Guided scenarios
Pre-built purple-team scenarios: a real range plus a red-then-detect-then-respond playbook you drive, with one-click host actions.
A guided scenario is a real range (the substrate) plus a playbook the learner drives, and, where it applies, one-click host actions. The lab boots clean: the payload is staged, not fired. You arm, detonate, and reset it from the browser, so you can run the loop as many times as you like.
The purple-team loop
- AttackDetonate
Fire the staged technique from the scenario panel (or run it by hand from the attacker box). A whitelisted, server-defined command runs on the lab host, no arbitrary execution.
- DetectCheck the SIEM
Open Wazuh and confirm the alert fired, then note what was missed. Coverage is the metric that matters.
- RespondReset & re-run
Restore the host and run it again after tuning a detection, until the gap closes.
What ships today
- Ransomware DR (container range) — a real AES T1486 encrypt of a data volume with a one-time backup, a poll-based EDR that flags the mass-encryption burst and ransom note, and a restore action. Includes its own Wazuh SIEM.
- Kerberoast to Domain Admin (AD range) — a GOAD-style seeded domain where kerberoasting a weak service account leads to Domain Admin, mapped to its Wazuh 4769 detection.
- Phish to lateral movement (custom two-workstation range) — a macro-phish foothold and lateral movement, detected in the SIEM.
Every guided scenario carries a Wazuh SIEM so the detect half of the loop is real, and a Fast toggle to provision it Express. Actions, detonate, reset, status, capture their output to Evidence as you go, so the report writes itself.
Run it, don't just read it
Launch a real range and close the attack-to-report loop. $5 free credit, no card.