Working title. See Naming for alternatives.
A cooperative tabletop incident response game for security teams, built on MITRE ATT&CK®, MITRE ATLAS™, NIST SP 800-53 and the NCSC Cyber Assessment Framework.
Status: v2, decks built and verified. Awaiting human playtesting. Players: 3–7 (one Scenario Lead, two to six Responders). Duration: 45–75 minutes. Audience: security teams, architects, GRC practitioners, and mixed technical/business groups running tabletop exercises.
The reference game in sources/ establishes the genre: hidden attack chain,
facilitator, d20 procedure rolls, turn limit. Those are game mechanics and are
not protectable, but cloning them would produce a worse game and an
uncomfortable IP position. BLAST RADIUS diverges on four structural points:
| Dimension | Common tabletop IR format | BLAST RADIUS |
|---|---|---|
| Player capability | Fixed procedure list dealt at random | Drafted control posture bought with a budget |
| Detection outcome | Facilitator checks a hand-written "detection" list | Resolved against the published CTID 800-53→ATT&CK mapping |
| Attack chain | Fixed length, fixed phases | Variable length, 5 stages drawn from live ATT&CK tactics |
| Failure mode | Run out of turns | Dwell time drives an escalating impact track |
The posture draft is the core original contribution. It turns the game from "guess the attack" into "defend the choices you made last budget cycle."
| Deck | Source | Purpose |
|---|---|---|
| Technique cards | ATT&CK v19.1 top-level techniques with at least one CTID mapping | The adversary's chain |
| Control cards | NIST SP 800-53 Rev 5 controls carrying a CTID ATT&CK mapping | The defender's posture |
| Complication cards | 24, original | Business friction, injected mid-incident |
| Objective cards | 8, original | What the adversary is actually after |
| CAF debrief sheet | NCSC CAF v4.0, 4 objectives and 14 principles | Post-game scoring |
| ATLAS expansion | 103 cards, MITRE ATLAS | AI/ML incident variant |
Deck sizes are whatever the mappings produce and are printed by the build, not fixed by hand. The current build yields 167 technique cards and 108 control cards.
Plus: one d20, an impact track (0–10), and a dwell counter.
┌─────────────────────────────────────────┐
│ T1566 INITIAL ACCESS │ ← ATT&CK ID + tactic
│ Phishing │ ← ATT&CK name
│ │
│ STEALTH 16 STAGE Entry │ ← derived stats
│ │
│ [MITRE ATT&CK description, verbatim] │ ← used under MITRE licence
│ │
│ Countered by 7 controls │ ← from the CTID mapping
└─────────────────────────────────────────┘
Stealth is the detection difficulty class. It is derived, not authored: the fewer 800-53 controls that map to a technique, the harder it is to see.
| 800-53 controls mapping to the technique | Stealth DC | Label | Cards |
|---|---|---|---|
| 1–6 | 18 | Silent | 35 |
| 7–9 | 16 | Quiet | 34 |
| 10–12 | 14 | Detectable | 28 |
| 13–16 | 12 | Noisy | 28 |
| 17+ | 10 | Loud | 42 |
Bands are recomputed on each build as equal-population quintiles, so these boundaries move with the source data rather than being fixed by hand.
┌─────────────────────────────────────────┐
│ SI-4 COST 5 │ ← 800-53 identifier
│ System Monitoring │ ← 800-53 control name
│ Family: System and Information Integrity│
│ │
│ ROLE Detect SIGNAL +4 │ ← derived stats
│ COVERAGE Foundational (364 techniques) │
│ │
│ Monitor the system to detect attacks │ ← written to fit the card
│ and indicators of potential attacks. │
│ │
│ NIST SP 800-53 Rev 5 · public domain │
└─────────────────────────────────────────┘
Because 800-53 is public domain, card text is written to fit the layout rather
than the layout bending around a fixed wording — which keeps the deck at
poker size. The control identifier is printed so a player can look up the full
statement, and the unabridged text is retained in the card data as full_text.
Cost and Signal are inversely related, by design. Foundational controls apply to hundreds of techniques but give a weak bonus; narrow controls apply rarely but land hard when they do. This is the central draft tension and it mirrors reality: continuous monitoring sees everything faintly, while a purpose-built control sees one thing clearly.
| Coverage tier | Techniques mapped | Cost | Signal | Cards |
|---|---|---|---|---|
| Deep | 1–5 | 1 | +6 | 28 |
| Focused | 6–8 | 2 | +5 | 17 |
| Broad | 9–20 | 3 | +4 | 22 |
| Pervasive | 22–64 | 4 | +3 | 20 |
| Foundational | 72–364 | 5 | +2 | 21 |
Tier boundaries are computed from the live distribution on every build, as equal-population quintiles of the observed coverage counts, rather than being hard-coded. A framework version bump therefore cannot silently skew the economy — if ATT&CK adds two hundred techniques, the bands move with it.
Role comes from the control's 800-53 family, grouped by NIST CSF 2.0 function:
| Role | CSF function | 800-53 families | In-game ability |
|---|---|---|---|
| Detect | Detect | AU, SI | +2 Signal on top of tier value, capped at +7 |
| Prevent | Protect | AC, AT, CM, IA, MA, MP, PE, PS | On a revealed technique this control maps to, reduce its impact contribution by 1 |
| Direct | Identify, Govern | CA, PL, PM, PT, RA, SA, SR | Once per game, reroll a failed check |
| Recover | Respond, Recover | CP, IR | Once per game, remove 2 from the impact track |
800-53's twenty families map onto all five CSF functions naturally, which makes this derivation both simple and defensible. Prevent still dominates the deck at 72 of 108 cards — realistic, and it makes the 12 Detect and 5 Recover cards genuinely contested picks in the draft.
| Stage | ATT&CK tactics included | Pool |
|---|---|---|
| Entry | Reconnaissance, Resource Development, Initial Access | 14 |
| Foothold | Execution, Persistence | 42 |
| Elevation | Privilege Escalation, Defense Impairment, Stealth | 33 |
| Expansion | Credential Access, Discovery, Lateral Movement | 33 |
| Objective | Collection, Command and Control, Exfiltration, Impact | 45 |
Entry is deliberately the smallest pool. Reconnaissance and resource development happen outside your estate, so almost none of it maps to a control you own — there really are fewer ways in than ways to move around once inside.
