TollBooth / OpenDoor

Live-fire investigation workshop

Investigate a real breach. Then find it before it happens.

Two scenarios, one shared incident — Acme Rentals. An AI agent, armed with the open-source Anthropic Cybersecurity Skills library, does the actual investigation while you drive and check its work.

QR code linking to this wiki casky-ai.github.io
/casky-workshops

Which path do I run?

Both scenarios can be driven two different ways. Pick whichever matches today's room setup — your facilitator will tell you which, but here's the difference:

Section 1 — Kali + Claude CodeSection 2 — Casky Box
Skill selection10 hand-picked skills, symlinked per laptopAuto-classified from all 817 skills, per investigation
Agent runtimeClaude Code installed per laptopOne shared casky-runner container
Verificationverify.sh — 9 raw tshark/jq checks on the data[VERIFIED] transcript per step — did the agent actually run the assigned skill's script
OutputCheat-sheet answer pagesStructured plan → findings → CISO-style consolidated report
Reset between attendees./reset.sh (<10s)Each investigation run is already fresh

Full setup for both is on the Setup page — do that first, before opening either scenario page.

The printed cheat sheet

Everyone should have (or can grab) the original color-coded cheat sheet — teal instruction pages, orange checkpoints, red answer pages. This wiki mirrors it exactly, with the answers collapsed so you can attempt each phase before checking.

Download the PDF


Authorized & lawful use only. All data in both scenarios is synthetic and self-contained — no live systems are touched. Built on the open-source Anthropic Cybersecurity Skills library (Apache-2.0); not affiliated with Anthropic PBC. Source data trimmed from BHUSA-Anthropic-CyberSecurity-Skills.