SSCP Lab

Incident Evidence Tabletop

Practice FIRST/NEXT decisions without touching production systems.

Goal

Practice FIRST/NEXT decisions without touching production systems.

Estimated cost: Free when performed with local diagrams, exports, or test data. If you use a real cloud, lab, or SaaS environment, verify cost and authorization first.

Concepts Reinforced

  • incident response lifecycle
  • forensics
  • chain of custody

Prerequisites

  • A non-production lab, diagram, or exported sample data.
  • Authorization to review the data or configuration.
  • A text editor or spreadsheet for notes.

Exact Steps

  1. Pick a ransomware or compromised-admin scenario.
  2. List volatile and durable evidence sources.
  3. Write the first five responder actions.
  4. Identify which actions could destroy evidence.
  5. Create a one-page post-incident lesson list.

Verification

The action sequence preserves evidence before destructive remediation.

Cleanup

Archive the tabletop notes with training records or delete local drafts.