You are a security team. Someone got in a while ago and is still here. The uncomfortable part is that you already made the decisions that determine how this goes.
Most tabletop exercises start when the alert fires. This one starts a budget cycle earlier — you draft your control posture first, then live with it.
Read the rules Design document GitHubWhen a control reveals a technique in this game, it is not because a designer decided it should. It is because MITRE's Center for Threat-Informed Defense maps that NIST 800-53 control to that ATT&CK technique. The game cannot teach you something the frameworks disagree with.
The corollary is the interesting part. When a check succeeds and reveals nothing, it is because the control you bought does not cover that stage of the attack — and that gap is real too. Teams normally discover it at 3am.
Spend a fixed budget on controls before the incident starts. Broad controls cost more and detect weakly; narrow ones cost little and detect sharply.
A technique's stealth rating comes from how many controls map to it. Nothing is hand-tuned for drama.
You do not run out of time. Impact accumulates while the chain stays hidden. What kills you is being slow, not being wrong.
Optional scoring against NCSC CAF v4.0 objectives, so a UK regulated organisation leaves with a gap list rather than an anecdote.
| Deck | Cards | Source |
|---|---|---|
| Technique cards | pending | MITRE ATT&CK v19.1 |
| Control cards | pending | NIST SP 800-53 Rev 5 |
| Complication cards | 24 | Original |
| Objective cards | 8 | Original |
Plus a 103-card MITRE ATLAS expansion for incidents involving AI systems.
| Source | Licence | Used for |
|---|---|---|
| MITRE ATT&CK v19.1 | MITRE terms of use | Technique cards |
| MITRE ATLAS | Public release | AI expansion |
| NIST SP 800-53 Rev 5 | Public domain | Control cards |
| CTID 800-53 → ATT&CK mappings | Apache 2.0 | The detection mechanic |
| NCSC CAF v4.0 | Open Government Licence v3.0 | Debrief scoring |
Every source permits redistribution. Full notices.