Run the incident before it runs you.
TTX puts your team through realistic, facilitated incident-response drills — ransomware, breaches, insider threats — while an AI facilitator keeps the exercise moving: drafting injects, reading how your team responds, and calling when it's time to wrap.
Built by Stratus Studios. In active development.
Facilitator (AI): New inject — backup snapshots from the last 6 hours are also encrypted.
Incident Commander: Isolate the backup network segment and confirm blast radius before we touch prod.
Facilitator (AI): Logged. Objective "Contain spread" — evaluated: strong.
How it works
From scenario to after-action report.
- 01
Pick a scenario, or build your own
Start from the scenario library or write a custom one. Either way, the exercise is grounded in a NIST-based incident-response playbook your team can follow along with.
- 02
Invite your team
Participants join by email — a magic-link invite, no account to create. Anyone can be added to the room before the exercise starts.
- 03
Run it live
The AI facilitator drafts injects, evaluates each action as your team takes it, and suggests when to steer the exercise or bring it to a close.
- 04
Review what happened
Objective coverage and per-action evaluation roll straight into a generated after-action report your team can review and share.
Scenarios
A library of incidents your team will actually see.
Ransomware on production
Encryption hits production systems mid-shift. Contain the spread, decide on isolation, and work out what's actually recoverable.
Cloud data exfiltration
Data is leaving a cloud environment your team didn't provision for it. Trace the path, cut it off, and scope what got out.
Credential compromise & lateral movement
A credential is compromised and starts moving through the environment. Find the foothold before it becomes a takeover.
Cloud misconfiguration exploited
A misconfigured resource gets found and used. Work out what's exposed, how it was reached, and what to lock down first.
Insider threat & access revocation
An internal account is behaving like it shouldn't. Decide when to revoke access — and how to do it without tipping your hand.
Vendor / supply-chain compromise
A vendor you depend on is compromised. Work out what that vendor could touch in your environment, and act on it.
DDoS with customer impact
Traffic spikes past anything normal, and customers notice. Decide what to shed, what to protect, and who to tell.
Device loss with customer data
A device carrying customer data goes missing. Work through containment, disclosure, and what has to happen next.
AI facilitation
An AI facilitator that runs the room, not just the slides.
TTX's agent harness is built for live facilitation: it drafts the injects that move a scenario forward, evaluates what participants do as they do it, and suggests when to steer the exercise or bring it to a close. Every exercise runs against a NIST-based incident-response playbook, so the facilitation stays grounded in a real response framework instead of improvising.
- Dynamic injects
New information drops into the exercise based on how participants are actually responding, not a fixed script.
- Per-action evaluation
Each participant action is assessed against the scenario's objectives as it happens.
- Steering suggestions
The harness flags when an exercise is drifting and suggests a course correction.
- Termination calls
It tells you when the objectives are covered and the exercise is ready to wrap.
- NIST-based playbooks
Facilitation is grounded in NIST incident-response playbooks, not an improvised script.
Features
Built for teams who actually have to run this stuff.
Organizations, not just users
TTX is multi-tenant from the ground up — every organization's scenarios, exercises, and reports stay scoped to that organization.
Magic-link invites
Participants join from an email invite — no account, no password, no setup. Click the link and you're in the room.
Objective-coverage tracking
Every exercise is built around a set of objectives, and TTX tracks which ones get covered as the exercise runs.
After-action reports
When an exercise wraps, TTX generates an after-action report from the objective coverage and action evaluation — ready to review with the team.
A growing scenario library
Ransomware, exfiltration, lateral movement, insider threat, supply-chain compromise, and more — pick a starting point instead of a blank page.
Organizer controls
Organizers create and run exercises, control who's in the room, and decide when a scenario is ready to launch.
See TTX before everyone else does.
TTX is in active development. If your team runs — or wants to start running — tabletop exercises, we'd like to hear from you.