Synthetic incident rehearsal

Run a ransomware or identity-abuse tabletop in under 90 minutes.

TTSim is your shared scenario room: role-based alerts, paced injects, and after-action reports — all synthetic, hosted at ttsim.infosechcc.com.

  • Role-scoped views
  • Solo or team runs
  • GM pacing controls

How a run works

Three steps from workspace to debrief

  1. Set up your organization

    Create a workspace — new orgs get a trial subscription automatically.

  2. Choose team or solo mode

    Assign seats for a live tabletop, or rehearse every role yourself in solo mode.

  3. Run the scenario & debrief

    Advance the clock, release injects, and export your after-action report.

Scenario library

Available storylines

Pick a pack when you create an exercise in the workspace.

enterprise-identity-abuse

Identity-Led Ransomware Escalation Drill

Synthetic exercise focused on compromised credentials, VPN access, lateral authentication, and pre-ransomware operational disruption in a medium-maturity enterprise.

enterprise-phishing-ransomware

Enterprise Phishing to Ransomware Exercise

Synthetic SOC exercise covering phishing delivery, host compromise, east-west authentication, IDS detections, and safe ransomware impact simulation.