All posts
PerspectiveJuly 2026 6 min read

Live range vs. courseware: why watching isn't doing

Videos and static labs teach you what an attack is. They can't tell you whether your detections would catch it. That gap is the whole point.

By The Tyrian team


Most security 'training' is courseware: a video explains a technique, a static lab lets you type the commands once, and a quiz confirms you watched. It's useful for learning vocabulary. It tells you nothing about whether your own detections would fire against that technique in production.

Knowing ≠ detecting

You can watch ten hours on LSASS dumping and still have a SOC that misses it, because the thing that matters isn't your understanding, it's whether the handle-access event is collected, whether a rule watches for it, and how fast it alerts. That's a property of your environment, not your knowledge.

What a live range adds

  • Real attacker and defender machines, not a scripted demo you click through.
  • Every action mapped to ATT&CK and scored against detections that actually fired.
  • Mean-time-to-detect per technique, so you find the slow ones.
  • A coverage map and report you can act on and show leadership.

The difference is measurement. Courseware ends when the video does. A live range ends with a number, detected, partial, missed, that you can improve and re-test.

Tyrian is a real, browser-accessible cyber range: one click provisions an isolated lab, runs a full ATT&CK-mapped kill chain, correlates your detections, and hands back the report. You can try the interactive version free, no signup.

See it on a real range

Run the interactive kill chain free, or create an account and start with $5 of credit.