Strong security controls reduce the number of serious incidents a team has to deal with, but they also reduce the opportunities to practice responding to one from start to finish.
When a major incident does happen, teams may be relying on processes and playbooks they’ve rarely had the chance to use together under realistic conditions.
That’s why we built Live Breach.
Live Breach gives security teams a realistic, hands-on environment to work through a live cyber attack together, from the first signs of compromise through investigation, containment, and eradication.
Why Live Breach?

We figured it’s time to go beyond talking through an incident. Tabletop exercises are useful for walking through decisions, responsibilities, and processes. But that’s only half of the process.
Live Breach adds the technical layer, giving you the other half.
Teams work directly with the evidence generated during an attack. Investigating what happened, establishing the scope of the compromise, containing the threat, and carrying the response through remediation.
The aim is to give incident response teams meaningful practice across the full lifecycle of an incident.
This is important because response speed has a direct impact on how far an attack can progress.
The average eCrime breakout time is now 29 minutes, while 57% of compromises recorded in 2024 were first identified by an external party rather than the affected organisation.
Teams need opportunities to build familiarity with the decisions and actions that follow an alert, before those decisions carry real consequences.
Built around how incident response teams work
Live Breach is designed for teams working through the same incident together. During an exercise, your team follow the investigation as it develops. They can share their findings, make containment decisions, and work through the technical steps needed to bring the incident under control.

Exercises run in-browser and on TryHackMe infrastructure, so teams can work through realistic attack activity without putting their own production systems at risk. Teams can choose from supported SIEM and EDR tooling for each exercise, ensuring the experience matches how they work day to day.
We’ve designed each exercise to be time-boxed and repeatable, making it easier for organisations to build realistic incident response practice into an ongoing readiness programme.
From investigation to containment and remediation

A major focus of Live Breach is the depth of the response. Teams work beyond the initial alert and follow the attack through the full investigation flow.
That includes:
- understanding what happened and establishing the scope of the compromise
- following attacker activity across the environment
- making containment decisions
- carrying out eradication and remediation actions
- reviewing how the team performed once the exercise is complete
This gives security leaders a clearer picture of how their incident response capability works as a whole, including the technical response and the way different team members and functions work together during the incident.
Relevant threats, realistic attack chains
Live Breach exercises are built around threat scenarios that every security team should be familiar with, including established threat actors and emerging attack techniques.
The scenario library includes threat actor-aligned exercises such as Cozy Bear, Volt typhoon, and Lazarus, alongside attack chains focused on newer areas of risk.
One example explores the security implications of AI coding agents.
We’ve seen that AI agents are becoming increasingly connected to developer workflows, repositories, credentials, and internal systems. Recent incidents have shown how malicious or untrusted content can manipulate those agents and turn legitimate access into part of a wider attack chain.
In the Live Breach scenario, teams work through activity involving credential access, persistence, data exfiltration, and lateral movement, using the available telemetry to understand the attack and carry the response through to remediation.
The goal is to give defenders practical experience with attack behaviours they may not yet have encountered in a real incident.
Turn exercise performance into something actionable
Live Breach also gives security leaders a better understanding of what happens after the exercise.
The post-exercise report captures team performance and highlights areas that need further attention, giving managers a concrete basis for improving incident response capability over time.
That can help teams answer practical questions such as:
- Where did the investigation slow down?
- Were important parts of the compromise missed?
- How effectively did the team move from investigation into containment?
- Where does the response process need more practice?
The output can also provide useful evidence of operational readiness for conversations with leadership, auditors, clients, insurers, and other stakeholders.
Making incident response practice more continuous
Incident response readiness is difficult to judge from documentation alone.
Teams need opportunities to work realistic incidents together, see where their processes hold up, identify where capability gaps remain, and use those lessons to improve the next response.
Live Breach brings that experience into TryHackMe as a repeatable, hands-on part of cyber team development.
It extends the way teams already use TryHackMe to build technical capability by giving them a higher-fidelity environment to apply those skills across a complete incident.
Live Breach is now available for organisations looking to build and validate incident response capability through realistic, team-based exercises.
Ayomide Joseph A.