RCCE Course
Course #78

Tabletops Deep Dive

📊 Level: Advanced
⏱️ Duration: 2 Days
🏷️ Track: Incident Response
📋 Prerequisites: Foundations
🖥️ Mode: Online Instructor-Led
📝 Course Description

RCCE students will learn tabletop exercise design, facilitation, and analysis for testing incident response readiness across security teams and business stakeholders. RCCE students will learn to develop realistic scenarios based on current threat intelligence, facilitate tabletop exercises that test communication protocols, decision-making under pressure, and coordination between technical and executive teams. The course covers exercise planning, participant briefing, inject management, observer evaluation criteria, after-action report writing, and translating exercise findings into concrete improvements to incident response plans and organizational resilience. This deep-dive course provides comprehensive technical coverage that goes beyond surface-level understanding. At an expert level, RCCE students will learn to master the nuances, edge cases, and advanced configurations that separate competent practitioners from true experts. Students will engage with complex real-world scenarios and gain the depth of knowledge required to troubleshoot difficult situations, mentor junior team members, and make architectural decisions with confidence.

🎯 Target Audience
  • Security Engineers building defensive controls
  • Security Analysts and Blue Team members
  • Systems Administrators with security responsibilities
  • GRC and Risk Professionals supporting controls
  • Professionals implementing Tabletops Deep Dive
🧠 What You Will Learn
  • Execute hands-on tasks for tabletops deep dive
  • Execute hands-on tasks for advanced cyber defense mastery
  • Explain Executive Overview fundamentals
  • Execute hands-on tasks for why tabletop exercises matter
  • Execute hands-on tasks for of orgs improved ir after ttx — covering IR plans before real incidents.
  • Measure attack surface reduction and program effectiveness
  • Execute hands-on tasks for core definitions & exercise taxonomy
  • Execute hands-on tasks for functional exercise
  • Execute hands-on tasks for full-scale exercise
  • Design a scalable privilege management architecture with policy and enforcement
  • Design a scalable privilege management architecture with policy and enforcement, including Align scenarios to org threat landscape.
  • Execute hands-on tasks for threat intelligence-driven scenarios
📚 Course Outline
Module 01Tabletops Deep Dive
Module 02Advanced Cyber Defense Mastery
Module 03Executive Overview
Module 04Why Tabletop Exercises Matter
Module 05of orgs improved IR after TTX
Module 06Risk Reduction
Module 07Core Definitions & Exercise Taxonomy
Module 08Functional Exercise
Module 09Full-Scale Exercise
Module 10Exercise Design & Scenario Development
Module 11Key Design Principles
Module 12Threat Intelligence-Driven Scenarios
Module 13Intelligence Sources
Module 14Scenario Realism Checklist
🧪 Lab Details

All hands-on labs run on Rocheston Rose X OS. Students practice tabletops deep dive by implementing the controls discussed in class, with a focus on real-world deployment, monitoring, and validation.

  • Lab 1: Execute hands-on tasks for tabletops deep dive
  • Lab 2: Execute hands-on tasks for advanced cyber defense mastery
  • Lab 3: Explain Executive Overview fundamentals
  • Lab 4: Execute hands-on tasks for why tabletop exercises matter
  • Lab 5: Execute hands-on tasks for of orgs improved ir after ttx
📊 Skill Level
Advanced
Beginner Intermediate Advanced Expert
Duration
2 Days
🎓
Certificate
Completion
🖥️
Lab Platform
Rose X OS
👨‍🏫
Mode of Training
Online Instructor-Led
🔥
Platform
Zelfire
🐦‍⬛
Cyber Range
Raven
📓
Study Material
CyberNotes
🏆 Certificate

Upon successful completion of this course, students will receive an official RCCE Course Completion Certificate for Tabletops Deep Dive, verifiable through the Rocheston certification portal.

🔑 Student Access & Materials
  • Full access to all course materials and slide decks
  • Hands-on lab access on Rocheston Rose X OS environment
  • Access to Rocheston CyberNotes
  • Access to Rocheston Zelfire — EDR/XDR SIEM platform
  • Access to Rocheston Raven — online cyber range exercise platform
  • Access to Rocheston Vulnerability Vines AI