Ranges & the builder
The range types (container, Active Directory, custom), Standard vs Express provisioning, sizing, and how to connect.
A range is the live infrastructure your engagement runs on. Tyrian launches ranges on real, isolated cloud hosts and folds a multi-host range into one lab you manage from a single card.
Container range (the fast default)
One host runs a Guacamole gateway plus N attacker and M victim containers. It boots in roughly one to two minutes and is priced per machine. This is the right choice for most red-vs-blue exercises: fast, cheap, and enough surface to run a full kill chain.
Active Directory range
A full four-host Windows AD range: a Linux broker/attacker, a Domain Controller (tyrian.lab, seeded with realistic users and a kerberoastable service account), a domain-joined workstation, and an all-in-one Wazuh SIEM. Sysmon and the Wazuh agent are pre-installed on the Windows hosts. The full range assembles in about 15 to 20 minutes.
Custom range
Compose exactly what you need in the Builder: the broker (always), plus a Domain Controller toggle, a workstation stepper (0 to 5, each a real VM that domain-joins when a DC is present or runs standalone), and a Wazuh SIEM toggle. Live host count and hourly cost update as you build.
Standard vs Express provisioning
- Standard builds the range on boot from a base image. Lowest cost.
- Express boots from a pre-baked golden image with tools, containers, and the SIEM already staged, roughly 2.3x faster on the container range (measured 97s vs about 3.5 min). Priced at a +50% premium so the quote equals what you are charged.
Sizing & price
Compute is metered per host-hour at a fixed rate stamped on each lab, so the builder quote matches the bill. A one-attacker, one-victim container range is about $0.20/hr; a full AD range is about $0.72/hr. Adding a Wazuh SIEM or extra workstations raises the rate accordingly. Ranges self-terminate after a session cap and when idle, so a forgotten lab cannot run up a bill.
Connecting
When a lab reaches READY, the card surfaces a rotated per-lab Guacamole password and a Connect button. Connect opens the broker's HTTPS Guacamole in one browser tab, RDP into the DC or workstation, SSH into the attacker or Wazuh box, no local client, no VPN. A separate SIEM button opens the Wazuh dashboard with its own credentials shown on the card.
Run it, don't just read it
Launch a real range and close the attack-to-report loop. $5 free credit, no card.