Import from XML on your PDI — no SDK, no CLI. Installs the whole platform, with all four operations as records.Select an operation
A competitive, self-paced CTF. Investigate realistic SIR incidents on your PDI and capture flags across the full attack lifecycle — phishing, malware, lateral movement, exfiltration, correlation, and triage.
Select this operationA competitive CTF built from real-world threats. Triage a queue of five unrelated SIR incidents — a DPRK fake IT worker, ransomware living-off-the-land, a poisoned software supply chain, AI deepfake CFO fraud, and a home-network botnet — grounded in open-source threat intelligence.
Select this operationThe expert cut. A breach discovered mid-stream — detection fired late, nothing is pre-verdicted, the tools disagree. Every flag is a salience inversion: the answer is the option your instincts steer you away from, overturned only by a bright-line record fact.
Select this operationA guided, narrative incident-response loop. Press START and a SIR incident appears — auto-enriched, with a playbook. Solve the matching challenge, resolve the incident, and the next scenario reveals itself. Five in a row.
Select this operation↑ Select an operation to get its update set and deploy steps.
Operation Quiet Harbor
SIR Capture the Flag · ServiceNow Range (x_snc_range)
What you'll deploy
A scoped app that seeds a full SIR incident queue on-platform, with action-gated reveals. Flags are graded by the hosted range service against the values seeded into your own instance, and rotate between cohorts.
1 · Register on the scoreboard
Create your player account (Register, top-right) — the email you register with is your handle. Your PDI's flags are tied to it, so do this before you download.
2 · Get the update set
Opens the start page, which also shows the two values to type in step 3.
3 · Install & run
- Activate plugins (if not already): Security Incident Response, Threat Intelligence.
- Import: All → Retrieved Update Sets → Import Update Set from XML → upload the file → Upload.
- Preview & commit: open the loaded set → Preview Update Set → resolve any problems → Commit Update Set.
- Open ServiceNow Range → Operations → Operation Quiet Harbor, set Handle to your scoreboard email and Enrollment token to the class key, then click Run.
4 · Play
Work the incident queue on your PDI and submit what you uncover for points on the live leaderboard.
Scoreboard → /scoreboard · Challenges → /challenges?op=quiet-harbor
Guides
Player guide — set up and play New to SecOps? SIR field guide
Operation Deep Current
SIR Capture the Flag · Real-World Threats · ServiceNow Range (x_snc_range)
What you'll deploy
A scoped app that seeds your own queue of five real-world SIR incidents on-platform — a DPRK fake IT worker, ransomware living-off-the-land, a poisoned software supply chain, AI deepfake CFO fraud, and a home-network botnet. Flags are graded by the hosted range service against the values seeded into your own instance, and rotate between cohorts.
1 · Register on the scoreboard
Create your player account (Register, top-right) — the email you register with is your handle. Your PDI's flags are tied to it, so do this before you download.
2 · Get the update set
Opens the start page, which also shows the two values to type in step 3.
3 · Install & run
- Activate plugins (if not already): Security Incident Response, Threat Intelligence.
- Import: All → Retrieved Update Sets → Import Update Set from XML → upload the file → Upload.
- Preview & commit: open the loaded set → Preview Update Set → resolve any problems → Commit Update Set.
- Open ServiceNow Range → Operations → Operation Deep Current, set Handle to your scoreboard email and Enrollment token to the class key, then click Run.
4 · Play
Work the queue of five real-world incidents on your PDI and submit what you uncover for points on the live leaderboard.
Scoreboard → /scoreboard · Challenges → /challenges?op=deep-current
Guides
Player guide — set up and play New to SecOps? SIR field guide
Operation Undertow
SIR Capture the Flag · Expert / Salience Inversion · ServiceNow Range (x_snc_range)
What you'll deploy
A scoped app that seeds your own mid-stream-breach SIR queue on-platform — detection fired late, nothing is pre-verdicted, and the tools disagree. Every flag is a salience inversion: the answer is the option a seasoned analyst's pattern-matching steers them away from, overturned only by a bright-line fact in the record. Flags are graded by the hosted range service against the values seeded into your own instance, and rotate between cohorts.
1 · Register on the scoreboard
Create your player account (Register, top-right) — the email you register with is your handle. Your PDI's flags are tied to it, so do this before you download.
2 · Get the update set
Opens the start page, which also shows the two values to type in step 3.
3 · Install & run
- Activate plugins (if not already): Security Incident Response, Threat Intelligence.
- Import: All → Retrieved Update Sets → Import Update Set from XML → upload the file → Upload.
- Preview & commit: open the loaded set → Preview Update Set → resolve any problems → Commit Update Set.
- Open ServiceNow Range → Operations → Operation Undertow, set Handle to your scoreboard email and Enrollment token to the class key, then click Run.
4 · Play
Work the mid-stream breach queue on your PDI and submit what you uncover for points on the live leaderboard.
Scoreboard → /scoreboard · Challenges → /challenges?op=undertow
Guides
Player guide — set up and play New to SecOps? SIR field guide
Operation Watchtower
SIR Implementation Workshop · ServiceNow Range (x_snc_range)
What you'll deploy
A scoped app that runs the five-scenario workshop entirely on your PDI: it generates auto-enriched SIR incidents (threat intel, observables, timeline, affected CIs, response tasks) and drives Flow Designer playbooks. One button starts it; one button resolves each scenario and advances to the next. The matching challenges are already on the hosted board — no CTFd setup required.
1 · Download the update set
2 · Install on your PDI
- Activate plugins (if not already): Security Incident Response, Threat Intelligence.
- Import: All → Retrieved Update Sets → Import Update Set from XML → upload the file → Upload.
- Preview & commit: open the loaded set → Preview Update Set → resolve any problems → Commit Update Set.
- Run it: ServiceNow Range → Operations → Operation Watchtower → Run. This creates scenario 1 of 5 — Watchtower unlocks one scenario at a time, so a single incident is expected. Click Resolve Scenario on it to complete it and reveal the next. (Difficulty is optional; everything else is pre-set.)
3 · Play
You play the five scenarios right in your PDI — open Operation Watchtower and press Run (step 2 above). They arrive one at a time: resolving each incident creates the next and reveals its challenge. Follow your progress and the matching challenges on the board.
Challenge board → /challenges?op=watchtower