Reference

Attacker & defender tooling

What is pre-installed on the attacker, victim, and detection hosts across the range types.


Every range boots with tooling staged so you can get to the exercise, not the setup. What is installed depends on the host's role.

Attacker hosts

The container range's attacker images and the AD range's Linux broker/attacker ship a working offensive toolkit (an SSH daemon plus common attack tooling) and, on the primary attacker, published ports so the firewall can expose a real listener. Express ranges bake these images in for a faster boot.

Victim & Windows hosts

Container victims run the target services a scenario needs. On the AD range, the Domain Controller and workstation are Windows Server 2022 with Sysmon and the Wazuh agent pre-installed; the DC is promoted to the tyrian.lab domain and seeded with realistic users and a kerberoastable service account (a GOAD-style path to Domain Admin).

Detection host

Ranges with a SIEM run an all-in-one Wazuh (indexer, manager, dashboard) with custom ATT&CK-mapped rules pre-loaded. See Detections & the SIEM.

Access layer

The broker runs Apache Guacamole behind nginx TLS, so RDP and SSH into every box come through your browser with no local client. Per-lab credentials are minted at launch and rotated, and surfaced on the lab card when the range is ready.

Bring your own licenses and agents: the hosts are real, so you can install a commercial EDR, your own Sigma rules, or a SIEM forwarder and test your actual stack.

Run it, don't just read it

Launch a real range and close the attack-to-report loop. $5 free credit, no card.