A common failure mode in "cyber ranges" is that they feel like a lab — flat networks, obvious fake data, no real consequences for noisy behavior. We designed our Red vs Blue ranges to avoid that: realistic network segmentation, planted data that behaves like real data, and a live SIEM/EDR stack watching everything, exactly like a production environment would.
Design principles
- Every range is isolated and fully disposable — nothing persists between engagements unless intended
- Network topology mirrors real enterprise segmentation, not a flat lab subnet
- King-of-the-Hill mode adds live, competitive pressure on top of the base scenario
- Every action generates telemetry — there's no "invisible" attack path
The goal isn't just realism for its own sake — it's that skills built here transfer directly to a real environment, instead of teaching habits that only work in a lab.