Scenarios
Tabletop exercises drawn from real incidents.
Pre-built AutoTableTop scenarios — each includes a settings file and a sample incident-response plan a facilitator can use to run an exercise based on the real-world event. New scenarios release regularly; AutoTableTop also generates unlimited custom scenarios for any environment you describe.
Featured
Scenarios with full breakdowns
Each scenario maps to a real cybersecurity incident, with all the supporting material a facilitator needs to run an AutoTableTop exercise from end to end.

AutoTableTop
Water/Wastewater Utility
AutoTableTop™ served as the platform for a ransomware crisis management competition (at a water & wastewater industry conference in April 2026) in which 16 participating teams (composed of working water and wastewater plant operators, maintenance technicians, laboratory staff, and collection systems professionals) responded to a simulated ransomware attack on a water treatment facility's SCADA / HMI.

AutoTableTop
FortiBleed Credential Compromise
In June 2026, independent researchers disclosed FortiBleed, a large-scale credential-harvesting campaign that exposed verified administrator and VPN credentials for more than 86,644 internet-facing Fortinet FortiGate devices across 194 countries. Unlike a conventional zero-day,

AutoTableTop Scenario
The Stryker "Wiper" incident
The Stryker Corporation cyberattack of March 11, 2026 represents a structural shift in the cyber threat landscape. This was not a ransomware attack for financial gain — it was a state-aligned destructive wiper operation conducted by Handala, an Iran-linked hacktivist group assessed by multiple intelligence firms as a front for Void Manticore, a destructive operations unit within Iran's Ministry of Intelligence and Security (MOIS). The stated motivation was retaliation for U.S. military strikes in Iran.

AutoTableTop Scenario
Rockwell Advisory PN1633 Tabletop Scenario for AutoTableTop™
A critical vulnerability (CVE-2023-3595 and CVE-2023-3596 in Advisory ID PNI1633) has been discovered in Rockwell Automation’s FactoryTalk Linx product, which is widely used for industrial automation. The flaw allows for remote code execution and denial-of-service attacks, potentially giving attackers administrator-level access and control over industrial systems.

AutoTableTop Scenario
SolarWinds 2019 Scenario
Sometime around January 2019, hackers from a group known as SolarStorm gained access to SolarWinds' network using either a zero-day vulnerability in a third-party service or application, a brute-force attack or social engineering.

AutoTableTop Scenario
Municipal Water Authority of Aliquippa (MWAA) 2023 Scenario
The Municipal Water Authority of Aliquippa (MWAA), a public utility that provides water service to residents and business in Aliquippa, PA experienced a cyberattack on November 25, 2023. This scenario recreates that attack.

AutoTableTop Scenario
Colonial Pipeline 2021 Scenario
Colonial Pipeline ransomware attack from May 2021, one of the biggest incidents in history with its impact on the U.S. Everything to help new facilitators learn how to use AutoTableTop.
Or generate your own.
AutoTableTop builds scenarios on demand.
Describe your environment and threat model. AutoTableTop generates a complete tabletop exercise tailored to your team.
