A live range, not a course library
Courseware teaches you what an attack is. Tyrian runs one, against real attacker and defender machines, and measures whether your detections catch it. Attack, detect, and report from a single session: evidence capture, self-writing reports, ATT&CK readiness, containment, and the cost architecture that keeps it cheap.
The engagement documents itself
A capture agent watches the whole kill chain and screenshots every milestone the moment it happens, beacon received, privilege gained, data staged, alert fired. Each frame is tagged with the technique, timestamp, and session.
- Auto-screenshots at every ATT&CK milestone
- Tagged with technique ID, stage, and tenant
- Timeline scrubber for annotation and review
- Feeds straight into report generation
Beacon received
T1059.00112:05:12Privilege escalation
T1548.00212:06:58Lateral movement
T1021.00212:08:20Data encrypted
T148612:09:03
Finished reports, not blank templates
Every report is assembled from session data: the attack narrative from the ATT&CK event sequence, the evidence gallery from captured milestones, detection coverage and mean-time-to-detect from the event bus. You add the narrative, the facts are already there.
- Red, Blue, and Purple team reports
- Executive summary with readiness score & trend
- Compliance coverage: NIST, ISO 27001, NCA ECC, DORA
- Export to PDF, DOCX, JSON, and ATT&CK Navigator
Initial Access
T1566.001
0:00DetectedExecution
T1059.001
0:31DetectedPrivilege Esc
T1548.002
1:46PartialLateral Movement
T1021.002
-MissedImpact
T1486
0:12Detected
Know exactly where detection breaks down
Every offensive action emits a structured, ATT&CK-tagged event. Tyrian correlates it against your detections in real time and scores coverage per tactic, so you can see, technique by technique, what was caught, what was partial, and what slipped through.
- Per-technique outcome: Detected / Partial / Missed
- Mean-time-to-detect from event-bus timestamps
- Readiness score per tactic, trended over time
- Prioritized gap-closure recommendations
From idea to report in four steps
No infrastructure to stand up, no tools to install, no teardown to remember. Tyrian handles the range so your team can focus on the exercise.
Pick a scenario
Choose from the library or describe what you want in plain language. The YAML lab definition is generated and validated for you.
Tyrian builds the lab
An isolated VPC of attacker and defender machines spins up from golden images, AD, workstations, C2, and the full SIEM/EDR stack, in under two minutes.
Run the engagement
Connect through your browser. Drive the attack, hunt the telemetry, or let automation run the chain while your blue team defends.
Get the report
Evidence, ATT&CK mapping, detection coverage, and readiness score are already assembled. Add narrative and export.
Offensive tooling, contained by default
A range preloaded with C2 and exploitation tooling is a serious responsibility. Containment isn't a feature we added, it's the foundation everything else is built on.
Default-deny egress
Every lab subnet blocks outbound internet at the VPC level. Only an explicit allowlist, OS mirrors, tool updates, the control plane, is permitted.
Contained C2 only
Sliver and Metasploit callbacks resolve exclusively to in-lab redirectors. C2 never listens on or dials the public internet.
Simulated internet
Scenarios that need 'the internet' get INetSim / FakeNet or a curated local mirror, never live egress.
Tenant isolation from day one
Every session, VM, subnet, and evidence object is scoped to a tenant. One customer's lab can never reach or read another's.
Authorization gate
Operators attest they will only target lab-owned assets before launch. Consent is logged with identity and timestamp.
Immutable audit trail
Every provision, connect, snapshot, and destroy is logged. Guacamole sessions are recorded for evidence and audit.
Platform RBAC + enterprise SSO. Org admin, team lead, operator, and read-only roles, with SAML / OIDC single sign-on and least-privilege IAM on the AWS side.
Enterprise range, credit-friendly bill
Cost isn't an afterthought, it's engineered in. Per-hour metering, aggressive auto-suspend, and a mandatory per-session cap mean you get the capability without the runaway bill.
Ranges boot from a warm image and start in seconds, no waiting around to begin training.
15 minutes idle auto-suspends the lab and stops the meter. Resume in under 60 seconds.
Transparent per-hour pricing that scales with your topology, with a hard per-session cap.
One transparent per-hour rate per machine, capped per session so a lab can never run away. Your subscription covers the platform.
Run your first engagement today
Spin up an isolated range in minutes. No infrastructure, no teardown, and an ATT&CK-mapped report waiting when you're done.
$5 starter credit. no card required.
- provision
- ~90s express
- isolation
- per-lab VPC + SG
- egress
- default-deny
- billing
- per host-hour