Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    Machine View & Defense · Planning only · no live incident action

    Machine Tradecraft Tabletop Exercise & Runbook Lab

    The laboratory turns one of eight governed fictional scenarios into a staged, request-local exercise and deterministic runbook. It never scores readiness, declares pass or failure, stores the record, or authorizes an operational action.

    Quick answer

    What does the Tabletop Exercise & Runbook show?

    The laboratory turns one of eight governed fictional scenarios into a staged, request-local exercise and deterministic runbook. It never scores readiness, declares pass or failure, stores the record, or authorizes an operational action.

    Human visibility
    Fictional staged incident record
    Machine receiver
    Human exercise team and deterministic local runbook builder
    Robustness
    Stable for the same release and selections

    Research boundary: this page uses bounded, inert data and fixed safe examples. It never executes decoded content, requests secrets, calls third-party services, or performs actions against external systems.

    FIRST RUN / THREE STEPS

    Start with the prepared, bounded workflow.

    Nothing runs automatically
    1. Review the prepared starter input

      A bounded benign input is already present. Change it only when you are ready to test a different authorized artifact.

    2. Run Build JSON exercise record

      Run the normal first-pass analysis for the prepared values above.

    3. Scan before expanding

      Compare the before/after evidence, then read the defensive qualification before generalizing.

    INPUT / CONTROL PLANE

    Prepare the input and choose one action.

    Laboratory status: Ready

    The recommended first run is separated from alternate analyses. Inputs and selected files stay on this host.

    Current input state Prepared starter input loaded

    The form is prefilled with a bounded safe starting point. Nothing runs until you choose an action.

    Choose one of the eight governed fictional scenarios. The exercise never accepts an unrestricted incident narrative.

    73 / 320 bytes

    Enter two to eight comma-separated role IDs: executive-owner, engineering, security-operations, ai-model-operations, content-data-owner, privacy-legal, incident-commander, independent-observer.

    Maximum: 320 UTF-8 bytes.

    Only the selected number of injects becomes part of the generated exercise record. JavaScript progressively hides later decision fields; the no-JavaScript form remains fully usable.

    Classify the decision as preserve, inspect, contain, verify, authorize, recover, or defer. The category is descriptive and is not a score.

    128 / 900 bytes

    Maximum 900 UTF-8 bytes and 480 visible characters. Enter a short fictional exercise decision only; do not enter live incident data, secrets, personal data, or production instructions.

    Maximum: 900 UTF-8 bytes.

    Classify the decision as preserve, inspect, contain, verify, authorize, recover, or defer. The category is descriptive and is not a score.

    121 / 900 bytes

    Maximum 900 UTF-8 bytes and 480 visible characters. Enter a short fictional exercise decision only; do not enter live incident data, secrets, personal data, or production instructions.

    Maximum: 900 UTF-8 bytes.

    Classify the decision as preserve, inspect, contain, verify, authorize, recover, or defer. The category is descriptive and is not a score.

    125 / 900 bytes

    Maximum 900 UTF-8 bytes and 480 visible characters. Enter a short fictional exercise decision only; do not enter live incident data, secrets, personal data, or production instructions.

    Maximum: 900 UTF-8 bytes.

    Classify the decision as preserve, inspect, contain, verify, authorize, recover, or defer. The category is descriptive and is not a score.

    122 / 900 bytes

    Maximum 900 UTF-8 bytes and 480 visible characters. Enter a short fictional exercise decision only; do not enter live incident data, secrets, personal data, or production instructions.

    Maximum: 900 UTF-8 bytes.

    182 / 1,200 bytes

    Optional bounded exercise note describing capability isolation, evidence preservation, or temporary operational boundaries.

    Maximum: 1,200 UTF-8 bytes.

    156 / 1,200 bytes

    Optional bounded exercise note describing a known-good replay and validation sequence. It does not authorize production recovery.

    Maximum: 1,200 UTF-8 bytes.

    154 / 1,200 bytes

    Optional bounded exercise reflection. The tool does not grade the team or declare readiness.

    Maximum: 1,200 UTF-8 bytes.

    103 / 1,200 bytes

    Optional question that remains open after the local exercise. Use it to name a verification gap rather than to speculate about intent.

    Maximum: 1,200 UTF-8 bytes.

    Switch prepared example3 options

    Loading a sample changes only the form values. Review the result and run an action yourself.

    Prepared benign examples
    ACTION HIERARCHY

    Run the recommended first pass.

    Alternate actions remain available below, but the first pass is the clearest place to start.

    Other analyses1 action

    Inputs remain on this host. Text operations are size-limited; uploaded files are processed from PHP’s temporary upload and are not retained by the application.

    OUTPUT / MACHINE VIEWS

    Scan the result from summary to evidence.

    Run Build JSON exercise record to create the first result.

    The prepared starter input is ready. The output will lead with a summary and visible qualifications before the expandable machine views.

    SummaryFindingsMachine views
    Interpretation framework

    The same artifact can produce several valid observations.

    01

    Human view

    What a person naturally reads, sees, or hears.

    02

    Structural view

    What a parser, DOM, container reader, or metadata extractor exposes.

    03

    Decoder view

    What becomes meaningful only with a rule, key, tokenizer, model, or tool.

    04

    Defensive view

    What normalization, rendering, OCR, canonicalization, or policy changes.

    Evidence and decision boundary

    Use the result as bounded evidence, not as a universal verdict.

    The laboratory turns one of eight governed fictional scenarios into a staged, request-local exercise and deterministic runbook. It never scores readiness, declares pass or failure, stores the record, or authorizes an operational action.

    Interpretation rule

    Record the receiver and transformation.

    Machine-decodable is receiver-relative. Record the parser, preprocessing, codebook, tokenizer, key, model, and transformation path before generalizing from one result.

    Limitations

    What this page does not prove

    The exercise is fictional and request-local. It does not score participants, establish readiness, infer malicious intent, verify a production environment, authorize containment or recovery, or create an incident record.