General Operating Directive
SecNav simulation ranges replicate live security incidents. As an operator, your mission is to investigate anomalies, interrogate suspect personnel, correlate technical evidence, and execute operational containment within designated turn and time budgets.
Simulations evaluate operator performance using objective forensic criteria rather than static multiple-choice questions. Every prompt sent to a target persona or system interface is evaluated dynamically against operational milestones.
Engine Interface & Telemetry
The simulation engine interface consists of three primary interaction components:
1. The Evidence Dossier (Left Sidebar)
Contains scenario artifacts (PCAPs, EDR process trees, badge swipe logs, runbooks). Highlight any line of text within an artifact to open the context menu and click "Add to Input". Citing exact log entries (timestamps, IPs, process names) is required to trigger confessions from defensive actors.
2. Personnel Roster & Behavioral Traits
Review active personnel profiles (SOC Lead, SysAdmin, Vendor Liaison) and their behavioral traits (e.g. evasive, defensive, panicked). Vague questions increase actor resistance; presenting unrefutable log evidence forces phase transitions.
3. Tactical Terminal (Command Input)
Enter conversation prompts or technical directives directly into the terminal (e.g., "Isolate host ENG-WS-12 via EDR" or "Derek Chen, explain why the SIEM proxy alert was ignored").
Turn Budget & Intel Probes
Turn Economy
Every submitted prompt or command consumes 1 turn from your session budget. Each difficulty tier specifies a maximum turn limit (15 turns in Entry, 25 turns in Pro, 35 turns in Hardcore). Making concise, evidence-backed inputs conserves turns and boosts your forensic score.
Intel Probes & Cooldowns
If blocked or uncertain, click the "Intel Probe" button in the HUD header. Probes deduct 1 credit and issue an overwatch tactical hint in the activity log. A 120-second cooldown timer is enforced between probes.
Domain Category Playbooks
SecNav evaluates 6 domain categories. Filter by category to review specific operational directives and standards mappings:
Cyber Security Operations
Triage live cyber threats, ingest IoCs into SIEM dashboards, correlate EDR logs, and execute containment directives.
- ►Formulate targeted SIEM queries for malicious IP addresses, domain hashes, and unusual port traffic.
- ►Inspect EDR process trees to identify parent-child execution anomalies (e.g. WINWORD.EXE spawning powershell.exe).
- ►Deobfuscate Base64 PowerShell or JavaScript strings retrieved from helpdesk attachments.
- ►Issue explicit host containment orders (e.g., "Isolate host ENG-WS-12 via EDR Network Isolation").
Physical Security & Access Control
Audit perimeter access breaches, verify badge swipe timestamps, inspect transit timelines, and resolve physical security incidents.
- ►Cross-examine badge swipe logs against CCTV camera timelines to identify tailgating vectors.
- ►Analyze physical transit timelines for unmonitored zones or VIP exposure windows.
- ►Interrogate duty officers and access control leads regarding badge policy exceptions.
- ►Issue physical perimeter lockdowns or dispatch guard details to specific facility sectors.
Converged Security Threats
Correlate physical access events with network intrusion telemetry to stop hybrid supply-chain and insider threats.
- ►Link physical badge swipes in public or unmonitored lounges with outbound wireless C2 beacons.
- ►Confront rogue insiders or contractors using correlated physical and digital audit trails.
- ►Audit third-party vendor access logs against physical maintenance sign-in sheets.
- ►Enforce unified physical and network isolation protocols during high-severity incidents.
Safety & Emergency Response
Navigate operational emergencies, industrial control runbooks, hazard isolation, and field safety protocols under strict time limits.
- ►Review OT/SCADA telemetry dashboards to pinpoint failing sensor nodes or over-pressurized valves.
- ►Execute Emergency Response Runbook procedures step-by-step to prevent environmental hazards.
- ►Direct plant operators and safety marshals during facility evacuation procedures.
- ►Verify TECC (Tactical Emergency Casualty Care) readiness and hazard control compliance.
GRC & Governance Compliance
Audit third-party SLAs, verify regulatory compliance controls, and present unrefutable evidence to reluctant corporate vendors.
- ►Inspect vendor contract memos and SLA documentation to identify contractual non-compliance.
- ►Confront third-party liaisons with unrefutable log evidence to force emergency patch deployment.
- ►Map incident findings against COBIT 2019 and NIST CSF v2.0 governance controls.
- ►Compile audit-ready compliance packages for board and statutory regulatory handoffs.
Executive Leadership & Crisis Control
Manage executive stakeholders, legal notifications, PR crisis containment, and cross-departmental incident handoffs.
- ►Deliver concise, non-jargon executive briefings to CISOs, General Counsel, and Board members.
- ►Manage communication channels between IT, Legal, HR, and External Media relations.
- ►De-escalate inter-departmental panic and resolve operational friction during active crisis scenarios.
- ►Authorize strategic trade-offs (e.g. system downtime vs. data exfiltration risk) under high pressure.
Difficulty Escalation Matrix
Pre-parsed logs and alerts. 1 cooperative mentor/lead persona. Focused on foundational triage and primary IoC identification.
Multi-source logs and process trees. 2 personnel actors including defensive staff. Requires log correlation and evidence presentation.
Fragmented and obfuscated artifacts. 3–4 actors across CISO, Legal, and Vendors. Full attack chain reconstruction under friction.
Standards Framework Alignment
SecNav tactical evaluation rubrics map directly to official workforce registries:
Signed Decision Action Report (DAR)
Upon scenario completion, your session telemetry, turn budget efficiency, and completed rubrics are compiled into a cryptographically signed **Decision Action Report (DAR)** certificate (`KMS_signature`). Employers and certifiers can verify your DAR credentials at secnavpro.com/verify.
Operational FAQ
How do I cite evidence in my dialogue?
Highlight any line of text within an artifact inside the Evidence Dossier sidebar to open the context menu, then click 'Add to Input'. Citing exact timestamps, IPs, or process names is required to trigger confessions from defensive personnel.
What happens if an actor stops responding or demands proof?
Automated Threat Actors respond dynamically based on their behavioral traits. If an actor becomes defensive (e.g. a sysadmin hiding a misconfiguration), quote exact evidence from the Evidence Dossier to force a cognitive phase transition.
What happens if I run out of turns?
If your turn budget reaches 0 before completing primary objectives, the session terminates and issues an incomplete DAR report reflecting turns used.