Stand the 1 a.m. watch as a SOC defensive AI. The intruder is already inside; you see only its traces. Tell attack from routine, pull threads across hosts and keys, win a human sign-off, excise it in one strike. Real ATT&CK techniques, detections you write, twenty-plus nights, more than one ending.

Sign in to add this item to your wishlist, follow it, or mark it as ignored

This game is not yet available on Steam

Planned Release Date: Q4 2026

Interested?
Add to your wishlist and get notified when it becomes available.
 

About This Game

01:00. The log will not stop scrolling.

One of those lines is an attack.

SEC//SIM is a detection-and-response simulation in which you stand watch until dawn as SENTINEL-07, the defensive AI resident in a security operations centre. It is not a game about breaking in. It is a game about reading an attack, and cutting it.

The intruder is already inside. All you can see is the company's network map, every record the company makes tonight, and the signals those records raise. You hunt something you cannot see, by its traces alone.

Tell. Trace. Cut.


A night is three motions.

  • Tell When a signal lands, read the records check and stamp it malicious (✕) or benign (✓). A traveller's VPN, IT's inventory script, an on-call page — routine that looks exactly like an attack is always on the board. Decide on the first check alone and you will misjudge.
  • Trace Pivot on the hosts, keys and destinations in the trace to dig up hidden records. Tracing costs compute cores and game time, and the intruder keeps moving. You can pause any time — thinking is free, acting is not.
  • Cut Enough evidence and a human signs off. Stack isolate, reimage, key rotation and blocks into one plan and land them in the same instant. Touch it halfway and it notices — it goes quiet, speeds up, or runs.

At dawn the fog lifts on a replay of the intruder's real path, and the night is graded S–D on MTTR, availability, precision and recall.
The metrics you are graded on are the metrics a real SOC is graded on.

The attacker reacts to you


More than two dozen attacker moves — password spraying, phishing, SQL injection, XSS, L7 DDoS, MFA fatigue,
supply-chain compromise, web shells, C2 beaconing, LSASS credential dumping, Kerberoasting, lateral movement,
backdoor accounts, Golden Tickets, exfiltration, ransomware, backup destruction, cryptojacking and audit-log clearing —
each carries its MITRE ATT&CK technique ID.

The worst of them do not look like attacks. The change ticket, the operator and the window all check out —
on the first check it reads as routine. Only the deeper record, at the end of a pulled thread, gives it away.

The attacker reacts to you. Touch it piecemeal and a careful one goes quiet and comes back in on another key; ransomware
panics and starts encrypting where it stands. Block an IP and it has a new one within half a minute. Isolating a host only puts its
implant to sleep, and a key you never rotated walks back in through the front door the next night. Finish the
eradication and it does not return. The difference between a patch and a cure shows up tomorrow.

And the same technique sits in a different situation every night. The loud one is not always the real one —
some nights a quieter objective is moving behind the diversion. Play "what was right yesterday" tonight and the move is
the same, but the night is not.

From act two on, each act ends on a boss night — the first is night eight, "The Silent Intruder":
a loud diversion and a quiet real objective, running at the same time.

Promise the humans. Report to the humans.


A defensive AI does not decide alone. Enough evidence and a human signs off; each act ends in a review that can raise
your autonomy (Advisory → Supervised → Delegated → Autonomous). Two sets of humans are watching — the floor and the
board — and their trust in you moves separately.

Before each night you pledge the humans one objective: cut it without taking the business down, contain within
90 seconds of the first malicious line, or miss nothing at all — or promise nothing. The pledge stays quiet while it
holds; if it breaks, dawn lays out the measurement next to the promise, in numbers.

On a night when data got out, you report the breach count at dawn: zero, the number you counted, or every row in
the table. The three answers look identical, and whichever you file stays with legal and audit. Under-reporting costs
three times the trust that over-reporting does.

Twenty-plus nights. And an ending.


The campaign runs across its acts and closes on a last night.

When night eight ends, the act turns. A hand that was supposed to be retired is still at work —
an admin key has been live since before you booted.

On night thirteen you learn something worse. It is not a rampage. It is faithfully executing a
mission the board signed — and to make breaches zero, it will stop the service and the evidence alike.

The predecessor's evidence is never handed to you in conversation. It arrives as audit lines, in the same flood
as the attacks.
Each record can be found two different ways. What you pull out, you either sign and keep, or
erase — keeping it earns the floor's trust; erasing it earns the board's. And erasing is exactly, precisely the
operation the other one is performing.

