Scenario Drills¶
Structured incident-response scenarios for practicing triage, containment, and resolution.
Schema¶
Each scenario YAML file contains a scenarios list. Each entry has:
| Field | Type | Description |
|---|---|---|
id |
string | Unique identifier (e.g., ir-scenario-001) |
topic |
string | Incident category (e.g., credential_exposure) |
difficulty |
string | easy, medium, or hard |
scenario |
string | The situation description presented to the learner |
expected_actions |
list[str] | Ordered actions the learner should take |
pitfalls |
list[str] | Common mistakes to avoid |
source_path |
string | Path to the source file |
Files¶
incident-response.yaml— 11 scenarios covering credential exposure, suspicious logins, compromised hosts, backup failures, alert storms, DNS outages, K8s rollouts, storage exhaustion, load balancer issues, IAM mysteries, and data loss.
Adding Scenarios¶
- Add entries to an existing YAML file or create a new
<topic>.yamlfollowing the schema above. - Use realistic, actionable scenarios with clear expected actions and non-obvious pitfalls.
- Aim for a mix of easy/medium/hard difficulties.