

A Real Game, Right in your browser
The demo runs the live Cyber Realm ruleset against an arena-style board. The same play mat, cards, and resource system from the tabletop game, rebuilt to play solo or to learn the flow before you open a physical deck.
01
02
03
04
Allocate resources each turn and spend them to deploy attacks, tools, and defenses.
Chain cards across the kill chain to push an attack through to its objective.
Cyber Lesson callouts explain the real tactic behind every card as you play it.
Runs on any modern browser — desktop or tablet. Nothing to install.
Every Attack Follows the cyber kill chain
Cyber Realm is built on the real Cyber Kill Chain. Each card belongs to a phase, and winning means moving an attack cleanly from one link to the next while your opponent tries to break the chain. The demo walks you through it step by step.
Recon
Scout the target. Reveal hidden assets, configs, and weak points.
e.g. Port Scanner
.png)
Weaponize
Build the payload. Hide malware in a trusted file or tool
e.g. Password Cracker
.png)
Delivery
Get it across the wire. Phishing, fake logins, the human seam.
e.g. Unsecured Access

Exploit
Fire the exploit. Execute code on the target asset.
e.g. Cred Attack

Install
Plant persistence so the foothold survives the turn.
e.g. RAT

Command & Control
Open a channel home. Relay orders past the firewall.
e.g. C2 Communication

Actions on Objectives
Act on the goal. Exfiltrate, disrupt, or hold the asset.
e.g. System Outage

Blue Team Runs the NIST Framework
Where the attacker works the cyber kill chain, the defender works the NIST Cybersecurity Framework. Five functions that turn scattered controls into a strategy. Your Detect, Protect, and Respond cards each live in one of these, and a strong defense covers all five.
.png)
Identify
Know what you're defending. Wells, pumps, SCADA, and the connections between them
e.g. Asset Discovery
.png)
Protect
Know what you're defending. Wells, pumps, SCADA, and the connections between them
e.g. Firewall Rule

Detect
Know what you're defending. Wells, pumps, SCADA, and the connections between them
e.g. Network Monitor

Respond
Know what you're defending. Wells, pumps, SCADA, and the connections between them
e.g. PCAP Analysis

Recover
Know what you're defending. Wells, pumps, SCADA, and the connections between them
e.g. Backup

The board at a glance
Red Team stages attacks up top, Blue Team holds the line below, and the utility's assets sit contested in the middle. Two meters device the match: the SCP Tracker and Utility Impact.
.jpg)
System Control Points
The defender's running score control coverage banked across the NIST functions. Climb it by standing up defenses; it's the measure of how locked-down the utility is when the next attack lands.
SCP Tracker
Damage to the water Service
Every attack that reaches an asset pushes Impact up green to amber to red. Let it max out and the utility fails and Red Team wins; Recover cards are how Blue Team walks it back down.
Utility Impact

.png)

