Skip to content

Scenario Drills

Structured incident-response scenarios for practicing triage, containment, and resolution.

Schema

Each scenario YAML file contains a scenarios list. Each entry has:

Field Type Description
id string Unique identifier (e.g., ir-scenario-001)
topic string Incident category (e.g., credential_exposure)
difficulty string easy, medium, or hard
scenario string The situation description presented to the learner
expected_actions list[str] Ordered actions the learner should take
pitfalls list[str] Common mistakes to avoid
source_path string Path to the source file

Files

  • incident-response.yaml — 11 scenarios covering credential exposure, suspicious logins, compromised hosts, backup failures, alert storms, DNS outages, K8s rollouts, storage exhaustion, load balancer issues, IAM mysteries, and data loss.

Adding Scenarios

  1. Add entries to an existing YAML file or create a new <topic>.yaml following the schema above.
  2. Use realistic, actionable scenarios with clear expected actions and non-obvious pitfalls.
  3. Aim for a mix of easy/medium/hard difficulties.