The platform

A live range, not a course library

Courseware teaches you what an attack is. Tyrian runs one, against real attacker and defender machines, and measures whether your detections catch it. Attack, detect, and report from a single session: evidence capture, self-writing reports, ATT&CK readiness, containment, and the cost architecture that keeps it cheap.

Automated evidence capture

The engagement documents itself

A capture agent watches the whole kill chain and screenshots every milestone the moment it happens, beacon received, privilege gained, data staged, alert fired. Each frame is tagged with the technique, timestamp, and session.

  • Auto-screenshots at every ATT&CK milestone
  • Tagged with technique ID, stage, and tenant
  • Timeline scrubber for annotation and review
  • Feeds straight into report generation
See how evidence flows into reports
Evidence timeline
4 milestones auto-captured
  1. Beacon received

    T1059.00112:05:12
  2. Privilege escalation

    T1548.00212:06:58
  3. Lateral movement

    T1021.00212:08:20
  4. Data encrypted

    T148612:09:03
12:08
Automated reports

Finished reports, not blank templates

Every report is assembled from session data: the attack narrative from the ATT&CK event sequence, the evidence gallery from captured milestones, detection coverage and mean-time-to-detect from the event bus. You add the narrative, the facts are already there.

  • Red, Blue, and Purple team reports
  • Executive summary with readiness score & trend
  • Compliance coverage: NIST, ISO 27001, NCA ECC, DORA
  • Export to PDF, DOCX, JSON, and ATT&CK Navigator
Purple Team Joint Report
72%
Readiness
+8 vs last run
TechniqueMTTD · Outcome
  • Initial Access

    T1566.001

    0:00Detected
  • Execution

    T1059.001

    0:31Detected
  • Privilege Esc

    T1548.002

    1:46Partial
  • Lateral Movement

    T1021.002

    -Missed
  • Impact

    T1486

    0:12Detected
ATT&CK readiness

Know exactly where detection breaks down

Every offensive action emits a structured, ATT&CK-tagged event. Tyrian correlates it against your detections in real time and scores coverage per tactic, so you can see, technique by technique, what was caught, what was partial, and what slipped through.

  • Per-technique outcome: Detected / Partial / Missed
  • Mean-time-to-detect from event-bus timestamps
  • Readiness score per tactic, trended over time
  • Prioritized gap-closure recommendations
Explore the scenario library
ATT&CK coverage
DetectedPartialMissed
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Move
Collection
Exfiltration
Impact
How it works

From idea to report in four steps

No infrastructure to stand up, no tools to install, no teardown to remember. Tyrian handles the range so your team can focus on the exercise.

01
01

Pick a scenario

Choose from the library or describe what you want in plain language. The YAML lab definition is generated and validated for you.

02
02

Tyrian builds the lab

An isolated VPC of attacker and defender machines spins up from golden images, AD, workstations, C2, and the full SIEM/EDR stack, in under two minutes.

03
03

Run the engagement

Connect through your browser. Drive the attack, hunt the telemetry, or let automation run the chain while your blue team defends.

04
04

Get the report

Evidence, ATT&CK mapping, detection coverage, and readiness score are already assembled. Add narrative and export.

Security & isolation

Offensive tooling, contained by default

A range preloaded with C2 and exploitation tooling is a serious responsibility. Containment isn't a feature we added, it's the foundation everything else is built on.

Default-deny egress

Every lab subnet blocks outbound internet at the VPC level. Only an explicit allowlist, OS mirrors, tool updates, the control plane, is permitted.

Contained C2 only

Sliver and Metasploit callbacks resolve exclusively to in-lab redirectors. C2 never listens on or dials the public internet.

Simulated internet

Scenarios that need 'the internet' get INetSim / FakeNet or a curated local mirror, never live egress.

Tenant isolation from day one

Every session, VM, subnet, and evidence object is scoped to a tenant. One customer's lab can never reach or read another's.

Authorization gate

Operators attest they will only target lab-owned assets before launch. Consent is logged with identity and timestamp.

Immutable audit trail

Every provision, connect, snapshot, and destroy is logged. Guacamole sessions are recorded for evidence and audit.

Platform RBAC + enterprise SSO. Org admin, team lead, operator, and read-only roles, with SAML / OIDC single sign-on and least-privilege IAM on the AWS side.

Transparent pricing

Enterprise range, credit-friendly bill

Cost isn't an afterthought, it's engineered in. Per-hour metering, aggressive auto-suspend, and a mandatory per-session cap mean you get the capability without the runaway bill.

< 2 min
To a live lab

Ranges boot from a warm image and start in seconds, no waiting around to begin training.

$0
While idle

15 minutes idle auto-suspends the lab and stops the meter. Resume in under 60 seconds.

Per hour
Only what you run

Transparent per-hour pricing that scales with your topology, with a hard per-session cap.

Per-machine pricing Auto-teardown armed
from $0.12/hr
per machine, billed by the second
$8.00
per-session cap
Attacker box$0.12/hr
Windows workstation$0.18/hr
Wazuh SIEM$0.24/hr
Domain Controller$0.18/hr

One transparent per-hour rate per machine, capped per session so a lab can never run away. Your subscription covers the platform.

start in 90 seconds

Run your first engagement today

Spin up an isolated range in minutes. No infrastructure, no teardown, and an ATT&CK-mapped report waiting when you're done.

$5 starter credit. no card required.

provision
~90s express
isolation
per-lab VPC + SG
egress
default-deny
billing
per host-hour