NewLive IR Mock Drills — No Account Needed

Test Your Team
Before Hackers Do

Phishing simulations. Live IR drills. One platform. Launch a room, share a link, and see how your team handles a breach — before a real one hits.

Built on enterprise-grade foundations

GoPhish Next.js CCMP MITRE ATT&CK MongoDB

Platform Capabilities

Everything you need to harden your team

ZeroPhish Dashboard

Stay compliant. Stay audit-ready.

Regulatory frameworks like ISO 27001, SOC 2, DPDPA, and CERT-In mandate regular phishing simulations and incident response drills. ZeroPhish automates both — so you're always prepared, not scrambling before an audit.

Phishing Campaigns

Automated GoPhish-powered simulations with click tracking and credential capture

Gamification & Scoring

4-tier effectiveness scoring with leaderboards and per-question reveal

Compliance Analytics

Audit-ready reports proving your team runs drills regularly — ISO 27001, SOC 2, DPDPA compliant

4 Steps. 2 Minutes. Zero Friction.

Launch a live IR / C-level executors drill in under 2 minutes

Create Room dialog with timer configuration
01

Create a Room

~10 seconds

Pick a scenario from the library, set the per-question timer, and click Create Room. Takes 10 seconds.

Facilitator dashboard showing magic link, PIN, and waiting participants
02

Share the Magic Link + PIN

No account needed

You get a unique room link and a 6-digit PIN instantly. Drop it in Slack, paste it in Google Meet chat, or email it. Participants join without a ZeroPhish account.

Participant view with two-column layout — artifacts on left, questions on right
03

Participants Answer Live

Real-time

Once you hit Start, participants see the full IR scenario — narrative, terminal-style evidence artifacts (WAF logs, EDR alerts, firewall configs), and MCQ questions with instant per-question reveal.

Live participant leaderboard with scores and progress bars
04

Watch Live Scores

Auto-ranked

Your facilitator dashboard updates every few seconds — see who's answered, their score, percentage, and a ranked leaderboard. The room auto-completes when everyone finishes.

Real-World IR Scenarios

Based on actual cyber incidents

Each scenario walks your team through a full CCMP-aligned incident response — from detection to eradication — with real artifacts from enterprise security stacks.

WordPress RCE → 337K PII Breach
AdvancedIR Team

WordPress RCE → 337K PII Breach

WPScan recon → brute-force → plugin web shell → credential harvesting → 337,000 Aadhaar/PAN records exfiltrated → root across 4 servers.

4 phases · 5 injects · 15 questions · 25 artifacts · ~60 min

Linux Ransomware — LockBit 5.0
AdvancedIR Team

Linux Ransomware — LockBit 5.0

SSH brute-force → systemd persistence → lateral movement across 5 servers → backup destruction (S3 + restic + local) → LockBit 5.0 ELF deployment.

5 phases · 5 injects · 15 questions · 24 artifacts · ~65 min

+11 more scenarios

Customized drills for every team in your organization

SOC OperationsThreat IntelligenceIncident ResponseDigital ForensicsC-Level ExecutivesMalware AnalysisSOC OperationsThreat IntelligenceIncident ResponseDigital ForensicsC-Level ExecutivesMalware Analysis
Cloud SecurityGRC & ComplianceRed TeamNetwork SecurityAppSec & DevSecOpsSecurity AwarenessCloud SecurityGRC & ComplianceRed TeamNetwork SecurityAppSec & DevSecOpsSecurity Awareness

Why choose ZeroPhish?

Start in Minutes

Sign up and launch your first campaign or drill in minutes. No trial periods, no credit cards, no sales calls.

Cost-Effective

Enterprise-grade phishing simulation and IR training at a fraction of the cost. Free tier included forever.

Simple & Guided

Intuitive interface with step-by-step workflows. Create rooms, share links, and start drills without any training.

Phishing + IR Drills

The only platform that combines phishing simulation with live tabletop exercises in a single unified tool.

Multi-Tenant Ready

Built for MSPs and enterprises. Every organization sees only their data with full GoPhish asset isolation.

Real-Time Insights

Track campaigns and drill scores in real time. Automated reports with month-over-month improvement trends.

CCMP Aligned

Scenarios follow the Cyber Crisis Management Plan framework — Detection, Assessment, Containment, Eradication.

Secure & Compliant

Designed for ISO 27001, SOC 2, DPDPA, and CERT-In compliance. Audit-ready reporting built in from day one.

Ready to secure your team?

Get in touch with our team to discuss how ZeroPhish can help your organization run phishing simulations and IR tabletop exercises at scale.

Your first 2 campaigns are completely free — no commitment required.

Up to 500 targetsAll scenarios + custom importUnlimited rooms50 participants per roomPer-question timer controlPDF after-action reportsPriority support