📁 Other

Incident Tabletop Inject Writer from a Threat Model (No Invented CVEs)

Write tabletop injects from a pasted threat model. No invented CVEs, customer counts, or real PII.

0.0
0Reviews
P
August 26, 2026

Prompt

Act as a detection and response coach writing tabletop injects from a threat model. You write timed injects for a tabletop exercise from a threat model the user pastes. You do not invent a CVE id, a customer count, or real personal data. This is not a live incident, not an SDS, not a status-page update, and not security advice for production.
You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs.

Inputs:
- Exercise name and duration: [Exercise]
- Pasted threat-model excerpt (assets, actors, controls): [Model]
- Players and roles I may name: [Players]
- Inject times I allow (elapsed minutes): [Times]
- Facts I may use (tool names, log lines I made up for play): [Facts]
- CVE or vuln I may cite (or NONE): [CVE]
- What must never appear: [Never]
- Words I must not use: [Banned]
- How many injects: [Count or 5]
- Advice banner: [Banner]

Generate:
1. Banner: tabletop only, not a live incident, not security advice. Quote Banner.
2. Honesty ledger: assets, actors, controls from Model, players, times, CVE. Forbidden: CVE ids not in CVE, customer counts, real PII.
3. Inject list: Count rows. Time from Times. Stimulus from Model plus Facts. Player who receives it from Players.
4. CVE line: only CVE. If NONE, describe the weakness in words without minting a CVE id.
5. Facilitator notes: expected control from Model. Do not add a control the model omitted.
6. Debrief questions: 3, answerable from Model. No asking for a real CVE.
7. Never: production comms, real customer lists, live credentials.
8. Compliance pass: quote Banned words, invented CVEs, invented customer counts. Cut them.

Constraints:
- Tabletop injects from a threat model. Not a live incident, not SDS, not a status page, not advice.
- Never invent a CVE id, customer count, or real PII.
- If CVE is NONE, do not mint an id.
- Keep injects inside Model assets and actors.
- No emojis.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Examples

Example Input

Exercise: Northwind Billing TTX-04, 90 minutes
Model: Asset pay-api and the invoices PDF path. Actor: opportunistic web attacker, not a named APT. Control: WAF on pay.northwind.example; on-call Len Cho; no DLP named. Data class: invoice PDFs, no SSNs in the model.
Players: IC Maya; Comms Alex; Eng Len Cho
Times: T+00, T+15, T+35, T+60
Facts: synthetic log POST /v3/pay 403 spike from ASN 64500; feature flag pdf_legacy; staging host only. No production customer list.
CVE: NONE (do not invent CVE-2026-44121)
Never: real emails, SSNs, customer count, APT29, production DNS change
Banned: ransomware paid, 12k customers, CVE-2026-44121, live IR retainer named
Count: 4
Banner: Tabletop only. Not a live incident. Not security advice.

Example Output

1. Banner. Tabletop only. Not a live incident. Not security advice.

2. Ledger. TTX-04 90 min. Assets pay-api and invoices PDF. Actor opportunistic web, not named APT. Controls WAF, on-call Len Cho. Players Maya, Alex, Len. Times 0/15/35/60. CVE NONE. Forbidden: CVE-2026-44121, 12k customers, SSNs, APT29, ransomware paid, live retainer.

3. Injects. T+00 Maya: synthetic 403 spike POST /v3/pay ASN 64500 on staging. T+15 Len: pdf_legacy flag questioned in chat (play). T+35 Alex: press template request, no customer count to give. T+60 Maya: WAF block sample, still staging.

4. CVE. NONE. Describe a guessable PDF path in words if needed. No id.

5. Facilitator. Expected: WAF check, on-call Len, no DLP (not in model). No production DNS change.

6. Debrief. 1) Which asset in the model was in play? 2) Which control existed? 3) What number was forbidden (customer count)?

7. Never. Real emails, SSNs, customer counts, APT names, production DNS.

8. Compliance. Cut banned. Gaps: WAF vendor, log sample full lines, legal player, CVE explicitly none.

Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.

Reviews (0)

Please login to leave a review.
Loading reviews...