INCIDENT SIMULATION // LOCAL

Cloud Siege

ROUND1 / 6 CROWN10 ENERGY5 00:45
RED0 BLUE0
Choose a battle Opponent not selected Record · 0–0

PRODUCTION ACCOUNT // LIVE ATTACK GRAPH

Defence-in-depth control map

Planning

PENDING INTENTS // PRIVATE

Round plan

PRIVATE ZONE // YOUR HAND

Choose a card

FIELD MANUAL / 2 MINUTES

How to play

Red builds an attack chain. Blue layers security controls across the same path. Plan independently, reveal together, and protect—or breach—the Crown over six rounds.

YOUR FIRST ROUND

Plan, lock, resolve

  1. 01
    Choose your battle and role

    Play the computer, another person in a second tab, or invite a friend. Red attacks; Blue defends.

  2. 02
    Inspect your hand

    Each card shows its energy cost and family. Select it to see compatible properties, legal targets, and its exact action.

  3. 03
    Build a legal plan

    Place Red units or Blue towers on highlighted nodes. Queue payloads, abilities, responses, detections, and recovery from the inspector.

  4. 04
    Check energy and targets

    Your pending plan is still editable. Remove an intent if you need energy or want to change the route, carrier, support, or target.

  5. 05
    Lock simultaneously

    Your plan stays hidden from the opposing game view. The round resolves after both seats lock, or automatically when time expires.

  6. 06
    Read the result

    Follow the event log, score, and Security Intel lesson. Select Next round when you are ready to plan again.

Energy resets every round: 5 in round 1, then 7, 9, and 10 from round 4 onward. Your opening hand has 6 cards from a randomized 24-card loadout. After round 1, both sides draw two cards at the start of each new round; unused energy does not carry over.

DETAILED REFERENCE

Open what you need

Cards and planning
RED // OFFENCE
  • Units travel a legal route toward the Crown. You may queue up to three per round.
  • Payloads attach to a queued unit whose properties satisfy the requirement.
  • Abilities change routes, suppress detection, create units, recover persistence, or disrupt towers.
BLUE // DEFENCE
  • Towers occupy highlighted node slots and persist between rounds until disabled. Each non-Crown node has two slots; the Crown has none.
  • Responses provide one-shot containment or protection against the current attack.
  • Detections support a compatible tower or response in their scope; they reveal activity but do not block alone.
  • Recovery restores Crown Integrity or removes a surviving foothold.

How to read a card: cost is in the circle; family and ID sit below the name. The inspector explains uses, produces, resists, scope, and legal controls. Highlighted map nodes are the only valid placements.

How attacks and controls resolve
  1. ENTRY

    Edge and identity controls try to stop the attack before it establishes access.

  2. EXECUTION

    Compute and workload controls contain what runs after entry succeeds.

  3. EXIT

    Data controls weaken or prevent payload damage before the unit reaches the Crown.

Compatibility is property-based. An exact control can fully block its matching technique; a broad control covers more techniques but may only weaken them. Published exceptions, resistances, finite tower capacity, detection support, and Red disruption can change the outcome.

Red units and payloads are spent after resolution. Blue towers persist, but their capacity refreshes each round.

Winning and battle score

RED WINSReduce Crown Integrity from 10 to 0 before the end of round 6.

BLUE WINSKeep at least 1 Crown Integrity after round 6.

The Crown decides the winner; points measure performance. The live score and final debrief count only outcomes that actually resolve.

RED SCORESDamage ×100 · reach +25 · bypass +40 · disable tower +60 · breach +250 · early breach +50 per round saved

BLUE SCORESBlock +80 · contain +90 · weaken +30 · mitigate ×35 · detect +20 · restore ×50 · survive round +100 · Integrity remaining ×40 · defence +250

Each rejected or otherwise illegal intent costs that side 10 points. Open the match debrief for the complete itemized score.

Playing against another person
  • Human vs Human: use Open opponent to play both seats in two tabs on this device.
  • Invite a Friend: choose your side, create a private 1-on-1 match, then copy the link or six-character code. Your friend automatically receives the opposite side.
  • Different device on your local network: open the game from the host's LAN address before creating the invite. A 127.0.0.1 link only works on the host device.

In private online 1-on-1 play, hands and pending plans remain seat-scoped. Only the board and resolved events are shared.

Learning while you play

Security Intel follows the current cards and public round events. Lessons progress from basic identity and network concepts to advanced cloud attack paths, detection engineering, and recovery.

Choose Another lesson for a different tip, or Pause tips at any time. Occasionally, the Security Gremlin interrupts a new draw with terrible advice and a real correction; pausing tips silences it too. The event log always remains the authoritative explanation of what happened in the game.

Tip: reopen this manual at any time with Rules in the top bar.