Attacker & defender tooling
What is pre-installed on the attacker, victim, and detection hosts across the range types.
Every range boots with tooling staged so you can get to the exercise, not the setup. What is installed depends on the host's role.
Attacker hosts
The container range's attacker images and the AD range's Linux broker/attacker ship a working offensive toolkit (an SSH daemon plus common attack tooling) and, on the primary attacker, published ports so the firewall can expose a real listener. Express ranges bake these images in for a faster boot.
Victim & Windows hosts
Container victims run the target services a scenario needs. On the AD range, the Domain Controller and workstation are Windows Server 2022 with Sysmon and the Wazuh agent pre-installed; the DC is promoted to the tyrian.lab domain and seeded with realistic users and a kerberoastable service account (a GOAD-style path to Domain Admin).
Detection host
Ranges with a SIEM run an all-in-one Wazuh (indexer, manager, dashboard) with custom ATT&CK-mapped rules pre-loaded. See Detections & the SIEM.
Access layer
The broker runs Apache Guacamole behind nginx TLS, so RDP and SSH into every box come through your browser with no local client. Per-lab credentials are minted at launch and rotated, and surfaced on the lab card when the range is ready.
Run it, don't just read it
Launch a real range and close the attack-to-report loop. $5 free credit, no card.