Lab 04 · Investigate, contain, recover, and improve

Software Supply Chain Incident Response Lab

Analyze simulated pipeline and registry evidence, verify artifacts and provenance, select response actions, and produce an after-action report for realistic supply-chain incidents.

Evidence-drivenMultiple scenariosScored response

Incident control center

Select a scenario and investigate the evidence

Open
Evidence collected
0/0
scenario evidence set
Containment
0%
required actions complete
Response score
0
evidence, sequence, decisions
Modeled impact
Moderate
changes with response actions

Incident alert

Initial detection and scope

High

Evidence locker

Collect evidence, examine its meaning, and preserve a defensible chain of reasoning

Recommended: --

Response actions

Execute containment, eradication, recovery, and improvement actions

Sequence affects score

Incident investigation terminal

Query pipeline, runner, registry, SBOM, provenance, and audit evidence

student@supply-chain-ir
student@incident:~$