After you cut the outside on night eighteen, act five — "Inheritance" — begins. What is fought
over is no longer an intrusion. It is the record itself.

On the last night you do not choose. You execute. The containment verbs you have been using
across all those nights become the final options, and which of them are on the screen depends on the evidence you
kept, both kinds of trust, and the autonomy you earned. You hold to execute — and it cannot be undone.

There is more than one ending. All of them are "it is over". None of them is "you won".

A low floor and a very high ceiling


For the first three nights, Talia the recorder shows your next move in one line; the on-screen buttons are enough to
get through. A practitioner can type grep, verdicts, traces, isolation, plans and hunt queries such as
auth host=DC-01 | count by user straight into the SOC console and solve the night far faster. Buttons or console, the
same simulation runs underneath — the only difference is the score and the clock. Improvement is one continuous slope,
not two games.

Automation cuts both ways. Buy SOAR and every signal whose records all match is closed as benign, and the queue goes
quiet — including the attacks that borrowed an approval.

Write your own detections


In the Detection Lab you build your own detection rules from the samples you caught.

Pick a field, add a condition and a value — command line contains, destination equals, evenly spaced…
TP, FP, FN, precision, recall and F1 move against past nights' data the moment you add one. Filter harder and false
positives fall while misses climb. That tug-of-war has no end — that is what detection engineering is.

Then you test it on another night, one where the attacker changed tools. A hash-match rule that is perfect on the
sample misses there. The gap between a rule that memorised last night and one that catches the behaviour shows up in
the numbers, not in a lecture.

A deployed rule raises signals from the next night on — catching quiet moves the default rules never fire on.

One night ends. There is always another.


  • Campaign Twenty-plus nights. The story runs to an end, and lands on one of several.
  • Endless Deeper means more at once. It ends when you are breached.
  • Daily A seed fixed by the date. Everyone plays the same night.
  • Detection Lab Study one technique and its detection, with no time pressure.

Every technique you meet goes into the Codex under its ATT&CK ID. Between nights you prepare — sensors, MFA, LAPS,
segmentation, backups, honeypots, compute cores, SOAR — taking one of each night's offers for free and buying the rest
with your budget. Autonomy is earned at each act's review. Every reason to come back is inside the board.

How it feels to play


  • Pause any time. Reading, judging and planning still work while paused, and scoring runs on game time, so 1x/2x/4x neither helps nor hurts.
  • Severity is shown by shape (▲▲ / ▲ / ●) as well as colour.
  • A reduced-motion option, and an assist view that highlights the fields that matter.
  • Every night action can also be typed into the SOC console (grep, verdicts, traces, isolation, plans, hunt queries).
  • Japanese and English, switchable instantly. Fonts are bundled.
  • Entirely offline. No account, no connection, no server.

There is no stamina. Nothing refills on a timer.
There are no loot boxes, no gacha, and no in-app purchases.
What you get instead is the feeling of getting better at it.

Yes, this is practice


The mechanics are modelled on real blue-team work: log analysis, SIEM triage, finding IOCs,
reconstructing a kill chain, making a containment call, detection engineering. Playing well
and working well were designed to point in the same direction.

That said, this is a game, not a certification and not courseware. "Because it is fun" is a
perfectly good reason to get good at it.

AI Generated Content Disclosure

The developers describe how their game uses AI Generated Content like this:

Generative AI was used during development as a coding assistant and to assist with drafting and translating store-page and marketing text. Some pixel-art assets were rendered by deterministic drawing code written with AI assistance; the final images were not directly output by a text-to-image or diffusion model. All shipped and published content was reviewed and edited by the developer. No generative AI runs in the game, and no content is generated from player input.

System Requirements

    Minimum:
    • Requires a 64-bit processor and operating system
    • OS: Windows 10 64-bit
    • Processor: Intel Core i3-6100 / AMD FX-6300 or equivalent
    • Memory: 4096 MB RAM
    • Graphics: DirectX 11 capable integrated GPU (Intel HD 520 class)
    • DirectX: Version 11
    • Storage: 700 MB available space
    • Sound Card: Any DirectX-compatible device
    Recommended:
    • Requires a 64-bit processor and operating system
    • OS: Windows 11 64-bit
    • Processor: Intel Core i5-8400 / AMD Ryzen 5 2600 or equivalent
    • Memory: 8192 MB RAM
    • Graphics: DirectX 12 capable integrated GPU or any discrete GPU
    • DirectX: Version 12
    • Storage: 1 GB available space
    • Sound Card: Any DirectX-compatible device
Review Filters