Evidence & reports
How evidence is captured automatically, and how the five report perspectives are assembled and exported to PDF.
The point of the range is proof. Tyrian captures evidence as you drive the loop and turns a torn-down session into an audience-ready report, no manual write-up.
Evidence capture
Scenario action outputs, detonate, check status, reset, are captured to Evidence automatically as you run them, each tagged attack or detection and mapped to ATT&CK. You can add screenshots too. Evidence is grouped per lab and sectioned by kind (attacks, detections, notes, screenshots) so a session reads as a clean timeline.
Five report perspectives
Tearing a lab down generates a session report that reframes the same captured session for five audiences:
- Executive — risk, coverage, and cost at a glance, with a recommendation.
- Red team — the actions executed and the ATT&CK techniques demonstrated.
- Blue team — detection posture, the alerts that fired, and the gaps.
- Purple team — an attack-vs-detection coverage table, GAP where undetected.
- Compliance — each technique mapped to NIST CSF, ISO 27001, NCA ECC, and DORA.
Professional PDF export
Export is a real branded vector PDF, not a screenshot of a print page: a chevron brand chip (white-labeled for MSSP client reports), styled coverage and control-mapping tables, and page footers. Download a single perspective or the full five-perspective report in one document.
Run it, don't just read it
Launch a real range and close the attack-to-report loop. $5 free credit, no card.