purple-team cyber range

Run the attack.
Prove the
detection.

One request brings up an isolated range: attacker and victim hosts, a browser gateway, and a Wazuh SIEM wired together in a private VPC. You drive the attack, your rules get scored on what they actually catch, and the session exports as an ATT&CK-mapped report.

$5 starter credit. no card. metered per host-hour.

~90s
express boot
deny
default egress
5
report views
$0.20
from, per hr
attack simulationin progress
Ransomware Outbreaktyrian.lab
  1. Initial accessT1566
  2. ExecutionT1059
  3. Cred accessT1003
  4. Lateral moveT1021
  5. ImpactT1486
detection & coverage1,248 ev/min
76%ATT&CK
Detected76%
Partial14%
Missed10%
telemetry, events / min
37+12%
detections
8
alerts
24
assets
top detections
  • highLateral movement via PsExecT1021.002
  • highLSASS handle accessT1003.001
  • medOffice spawned script hostT1059.005
  • lowKerberoast, RC4 TGS requestT1558.003

Aligned with the frameworks your assessors already use

MITRE ATT&CKNIST CSF 2.0ISO 27001NCA ECCDORACIS ControlsMITRE ATT&CKNIST CSF 2.0ISO 27001NCA ECCDORACIS Controls
architecture

What actually runs when you launch a lab

No abstractions. Real EC2 hosts, real containers, real telemetry, torn down when you are done.

01substrate

Real hosts. Containers and VMs, not a simulator.

A container range is one EC2 host running a Guacamole gateway plus your attacker and victim Docker images. An AD range is four machines: a domain controller (tyrian.lab, seeded users and a kerberoastable SPN), a domain-joined workstation, an all-in-one Wazuh, and a Linux broker.

broker linux t3.medium guacamole gateway dc-01 win t3.medium ad-ds, sysmon, wazuh-agent ws-01 win t3.medium domain-joined wazuh linux t3.large indexer + manager + dash
02detect

Scored against your detections

Wazuh rules elevate the telemetry your attack generates into alerts, each tied to an ATT&CK id. Coverage is detected over exercised; every miss is a GAP and your next rule to write.

level 12 4769 RC4 T1558.003 kerberoast DETECTED
03contain

Default-deny egress

Every lab security group drops allow-all. DNS, 80/443, and intra-lab traffic only, so a box can pull packages but cannot beacon out. GuardDuty is on.

04cost

Metered by the host-hour

A per-instance rate is stamped on each lab. A 1+1 range is $0.20/hr, a full AD range $0.72/hr. Pay-as-you-go hard-stops at $0; nothing bills after the fact.

05isolate

One security group per lab

Each range gets its own SG in its own VPC. Ingress defaults to your IP; opening 0.0.0.0/0 is an explicit, warned choice. Organizations are opt-in with owner/admin/operator/viewer roles and an append-only audit log.

06speed

Express boots from a golden AMI

Standard builds the range on boot from a base image. Express detects/opt/lab/.bakedand skips the install and image pull: 97s versus about 3.5 minutes, at a 50% premium on the rate.

07prove

Session to report, no write-up

Action output auto-captures as evidence, mapped to ATT&CK. Tear the lab down and it assembles a report for five audiences, Executive, Red, Blue, Purple, and Compliance, exportable as a branded vector PDF.

detonate > capture > wazuh > coverage > report.pdf
See how the whole loop works
one request

Four machines, wired, isolated, and torn down when you say so

Nothing routes out of the lab except package mirrors and AWS. The only way in is one TLS port on the broker, and by default it is open to your IP alone.

isolated vpcegress: dns + 443 only:443YoubrowserBrokerguacamoleAttackerkali toolingDC-01tyrian.labWS-01domain-joinedWazuhsiem
97s
express boot, measured
4hosts
in a full AD range
0open ports
beyond your own IP
5views
per session report
the purple loop

Two teams. One range.
The same evidence.

Most tools pick a side. Tyrian runs both halves against each other in one isolated environment, so the attack and the detection are measured against the same session rather than argued about in a retro.

red team

Attack

Emulate a real adversary against machines you actually control, with the whole chain instrumented from initial access to impact.

