Incident Arcade / Security Training / August 17, 2026

Incident Arcade: From Security Quiz to Analyst Simulation

Incident Arcade started as a simple security challenge. Seventy-seven scenarios later, it has evolved into something much closer to a lightweight SOC simulation.

Incident Arcade · Security Training · AWS Security · SOC · SIGNAL//NOISE

Incident Arcade started with a simple idea: present a security event, give the analyst enough context to investigate it, and ask them to decide whether they were looking at signal or noise.

That worked. But it also exposed the limitation of the original format.

Real incident response is not a multiple-choice exam. Analysts rarely receive every relevant fact at once. They work through incomplete information, competing explanations, noisy alerts, questionable severity ratings, and response decisions where doing too much can be just as damaging as doing too little.

So Incident Arcade evolved.

Today the Arcade contains 77 security scenarios spanning identity, credentials, IAM, network exposure, S3 and data access, logging, detection, compute, AWS API activity, persistence, containment, and false-positive analysis.

More importantly, the gameplay has changed.

Analysts now make separate decisions about classification, severity, confidence, and response. Evidence can be requested selectively rather than automatically exposed. Some incidents unfold across multiple stages. Boss cases deliberately mix useful signals with irrelevant activity. Rapid-response cases test triage under time pressure, while more advanced investigations reward patience and evidence discipline.

The scoring philosophy changed too.

A good analyst is not someone who calls everything malicious, labels everything Critical, opens every artifact, and escalates every alert.

Sometimes the best decision is:

Monitor / No Action.

That is intentional.

SIGNAL//NOISE is built around the idea that security work is as much about restraint and judgment as detection.

We also added progression — XP, analyst ranks, streaks, mastery, badges, records, daily incidents, difficulty tiers, and challenge modes — but the rule has been to keep those systems subordinate to the investigation itself.

The Arcade should feel like a security application with game mechanics, not a game wearing a cybersecurity costume.

That distinction became even more important as the scenario library grew. More capabilities created more interface density, which forced us to rethink desktop layout, mobile usability, navigation, and how much secondary information should remain visible while somebody is working a case.

The result is considerably different from the application we started with.

And the next step is even more interesting.

Instead of making the Arcade look increasingly like a SOC workstation, we are exploring the opposite approach:

bring the scenarios into an actual analyst-workstation experience.

That is where SATIE comes in.

← Back to aMusings