Work the full incident, end to end
Trace what happened, understand the scope of the attack, contain it, and work through eradication as the exercise unfolds.

Live breach giveaway
We're giving six security teams a free three-hour Live Breach exercise to find out. Work the incident end to end. Find the threat, scope the attack, contain it and eradicate it, all on TryHackMe infrastructure.
Apply for your teamApplications close 18 October.
What you get
Your team will take the incident from first alert through scoping, containment and remediation — making the calls needed to bring the attack under control.
Trace what happened, understand the scope of the attack, contain it, and work through eradication as the exercise unfolds.

Your own systems aren't touched. Choose from a range of commercial SIEM and EDR tools per exercise.

Your IR team works the investigation as one — making decisions, coordinating the response, and driving the incident to remediation.

Your post-exercise report shows how the team performed, where gaps surfaced and what needs to improve.

Why live breach?
The average eCrime breakout time is 29 minutes. Live Breach puts your team into a realistic incident where they have to investigate what happened, understand the scope and bring the attack under control.
Experience realistic threat behaviour firsthand.
Find response gaps before a real breach exposes them.
Who can apply
Live Breach is built for security teams responsible for investigating and responding to incidents together.
Applications close 18 October. Selected teams are notified the week of 20 October.
Complete the form below to apply for the Live Breach exercise.
Loading application form…
By applying, you agree to the giveaway terms and conditions