Run the attack.
Prove the
detection.
One request brings up an isolated range: attacker and victim hosts, a browser gateway, and a Wazuh SIEM wired together in a private VPC. You drive the attack, your rules get scored on what they actually catch, and the session exports as an ATT&CK-mapped report.
$5 starter credit. no card. metered per host-hour.
- ~90s
- express boot
- deny
- default egress
- 5
- report views
- $0.20
- from, per hr
- Initial accessT1566
- ExecutionT1059
- Cred accessT1003
- Lateral moveT1021
- ImpactT1486
- highLateral movement via PsExecT1021.00210:23:31
- highLSASS handle accessT1003.00110:22:47
- medOffice spawned script hostT1059.00510:22:03
- lowKerberoast, RC4 TGS requestT1558.00310:21:14
Aligned with the frameworks your assessors already use
What actually runs when you launch a lab
No abstractions. Real EC2 hosts, real containers, real telemetry, torn down when you are done.
Real hosts. Containers and VMs, not a simulator.
A container range is one EC2 host running a Guacamole gateway plus your attacker and victim Docker images. An AD range is four machines: a domain controller (tyrian.lab, seeded users and a kerberoastable SPN), a domain-joined workstation, an all-in-one Wazuh, and a Linux broker.
Scored against your detections
Wazuh rules elevate the telemetry your attack generates into alerts, each tied to an ATT&CK id. Coverage is detected over exercised; every miss is a GAP and your next rule to write.
Default-deny egress
Every lab security group drops allow-all. DNS, 80/443, and intra-lab traffic only, so a box can pull packages but cannot beacon out. GuardDuty is on.
Metered by the host-hour
A per-instance rate is stamped on each lab. A 1+1 range is $0.20/hr, a full AD range $0.72/hr. Pay-as-you-go hard-stops at $0; nothing bills after the fact.
One security group per lab
Each range gets its own SG in its own VPC. Ingress defaults to your IP; opening 0.0.0.0/0 is an explicit, warned choice. Organizations are opt-in with owner/admin/operator/viewer roles and an append-only audit log.
Express boots from a golden AMI
Standard builds the range on boot from a base image. Express detects/opt/lab/.bakedand skips the install and image pull: 97s versus about 3.5 minutes, at a 50% premium on the rate.
Session to report, no write-up
Action output auto-captures as evidence, mapped to ATT&CK. Tear the lab down and it assembles a report for five audiences, Executive, Red, Blue, Purple, and Compliance, exportable as a branded vector PDF.
Four machines, wired, isolated, and torn down when you say so
Nothing routes out of the lab except package mirrors and AWS. The only way in is one TLS port on the broker, and by default it is open to your IP alone.
- 97s
- express boot, measured
- 4hosts
- in a full AD range
- 0open ports
- beyond your own IP
- 5views
- per session report
Two teams. One range.
The same evidence.
Most tools pick a side. Tyrian runs both halves against each other in one isolated environment, so the attack and the detection are measured against the same session rather than argued about in a retro.
Attack
Emulate a real adversary against machines you actually control, with the whole chain instrumented from initial access to impact.
- Attacker containers and VMs
- Kali-style tooling pre-baked, or bring your own
- Guided kill chains
- Kerberoast to DA, ransomware detonation, phish to lateral
- On-demand detonation
- The lab boots clean; you arm it when you are ready
- Seeded AD weaknesses
- Roastable SPNs, AS-REP users, abusable ACLs
Defend
Watch the same attack land in your SIEM, and find out which of your rules fire, which fire late, and which never fire at all.
- Wazuh SIEM per range
- Indexer, manager, and dashboard, wired to every host
- Your rules, scored
- Coverage is detected over exercised, not a vanity number
- Sysmon on every endpoint
- Real Windows telemetry, not synthetic log lines
- Gaps you can act on
- Every miss names the technique and the rule to write
Tear the range down and the session becomes one report, written for five audiences.
See what a report containsA living library of real attacks
Each scenario is a full, instrumented kill chain with mandatory ATT&CK mapping and expected detections. New scenarios track CISA KEV and current ransomware TTPs.
Ransomware Outbreak
Phishing delivery through AD privilege escalation to domain-wide encryption. The full kill chain, instrumented end to end.
- Initial Accessthen
- Privilege Escalationthen
- Impact
Insider Threat
A trusted operator stages and exfiltrates data over a contained channel. Tests behavioural and DLP detection.
- Collectionthen
- Exfiltration
Cloud IAM Escalation
Misconfigured roles and over-broad policies chained into a full cloud takeover path.
- Privilege Escalationthen
- Persistence
Web App Compromise
External foothold via an exposed application, pivoting inward to internal services.
- Initial Accessthen
- Lateral Movement
Supply Chain / CI-CD
A poisoned build pipeline delivers implanted artifacts to production. Tests pipeline integrity monitoring.
- Initial Accessthen
- Persistence
AD Vulnerability Selector
Compose a bespoke Active Directory weakness set, Kerberoasting, ADCS, delegation, and hunt it.
- Credential Accessthen
- Privilege Escalation
One range for your whole org, or every client you defend
The same live, isolated cyber range, wrapped in the controls a security org or a managed provider needs. Provisioned by us, not self-serve.
Every client gets their own range
Run one console across your whole client book. Each client is an isolated organization with its own labs, its own people, and its own line on the bill.
- Isolated client tenants, spun up in seconds
- Consolidated billing with per-client cost allocation
- White-labeled session reports carrying your name
- One cross-client view of live labs, members, and spend
Onboard analysts on real infrastructure
Give a new hire a real domain to break and a real SIEM to find it in, on their first day, without building a lab or waiting on procurement.
- SAML / OIDC single sign-on
- Owner, admin, operator, and view-only roles
- Full audit log of launches, teardowns, and member changes
- Committed-use compute and higher concurrent-lab limits
Enterprise and MSSP plans are provisioned for you, with committed-use compute and annual invoicing.
Book a demoMap every exercise to the control that matters
Tyrian turns engagement outcomes into control-coverage evidence, with per-control references your assessors can follow, across the frameworks that govern Gulf, EU, and global security programs.
NIST CSF 2.0
Function & category coverage
ISO 27001:2022
Annex A control evidence
NCA ECC
Gulf-priority, first-class mapping
DORA
Financial-sector resilience
Compliance reports are framed as control-coverage evidence to support an assessment. They are not a certification and do not constitute a formal audit result.
Run your first engagement today
Spin up an isolated range in minutes. No infrastructure, no teardown, and an ATT&CK-mapped report waiting when you're done.
$5 starter credit. no card required.
- provision
- ~90s express
- isolation
- per-lab VPC + SG
- egress
- default-deny
- billing
- per host-hour