Attacker containers and VMs
Kali-style tooling pre-baked, or bring your own
Guided kill chains
Kerberoast to DA, ransomware detonation, phish to lateral
On-demand detonation
The lab boots clean; you arm it when you are ready
Seeded AD weaknesses
Roastable SPNs, AS-REP users, abusable ACLs
blue team

Defend

Watch the same attack land in your SIEM, and find out which of your rules fire, which fire late, and which never fire at all.

Wazuh SIEM per range
Indexer, manager, and dashboard, wired to every host
Your rules, scored
Coverage is detected over exercised, not a vanity number
Sysmon on every endpoint
Real Windows telemetry, not synthetic log lines
Gaps you can act on
Every miss names the technique and the rule to write

Tear the range down and the session becomes one report, written for five audiences.

See what a report contains
Scenario library

A living library of real attacks

Each scenario is a full, instrumented kill chain with mandatory ATT&CK mapping and expected detections. New scenarios track CISA KEV and current ransomware TTPs.

Browse all scenarios
FlagshipLive

Ransomware Outbreak

Phishing delivery through AD privilege escalation to domain-wide encryption. The full kill chain, instrumented end to end.

att&ck path
  1. Initial Accessthen
  2. Privilege Escalationthen
  3. Impact
Scenario 2Beta

Insider Threat

A trusted operator stages and exfiltrates data over a contained channel. Tests behavioural and DLP detection.

att&ck path
  1. Collectionthen
  2. Exfiltration
Scenario 3Beta

Cloud IAM Escalation

Misconfigured roles and over-broad policies chained into a full cloud takeover path.

att&ck path
  1. Privilege Escalationthen
  2. Persistence
Scenario 4Soon

Web App Compromise

External foothold via an exposed application, pivoting inward to internal services.

att&ck path
  1. Initial Accessthen
  2. Lateral Movement
Scenario 5Soon

Supply Chain / CI-CD

A poisoned build pipeline delivers implanted artifacts to production. Tests pipeline integrity monitoring.

att&ck path
  1. Initial Accessthen
  2. Persistence
Scenario 6Soon

AD Vulnerability Selector

Compose a bespoke Active Directory weakness set, Kerberoasting, ADCS, delegation, and hunt it.

att&ck path
  1. Credential Accessthen
  2. Privilege Escalation
Enterprise & MSSP

One range for your whole org, or every client you defend

The same live, isolated cyber range, wrapped in the controls a security org or a managed provider needs. Provisioned by us, not self-serve.

For MSSPs & MSPs

Every client gets their own range

Run one console across your whole client book. Each client is an isolated organization with its own labs, its own people, and its own line on the bill.

  • Isolated client tenants, spun up in seconds
  • Consolidated billing with per-client cost allocation
  • White-labeled session reports carrying your name
  • One cross-client view of live labs, members, and spend
See how MSSPs use Tyrian
For security teams

Onboard analysts on real infrastructure

Give a new hire a real domain to break and a real SIEM to find it in, on their first day, without building a lab or waiting on procurement.

  • SAML / OIDC single sign-on
  • Owner, admin, operator, and view-only roles
  • Full audit log of launches, teardowns, and member changes
  • Committed-use compute and higher concurrent-lab limits
See enterprise capabilities

Enterprise and MSSP plans are provisioned for you, with committed-use compute and annual invoicing.

Book a demo
Compliance evidence

Map every exercise to the control that matters

Tyrian turns engagement outcomes into control-coverage evidence, with per-control references your assessors can follow, across the frameworks that govern Gulf, EU, and global security programs.

NIST CSF 2.0

Function & category coverage

ISO 27001:2022

Annex A control evidence

NCA ECC

Gulf-priority, first-class mapping

DORA

Financial-sector resilience

Compliance reports are framed as control-coverage evidence to support an assessment. They are not a certification and do not constitute a formal audit result.

start in 90 seconds

Run your first engagement today

Spin up an isolated range in minutes. No infrastructure, no teardown, and an ATT&CK-mapped report waiting when you're done.

$5 starter credit. no card required.

provision
~90s express
isolation
per-lab VPC + SG
egress
default-deny
billing
per host-hour