Tyrian
PlatformEnterpriseLearnPricingDocs
Sign inGet started
Blog

Notes from the range

Threat research and detection-engineering practice, every post grounded in MITRE ATT&CK.

Perspective
PerspectiveJuly 2026 6 min

Live range vs. courseware: why watching isn't doing

Videos and static labs teach you what an attack is. They can't tell you whether your detections would catch it. That gap is the whole point.

Threat researchJune 2026

Anatomy of a ransomware kill chain (ATT&CK-mapped)

From a single phishing email to domain-wide encryption, the seven stages of a ransomware intrusion, the ATT&CK technique behind each, and where you get to intervene.

9 min read
Detection engineeringJune 2026

Detecting lateral movement: SMB, PsExec, and the gap everyone has

The stage where one foothold becomes a domain compromise is also the one SOCs miss most. Here's why, and the telemetry that closes it.

8 min read
Detection engineeringMay 2026

LSASS credential dumping, and how to actually catch it

LSASS is where Windows keeps the keys. Dumping it (T1003.001) is a favorite of every ransomware crew, and one of the highest-fidelity things you can detect.

7 min read
Tyrian

A browser-accessible purple-team cyber range. Isolated cloud labs, automated evidence, and reports that write themselves.

Platform

  • Overview
  • Evidence capture
  • Automated reports
  • Scenario library
  • Security & isolation

Product

  • Pricing
  • Enterprise & MSSP
  • Docs
  • Try a live scenario
  • Book a demo
  • Sign in

Learn

  • Learning modules
  • ATT&CK library
  • Detection Pack (free)
  • ATT&CK glossary
  • Free scenario

Company

  • Blog
  • Contact
  • Feedback
  • Book a demo

Legal

  • Acceptable Use
  • Terms of Service
  • Privacy Policy
  • Refund Policy

© 2026 Tyrian. All rights reserved.

Tyrian provides isolated lab environments for authorized security testing only. Use is governed by the Acceptable Use Policy.