tracking, so the same gaps recur. Other causes include vague objectives, overly scripted injects, and excluding cross-functional roles like Legal and Communications.