Facilitator note: the draft is where most of the learning happens. Let the argument run. Six minutes of "do we buy monitoring or do we buy MFA" is worth more than the rest of the game.
Each round, the Responders take one action as a team, then the clock advances.
INVESTIGATE. Nominate one control card you hold and one stage you are probing. Roll d20 + that control's Signal against the Stealth DC of the hidden technique at that stage — +5 to the DC if the control is not in that technique's 800-53 mapping.
The +5 rather than an automatic miss is deliberate. An earlier draft made unmapped controls fail outright, which made the game unwinnable: a 14-point posture buys around eight controls, each mapping to roughly 8% of techniques, so the chance of covering all five chain stages was about 3%. Simulation caught it (see §5.3). The soft penalty keeps the mapping meaningful while leaving a route through.
CONTAIN. Nominate a revealed technique and a control. Roll d20 + Signal against Stealth DC + 2, and +5 more if the control is unmapped. On success the technique is contained and stops contributing to impact. Contained techniques cannot be re-activated.
CONVENE. Once per game only. Skip the round's action; in exchange, reduce the impact track by 2 and refresh all cooldowns. Represents standing up a formal incident bridge and getting the right people in the room.
After every action, the dwell counter increases by 1. On rounds 4, 7, 10 and 13 the adversary advances, adding to the impact track:
A Prevent control listed on a revealed technique reduces the advance by 1, minimum 1.
An earlier draft had each technique contribute its stage number, which meant the first advance alone dealt 15 against a ceiling of 10 — a guaranteed loss before the team had done anything wrong. The flat count keeps dwell time as the pressure without making round 4 an execution.
data/build/verify.py Monte Carlos 3,000 games with a deliberately naive
agent: random greedy draft, always probes the earliest unrevealed stage, no
strategy at all. Current parameters give a 32% naive win rate with a median
of 11 rounds.
That is the target band. A naive agent should lose more often than it wins, so that deliberate drafting and sensible stage targeting — the actual skills the game is teaching — are worth something. Skilled play should land around 55–65%.
Budget sensitivity is the informative part. Measured across 3,000 games each:
| Budget | Naive win rate |
|---|---|
| 10 | 27.6% |
| 14 | 33.3% |
| 18 | 34.6% |
| 22 | 37.1% |
| 26 | 39.8% |
Nearly doubling the budget buys twelve percentage points. The binding constraint is control coverage, not money — which is both a good game property and an uncomfortably accurate one. Spending more on controls that overlap what you already have does very little; the teams that win are the ones whose posture spans the kill chain. That is the argument the game exists to provoke, and it falls out of the mapping data rather than being asserted.
Responders win if every technique in the chain is revealed and the Objective-stage technique is contained before the impact track reaches its ceiling.
Responders lose if the impact track reaches the ceiling first. The Lead then reveals the full chain and the objective, and narrates the outcome.
Impact ceiling is set by the Objective card, typically 10 for a standard game, 8 for a hard game, 12 for a teaching game.
There is no turn limit. The impact track is the pressure, which means a team that is making progress is never arbitrarily cut off, and a team that is flailing loses in a way that is legible to them.
The debrief is part of the game, not an optional extra. Fifteen minutes:
The expansion replaces the Entry and Foothold stages with ATLAS stages and adds an AI System asset with its own impact track.
| Stage | ATLAS tactics | Notes |
|---|---|---|
| AI Entry | ML Model Access, Initial Access | Model theft, API abuse |
| AI Foothold | ML Attack Staging, Execution | Poisoning, backdoors |
ATLAS techniques carry no 800-53 mapping, so their Stealth DC is authored rather than derived, and their counters come from ATLAS mitigations. This is flagged on the card so players know the provenance differs.
| Source | Licence | Adaptation |
|---|---|---|
| MITRE ATT&CK v19.1 | MITRE terms of use, royalty-free | Permitted, with MITRE's copyright designation |
| MITRE ATLAS | Public release, distribution unlimited | Permitted |
| NIST SP 800-53 Rev 5 | Public domain, 17 U.S.C. §105 | Unrestricted |
| CTID 800-53 → ATT&CK mappings | Apache License 2.0 | Permitted, retain notice |
| NCSC CAF v4.0 | Open Government Licence v3.0 | Permitted, attribute Crown copyright |
| Game rules, cards, layout, code | Original | CC BY-SA 4.0 |
Every source permits redistribution. Two constraints remain, both trivial: retain the notices, and keep MITRE marks out of the product name.
When reusing framework content, measure what you are actually shipping rather than the field that flatters you. A card set can look like a modest extract on one measure — a small fraction of the control descriptions, say — while carrying almost the whole of a mapping table that the publisher considers its core work product.
The rule this project follows: audit every field in the shipped output,
including derived and relational data, and check each against the licence
covering it. data/build/verify.py enforces the notice requirements on every
build so the position cannot drift silently.
This is a considered reading of the licences, not legal advice.
BLAST RADIUS is the working title. Alternatives that avoid all third-party
marks: