Incident Response (IR) Drill
Technical drill focusing on detection, containment, and eradication.
Functional Drill 1 Day
Scroll
Back to List
Scenario Overview
A technical, hands-on drill designed for your SOC and System Administrators. We simulate indicators of compromise (IoCs) within a controlled environment to measure the "Mean Time to Detect" (MTTD) and "Mean Time to Respond" (MTTR). This "walk" phase uses limited live injects.
How It Works
Scenario Design
Selecting specific technical IoCs (e.g., beaconing malware).
Technical Setup
Configuring the range or isolated subnet.
Drill Execution
Launching real but contained malware samples or scripts.
Analysis
Reviewing logs to see if the team detected the activity.
Key Outcomes
Detection logic tuning
Improved MTTD/MTTR metrics
Training Objectives
- Assess tool efficacy (SIEM, EDR, Firewall)
- Practice containment strategies (network isolation)
- Validate forensic evidence preservation
- Identify blind spots in network visibility
Who Should Attend
- SOC Analysts
- Network Engineers
- System Administrators
Related Exercises
Prerequisites
- • Access to SIEM/EDR consoles
- • Authorized testing window
Value to Business
- » Metrics-driven assessment of SOC performance
- » Identifies tool misconfigurations
- » Improves technical response speed