Guide

Guided scenarios

Pre-built purple-team scenarios: a real range plus a red-then-detect-then-respond playbook you drive, with one-click host actions.


A guided scenario is a real range (the substrate) plus a playbook the learner drives, and, where it applies, one-click host actions. The lab boots clean: the payload is staged, not fired. You arm, detonate, and reset it from the browser, so you can run the loop as many times as you like.

The purple-team loop

  1. AttackDetonate

    Fire the staged technique from the scenario panel (or run it by hand from the attacker box). A whitelisted, server-defined command runs on the lab host, no arbitrary execution.

  2. DetectCheck the SIEM

    Open Wazuh and confirm the alert fired, then note what was missed. Coverage is the metric that matters.

  3. RespondReset & re-run

    Restore the host and run it again after tuning a detection, until the gap closes.

What ships today

  • Ransomware DR (container range) — a real AES T1486 encrypt of a data volume with a one-time backup, a poll-based EDR that flags the mass-encryption burst and ransom note, and a restore action. Includes its own Wazuh SIEM.
  • Kerberoast to Domain Admin (AD range) — a GOAD-style seeded domain where kerberoasting a weak service account leads to Domain Admin, mapped to its Wazuh 4769 detection.
  • Phish to lateral movement (custom two-workstation range) — a macro-phish foothold and lateral movement, detected in the SIEM.

Every guided scenario carries a Wazuh SIEM so the detect half of the loop is real, and a Fast toggle to provision it Express. Actions, detonate, reset, status, capture their output to Evidence as you go, so the report writes itself.

Run it, don't just read it

Launch a real range and close the attack-to-report loop. $5 free credit, no card.