The challenge behind the engagement.
Technical tabletops test whether your responders, your monitoring provider, and your playbooks work together under one scenario. We write a technical scenario and a timeline of events around your environment, with realistic evidence: an endpoint alert, sign-in records, an access-policy change, an unexpected app authorization, and an extortion note. Responders walk each phase of a response, from detection through recovery: which alert fired, who saw it, and how the scope is set from the activity and audit trails available. They decide what to capture before containment, what isolation and credential resets would break, and the order to rotate secrets and restore. Nothing is executed, no credentials change hands, and any console view stays read-only. You receive an after-action report, playbook redlines, and a detection and logging gap list.
For security and IT teams that own the first hours of a response, and for organizations relying on a monitoring provider whose hand-offs have never been rehearsed. Typical triggers: a new detection or logging platform, a cloud migration, a change of managed provider, or a plan that has been written but never walked.
What we do.
What you can use.
Map your systems to the scenario
We collect the plan and playbooks, the asset and identity inventory for the scenario systems, architecture diagrams, log sources with retention periods, and monitoring runbooks and contacts. Objectives are written to your tooling, for example responders identify the initial access path from sign-in and endpoint activity records.
Walk each phase against the evidence
Responders work the event timeline phase by phase: triage and escalation, then scoping the intrusion through activity and audit trails and hunting for persistence. Next come memory and disk capture before containment, isolation and credential resets and what they break, and eradication and rotation order. Restore priorities and re-entry monitoring follow the recovery plan. Optional read-only screen sharing shows where they would look.
Report gaps and redline the playbooks
The after-action report names technical findings: alerts nobody receives, missing log sources, undocumented system owners, untested restores, and playbook steps that reference retired tools. Corrective actions are written into the runbooks themselves. The detection and logging gap list is scoped so Detection & Response Validation can later prove each item live.
Who it’s for.
When you need it.
- Security and IT teams that own the first hours of a technical response
- Organizations relying on an MSP or MDR whose response hand-offs are untested
- Responders working across on-premises, cloud, and SaaS systems with uneven logging
- Teams with playbooks on paper that have never been walked against real evidence
- A new endpoint detection or logging platform has just been rolled out
- A cloud migration or architecture change alters where evidence now lives
- A change of managed provider leaves the response hand-offs untested
- Leadership wants proof responders can execute the plan before an incident
What the scope can include.
- 01
Technical scenario with alert text, log excerpts, access-policy changes, app authorizations, and an extortion note
- 02
Detection and triage: which alert fired, who saw it, how it was escalated, and to whom
- 03
Scoping and evidence preservation: tracing activity, finding persistence, reviewing audit logs, capturing memory and disk, chain of custody
- 04
Containment and eradication: host isolation, disabling accounts, revoking credentials and sessions, blocking outbound traffic, pausing the delivery pipeline, rebuild criteria
- 05
Recovery essentials: offline backup integrity, restore order, re-entry monitoring, and hand-off to business owners
- 06
Coordination injects for MDR and MSP hand-offs, counsel and retainer engagement, and executive information requests
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
One IT team or outside IT provider, 2–3 hour session, mostly cloud or office systems
About 28–40 hoursIT, security, and your monitoring provider together, half-day session, cloud plus on-site systems
About 44–60 hoursSeveral response teams or locations, full day or multiple sessions, complex cloud and on-site systems
About 64–90 hours- Number of systems, log sources, and cloud platforms the scenario has to reflect
- Number of teams and outside providers taking part (MSP, MDR, cloud vendors)
- Number of playbooks tested and redlined
- Session length and whether multiple sessions are needed
3–5 weeks from kickoff to session, with the after-action report delivered 1–2 weeks after
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Technical scenario and event timeline, reusable for the next drill
- Evaluator checklists tied to each playbook under test, with hot-wash notes
- After-Action Report and Improvement Plan with technical findings and corrective actions written into the runbooks
- Detection and logging gap list ready for a live Detection & Response Validation exercise
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
How is this different from Detection & Response Validation?
Nothing is executed here. A technical tabletop tests people, procedures, and decision flow through discussion: who sees the alert, who decides to isolate, what gets captured first, who calls the MDR. Detection & Response Validation, in our Red Team Operations core, runs real techniques beside your defenders to prove whether the tooling fires. The tabletop comes first because it produces the list of detections, log sources, and hand-offs that a live exercise should later test, with no production exposure at all.
Do we need our MSP or MDR provider in the room?
We strongly recommend it. The gaps a technical tabletop tends to surface sit at the hand-off between provider and client. Who does the provider call at 2 a.m.? What are they authorized to isolate without asking? Which logs do they hold, for how long, and who exports evidence before a host is re-imaged? If the provider cannot attend, we test the hand-off against their runbook and contract instead and record every point where the answer is unknown.
- NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile
- NIST SP 800-84: Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities
- NIST SP 800-184: Guide for Cybersecurity Event Recovery
- CISA Tabletop Exercise Packages
- #StopRansomware Guide
- Homeland Security Exercise and Evaluation Program (HSEEP)
- Technical Approaches to Uncovering and Remediating Malicious Activity (AA20-245A)
