Tabletop ransomware exercises are good for those caring about cutlery encryption, we’re interested in how well our security tool stack performs on observed real world intelligence offensive procedures, on standardised operating system environments in our organisation. How can we run thousands of offensive procedures, and back the detection promises made to the CISO with actual data?