ThreatGEN
AutoTableTop

Scenarios

Tabletop exercises drawn from real incidents.

Pre-built AutoTableTop scenarios — each includes a settings file and a sample incident-response plan a facilitator can use to run an exercise based on the real-world event. New scenarios release regularly; AutoTableTop also generates unlimited custom scenarios for any environment you describe.

Featured

Scenarios with full breakdowns

Each scenario maps to a real cybersecurity incident, with all the supporting material a facilitator needs to run an AutoTableTop exercise from end to end.

Water/Wastewater Utility

AutoTableTop

Water/Wastewater Utility

AutoTableTop™ served as the platform for a ransomware crisis management competition (at a water & wastewater industry conference in April 2026) in which 16 participating teams (composed of working water and wastewater plant operators, maintenance technicians, laboratory staff, and collection systems professionals) responded to a simulated ransomware attack on a water treatment facility's SCADA / HMI.

FortiBleed Credential Compromise

AutoTableTop

FortiBleed Credential Compromise

In June 2026, independent researchers disclosed FortiBleed, a large-scale credential-harvesting campaign that exposed verified administrator and VPN credentials for more than 86,644 internet-facing Fortinet FortiGate devices across 194 countries. Unlike a conventional zero-day,

The Stryker "Wiper" incident

AutoTableTop Scenario

The Stryker "Wiper" incident

The Stryker Corporation cyberattack of March 11, 2026 represents a structural shift in the cyber threat landscape. This was not a ransomware attack for financial gain — it was a state-aligned destructive wiper operation conducted by Handala, an Iran-linked hacktivist group assessed by multiple intelligence firms as a front for Void Manticore, a destructive operations unit within Iran's Ministry of Intelligence and Security (MOIS). The stated motivation was retaliation for U.S. military strikes in Iran.

Rockwell Advisory PN1633 Tabletop Scenario for AutoTableTop™

AutoTableTop Scenario

Rockwell Advisory PN1633 Tabletop Scenario for AutoTableTop™

A critical vulnerability (CVE-2023-3595 and CVE-2023-3596 in Advisory ID PNI1633) has been discovered in Rockwell Automation’s FactoryTalk Linx product, which is widely used for industrial automation. The flaw allows for remote code execution and denial-of-service attacks, potentially giving attackers administrator-level access and control over industrial systems.

SolarWinds 2019 Scenario

AutoTableTop Scenario

SolarWinds 2019 Scenario

Sometime around January 2019, hackers from a group known as SolarStorm gained access to SolarWinds' network using either a zero-day vulnerability in a third-party service or application, a brute-force attack or social engineering.

Municipal Water Authority of Aliquippa (MWAA) 2023 Scenario

AutoTableTop Scenario

Municipal Water Authority of Aliquippa (MWAA) 2023 Scenario

The Municipal Water Authority of Aliquippa (MWAA), a public utility that provides water service to residents and business in Aliquippa, PA experienced a cyberattack on November 25, 2023. This scenario recreates that attack.

Colonial Pipeline 2021 Scenario

AutoTableTop Scenario

Colonial Pipeline 2021 Scenario

Colonial Pipeline ransomware attack from May 2021, one of the biggest incidents in history with its impact on the U.S. Everything to help new facilitators learn how to use AutoTableTop.

Or generate your own.

AutoTableTop builds scenarios on demand.

Describe your environment and threat model. AutoTableTop generates a complete tabletop exercise tailored to your team.