Scenario library / Supply chain
Poisoned Software Update: a tabletop exercise scenario
A monitoring agent deployed across your servers shipped a signed update containing a backdoor. The vendor confirms several release versions are affected.
90 min · Executive + technical + vendor management

What this is modelled on
Modelled on compromises of trusted build and update pipelines, where signed software from a legitimate vendor delivers attacker code into every customer that installed the release.
Why it matters
Every control that trusts signed vendor software worked exactly as designed and still let the attacker in. The exercise tests how you reason about compromise you cannot see.
Exercise objectives
- Test asset inventory speed for a specific software version
- Rehearse hunt tasking with limited indicators
- Decide on removal versus isolation of a business-critical agent
- Review software supply chain assurance requirements
Decision points tested
- Remove the agent and lose monitoring, or isolate and keep visibility
- Whether to treat the segment as breached
- External forensic support engagement
- Client and regulator disclosure timing
Sample inject timeline
- T+0
Vendor disclosure
The vendor names affected versions and publishes limited indicators.
- T+20
Inventory answer
Asset data cannot confirm the version installed on a third of the estate.
- T+45
Hunt hit
Beaconing is found from two servers in a segment with access to customer data.
- T+70
Customer question
A regulated client asks whether their data environment was touched.
What the after-action report should capture
- Inventory and version-tracking gaps
- Hunt capability and log coverage
- Vendor assurance requirements to renegotiate
- Segmentation effectiveness
Run this scenario with your team
Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.
