Hero Background 0

Incident Response (IR) Drill

Technical drill focusing on detection, containment, and eradication.

Functional Drill 1 Day
Scroll
Back to List

Scenario Overview

A technical, hands-on drill designed for your SOC and System Administrators. We simulate indicators of compromise (IoCs) within a controlled environment to measure the "Mean Time to Detect" (MTTD) and "Mean Time to Respond" (MTTR). This "walk" phase uses limited live injects.

How It Works

Scenario Design

Selecting specific technical IoCs (e.g., beaconing malware).

Technical Setup

Configuring the range or isolated subnet.

Drill Execution

Launching real but contained malware samples or scripts.

Analysis

Reviewing logs to see if the team detected the activity.

Key Outcomes

Detection logic tuning
Improved MTTD/MTTR metrics

Training Objectives

  • Assess tool efficacy (SIEM, EDR, Firewall)
  • Practice containment strategies (network isolation)
  • Validate forensic evidence preservation
  • Identify blind spots in network visibility

Who Should Attend

  • SOC Analysts
  • Network Engineers
  • System Administrators

Prerequisites

  • • Access to SIEM/EDR consoles
  • • Authorized testing window

Value to Business

  • » Metrics-driven assessment of SOC performance
  • » Identifies tool misconfigurations
  • » Improves technical response speed