Prepare Your Team for
Real-World Crises

DrillsForge is the enterprise platform for running realistic tabletop exercises. Simulate cyber incidents, physical security breaches, workplace violence scenarios, and crisis situations — all in a collaborative, real-time environment.

Start Now! See How It Works
acme-cyber.drillsforge.com — Dashboard
DrillsForge Dashboard — exercise overview, metrics, and quick actions

Click any screenshot to enlarge

Why "DrillsForge"?

Drills + Forge

Drills — as in tabletop exercise drills: the structured, repeatable practice sessions that prepare security teams for real-world incidents. Forge — as in a foundry or workshop: the place where raw skill is heated, hammered, and hardened into expertise. Together, DrillsForge is where teams come to sharpen their crisis response through deliberate, realistic practice.

Everything You Need for Effective Exercises

From scenario design to after-action review — DrillsForge has it covered.

Pre-Built Scenarios

25+ ready-to-run scenarios spanning cyber incidents, physical security breaches, workplace violence, executive protection, and crisis management. Or create your own.

Real-Time Simulation

Live inject delivery with timed events, branch points, and dynamic difficulty. Participants receive scenario events in real time via server-sent events (SSE).

AI-Powered Reactive Injects

A built-in LLM analyses every participant response and generates realistic follow-up events in real time — escalating situations when decisions fall short, and introducing new challenges when the team responds well. The AI also auto-generates full scenario inject sets with scoring rules, so facilitators can build exercises in seconds instead of hours.

Automated Scoring

Built-in scoring engine evaluates response timeliness, decision quality, and task completion. Facilitators can override scores with justification.

After-Action Review

Comprehensive post-exercise reports with timeline visualization, scoring breakdown, participant performance, and AI-generated recommendations.

Enterprise SSO

Optional seamless login experience with Azure AD (Entra ID) or Google Workspace. Auto-provision users from your corporate directory with role-based access control.

Role-Based Assignments

Assign participants to scenario-specific roles (Incident Commander, SOC Analyst, Legal Counsel) with role-targeted inject delivery.

Multi-Department Support

Each department gets its own isolated workspace with independent users, scenarios, and exercises. Perfect for large enterprises.

Full Audit Trail

Every action logged with timestamps, IP addresses, and user attribution. Complete accountability for compliance requirements.

See the Platform in Action

Walk through the full exercise lifecycle — from scenario selection to after-action review.

Step 1

Browse the Scenario Library

Choose from 25+ professionally designed scenarios covering cyber incidents, physical security breaches, workplace violence, executive protection, and crisis management. Each scenario is fully configured with timed injects, role assignments, and scoring criteria.

  • Filter by category, difficulty, and duration
  • Preview inject timelines before launching
  • Create unlimited custom scenarios
Scenario Library
DrillsForge scenario library with cyber, physical, and crisis categories
Step 2

Review Scenario Details

Drill into any scenario to see its full structure — injects with timing and severity, role definitions, difficulty settings, and expected duration. Facilitators see everything upfront so they can tailor the exercise to their team's needs.

  • Detailed inject timeline with severity levels
  • Role-based inject targeting
  • Configurable difficulty and duration
Scenario Detail
DrillsForge scenario detail showing injects, roles, and difficulty settings
Step 3

Launch an Exercise Session

Create a new exercise session in seconds. Choose your scenario, assign participants to their roles, adjust difficulty settings, and you're ready to go. The setup is intentionally streamlined — a facilitator can go from zero to running in under a minute.

  • One-click session creation from any scenario
  • Assign real team members to scenario roles
  • Adjust difficulty and timing per session
Create Session
DrillsForge session creation with role assignments and settings
Step 4

Run the Live Exercise

Once the session starts, injects fire in real time via server-sent events (SSE). Participants see scenario events appear on their screens — critical alerts, emails, phone calls, and intelligence reports — delivered at precisely timed intervals to build pressure and test decision-making.

  • Real-time inject delivery with SSE
  • Facilitator controls to pause, skip, or inject ad-hoc events
  • Live scoring as participants respond
Live Exercise — In Progress
DrillsForge live exercise with active injects and participant responses
AI-Powered

AI Reacts to Your Decisions

This is what sets DrillsForge apart. The built-in LLM engine reads every participant response and generates realistic follow-up events in real time. Made the wrong call? Expect escalating alerts — media inquiries, regulatory notifications, or cascading system failures. Responded well? The AI introduces new complications that push your team's skills further. No two exercises ever play out the same way.

The AI also accelerates scenario creation: facilitators can generate a full set of timed injects with scoring rules in seconds, then fine-tune as needed. It even writes the executive summary and improvement recommendations in the After-Action Report.

  • LLM-powered dynamic scenario branching based on player decisions
  • Automatic escalation and de-escalation reacting to response quality
  • One-click AI scenario inject generation with scoring rules
  • AI-generated after-action narratives and recommendations
  • Creates uniquely unpredictable exercises every time
AI Reactive Inject
DrillsForge AI engine generating reactive injects based on participant decisions
Step 5

After-Action Review

When the exercise concludes, DrillsForge generates a comprehensive after-action report. Review the full timeline, scoring breakdown per inject, participant performance, and AI-generated recommendations for improvement. Print it, share it, or use it for compliance documentation.

  • Complete inject timeline with response details
  • Scoring breakdown and performance metrics
  • Printable PDF-ready reports for leadership
After-Action Report
DrillsForge after-action report with scores, timeline, and recommendations
Results

Track Progress Over Time

Your dashboard reflects completed exercises with scores, session history, and team readiness metrics. Use this data to identify gaps, schedule follow-up exercises, and demonstrate your security program's maturity to leadership and auditors.

