Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+17 more

    Security Operations Tabletop Exercise Facilitator

    2

    Design, facilitate, and document professional security incident response tabletop exercises and after-action reports.

    Secure checkout via Stripe

    0 installsSecurity scanned

    See it in action

    You say

    Design a three-hour ransomware security operations tabletop exercise for Tier 1 analysts, Tier 2 analysts, the SOC manager, IT operations, legal, communications, and executive stakeholders. Keep tooling generic and produce a facilitator guide, timed inject schedule, evaluation scorecard, and after-action report template.

    Your agent does

    The skill produces an exercise planning brief confirming objectives, participants, and duration, a timed inject schedule with six escalating injects covering detection, triage, containment, executive briefing, communications, and recovery decisions, a facilitator guide with role-based discussion prompts and observer notes for each inject, an evaluation scorecard assessing process quality, decision making, escalation, communication, and documentation, and an after-action report structure separating strengths, gaps, risks, root causes, actions, owners, and validation points. All tooling references are marked as generic placeholders.

    What you get

    Design realistic incident scenarios with timed technical and business injectsValidate internal IR playbooks and cross-functional escalation workflowsProduce audit-ready After Action Reports and remediation action trackersTest communication lines between technical teams and executive leadership

    About this skill

    High-Fidelity Security Tabletop Facilitation

    This skill automates the complex process of designing, running, and documenting professional security operations tabletop exercises (TTX). Instead of spending days drafting scenarios and injects, developers and security leads can generate comprehensive exercise packages tailored to their specific stack and playbooks.

    What it does

    • Architects realistic multi-stage incident scenarios (Ransomware, BEC, Supply Chain, etc.).
    • Generates timed "injects" with specific evidence artifacts (log snippets, alerts, tickets).
    • Validates existing IR playbooks and cross-functional escalation workflows.
    • Produces professional After Action Reports (AAR) with strength/gap analysis and remediation trackers.

    Why use this skill

    Prompting a generic AI often results in shallow, linear stories. This skill follows a rigorous evaluation framework, forcing participants to make hard decisions at each stage. It integrates context from your SIEM, EDR, and SOAR tools to create realistic technical hurdles while managing the non-technical aspects like legal, PR, and executive briefings. It ensures your IR drills are audit-ready and demonstrate measurable resilience improvement.

    Supported Deliverables

    • Exercise Plan: Strategy, scope, and objectives.
    • Facilitator Guide: Detailed prompts, expected answers, and observer notes.
    • Inject Schedule: A timeline of technical and business developments.
    • Scorecard & AAR: Structured evaluation of team performance and gap identification.

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 3 months ago

    • One-time purchase, yours forever

    Listed3 months ago

    Frequently Asked Questions