Live range vs. courseware: why watching isn't doing
Videos and static labs teach you what an attack is. They can't tell you whether your detections would catch it. That gap is the whole point.
By The Tyrian team
Most security 'training' is courseware: a video explains a technique, a static lab lets you type the commands once, and a quiz confirms you watched. It's useful for learning vocabulary. It tells you nothing about whether your own detections would fire against that technique in production.
Knowing ≠ detecting
You can watch ten hours on LSASS dumping and still have a SOC that misses it, because the thing that matters isn't your understanding, it's whether the handle-access event is collected, whether a rule watches for it, and how fast it alerts. That's a property of your environment, not your knowledge.
What a live range adds
- Real attacker and defender machines, not a scripted demo you click through.
- Every action mapped to ATT&CK and scored against detections that actually fired.
- Mean-time-to-detect per technique, so you find the slow ones.
- A coverage map and report you can act on and show leadership.
The difference is measurement. Courseware ends when the video does. A live range ends with a number, detected, partial, missed, that you can improve and re-test.
See it on a real range
Run the interactive kill chain free, or create an account and start with $5 of credit.