Guide

Getting started

Create your workspace, fund it, launch your first lab, and run a full attack-to-report loop in your browser.


Tyrian is a browser-accessible purple-team cyber range. You launch an isolated cloud lab of attacker and defender machines, run a real attack, watch your detections fire, and get a report, without installing anything. This guide takes you from sign-up to your first report in under ten minutes.

1. Create your workspace

Sign up with an email and password, or Continue with Google. New individual workspaces are granted a one-time $5 starter credit, no card required. A single verified email is one account is one workspace.

2. Fund it

Every lab runs on real cloud compute, so a workspace needs funds before it can launch. Your $5 starter credit covers a full session. When it runs low you can top up ($10 / $25 / $50 / $100) or subscribe to a plan, in Billing. Metering is by the host-hour, drawn from your credit; nothing is billed after the fact.

3. Launch your first lab

The fastest first run is a guided scenario. Open Scenarios, pick one (Ransomware DR is a good start), and click launch. Tyrian provisions the range, an attacker box, a victim, and a Wazuh SIEM, and boots it in a couple of minutes. The lab card shows live phase and progress, then the rotated credentials and a Connect button when it is ready.

Prefer to compose your own? Use the Builder to drag attacker and victim machines onto a range, or add a Windows Active Directory range. See Ranges & the builder.

4. Run the attack, then detect

Connect opens the range in your browser (RDP and SSH tunnelled through Apache Guacamole, no client needed). Guided scenarios boot clean with the payload staged but not fired, you arm it from the browser. Use the scenario panel's Detonate, Check status, and Reset actions, then open the SIEM to see the alerts. Every action's output is captured to Evidence automatically.

5. Get your report

When you tear the lab down, Tyrian assembles a session report: duration, spend, ATT&CK techniques exercised, detections, and an evidence snapshot, framed for five audiences (Red, Blue, Purple, Executive, Compliance) and exportable as a professional PDF. That closes the loop: attack, detect, prove it.

Run it, don't just read it

Launch a real range and close the attack-to-report loop. $5 free credit, no card.