  • Historical exercise results at a glance
  • Team readiness trends and scoring history
  • Evidence for compliance and audit requirements
Dashboard — Post Session
DrillsForge dashboard showing completed exercise results and metrics

Real-World Scenarios, Ready to Run

Our scenario library covers the threats that keep security leaders up at night.

CYBER 90 min
Ransomware Attack

Ransomware spreading across the corporate network. 15+ hosts encrypted, ransom demanded. Coordinate SOC response, executive comms, and recovery.

7 injects · 5 roles · High difficulty
PHYSICAL 60 min
Data Center Breach

Unauthorized individual in restricted server room. Rogue device detected. Coordinate guards, law enforcement, and IT security response.

5 injects · 5 roles · Medium difficulty
CRISIS 90 min
Active Assailant

Active shooter on the executive floor. SWAT coordination, employee accountability, media management, and post-incident recovery.

7 injects · 6 roles · High difficulty
PHYSICAL 75 min
Workplace Violence

Estranged domestic partner arrives at campus making threats. Armed subject in stairwell. Police coordination, lockdown, and de-escalation.

7 injects · 6 roles · High difficulty
CRISIS 75 min
Bomb Threat

Credible bomb threat with suspicious package found. Building evacuation, bomb squad coordination, and evidence preservation.

6 injects · 6 roles · High difficulty
CRISIS 90 min
Drone Attack on Facility

Incendiary drones targeting manufacturing and R&D buildings. Fire response, FBI coordination, chemical hazard assessment.

6 injects · 6 roles · High difficulty

Plus: CEO Residence Duress Alarm, CFO Blackmail, Zero-Click Exploit, Executive Threats, and more. Create unlimited custom scenarios.

Up and Running in Minutes

From signup to your first exercise in under 30 minutes.

1
Sign Up

Verify your corporate email, choose your workspace URL, and complete payment. Takes 2 minutes.

2
Configure Users & SSO

You may configure users manually or optionally connect Azure AD or Google Workspace for seamless team login. Auto-provision users from your directory.

3
Pick a Scenario

Choose from our library of pre-built scenarios or create a custom exercise for your team.

4
Run the Exercise

Invite participants, assign roles, and start the simulation. Real-time scoring and AI-driven injects.

Simple, Transparent Pricing

One plan. Up to 25 users. Up to 15 per session. No surprises.

SMART VALUE

Annual Plan

$799
per workspace / year
  • Up to 25 workspace users
  • Up to 15 participants per session
  • All pre-built scenarios
  • Custom scenario builder (unlimited)
  • AI-powered reactive injects
  • Automated scoring & AAR
  • Azure AD & Google SSO support
  • Full audit trail
  • All data encrypted at rest and in transit
  • Compliance Alignment: NIST, CISA, ISO 27001, DHS
  • 30-day money-back guarantee
  • Email support
Get Started Now

30-day money back guarantee. Cancel anytime.

Built for Enterprise Scale

Large organizations often have multiple departments that need independent exercise programs. DrillsForge supports this natively.

Separate Workspaces per Department

IT/Cyber, Corporate Security, Legal, HR — each gets their own isolated workspace with independent users, scenarios, and billing.

Custom Subdomains

acme-cyber.drillsforge.com, acme-legal.drillsforge.com — clean, professional URLs for each department.

Independent SSO support

Each workspace configures its own secure Azure AD or Google SSO, allowing different security policies per department.

Example: Acme Corporation
acme-cyber.drillsforge.com
IT Security & Cyber Response Team
acme-security.drillsforge.com
Corporate Physical Security
acme-legal.drillsforge.com
Legal & Compliance

Frequently Asked Questions

A tabletop exercise (TTX) is a discussion-based exercise where key personnel walk through a simulated scenario to test their response plans, decision-making, and coordination. Unlike live drills, TTX exercises are low-cost, low-risk, and can simulate scenarios that would be impossible or dangerous to recreate physically.

DrillsForge is designed for enterprise teams. We require a corporate email (e.g., jim.smith@acme.com) to verify you represent a legitimate organization. This ensures the security and integrity of the platform for all customers. Free email providers like Gmail and Yahoo are not accepted.

Absolutely! Each department signs up for its own independent workspace with a unique subdomain (e.g., acme-cyber.drillsforge.com, acme-legal.drillsforge.com). Each workspace has its own users, scenarios, billing, and SSO configuration — providing complete isolation between departments.

After signing up, you can optionally configure Azure AD (Entra ID) or Google Workspace SSO in the admin panel. Once configured, your team members can log in using their corporate credentials — no separate passwords needed. New users can be auto-provisioned on first login with a default role you choose. Your workspace's SSO configuration is completely independent, so different departments can use different identity providers if needed. No SSO? No problem, just use our standard local user accounts. Your users are notified via email when you have enrolled them.

We offer a 30-day money-back guarantee. If you're not satisfied with DrillsForge within the first 30 days of your annual subscription, contact us for a full refund — no questions asked. After that your subscription will automatically renew annually.

Up to 25 workspace users, up to 15 per session. Your subscription includes up to 25 user accounts in your workspace — enough for your core team plus external contractors or vendors. Each exercise session supports up to 15 active participants, which is more than enough for realistic cross-functional tabletop exercises with SOC analysts, executives, legal counsel, and communications staff.

Yes. Each workspace is completely isolated — no data is shared between organizations. All data is encrypted in transit (TLS) and at rest. We maintain a full audit trail of all user actions. Role-based access control (RBAC) ensures users only see what they need to see.

Latest from Our Blog

Insights on tabletop exercises, incident response, and crisis preparedness.

Ready to Forge Your Team's Readiness?

Start running professional tabletop exercises in minutes.

Get Started — $799/year

30-day money-back guarantee · No commitment