Try it free

Run a live kill chain in your browser

No signup, no install. Step through a real ransomware intrusion, mapped to MITRE ATT&CK, and watch technique by technique what a SOC would catch, and where it wouldn't. This is a taste of what the real range does against your own detections.

Ransomware Outbreak, live kill chain10.13.0.0/24 · contained

You're the SOC. Step through a real ransomware intrusion and watch, technique by technique, what your detections would catch.

Detection readiness

0%
of executed techniques caught

0 / 7 techniques run

0
Detected
0
Partial
0
Missed

This is a guided sample.

The real range provisions actual attacker and defender machines, runs the chain against your telemetry, and exports the ATT&CK Navigator layer + reports.

How it works