Platform Updates
Lab Builder - Practical Labs
We're excited to announce a significant enhancement to our Lab Builder capability with the introduction of Practical Labs. This new capability will empower you to bring your own Amazon Machine Images (AMIs) directly into the Lab Builder environment, opening up a world of possibilities for creating custom labs tailored to your specific needs. Additionally, you'll notice an uplift to the user interface for our existing Immersive Labs and AppSec practical labs, providing a more streamlined and intuitive experience. This update is a key step in our vision to eventually enable internal content authors, the community, and external subject matter experts to build and publish labs on the platform. We believe this will provide even greater flexibility and value, allowing you to build labs on your own internal tools and policies, ultimately making Immersive an even more integral part of your security training programs.
Improved Lab Assignment Lifecycle
We're delivering improvements focused on bringing greater Clarity & Confidence to Assignments. In this release, we've specifically enhanced the control and visibility managers have over the Lab Assignment lifecycle. You'll now have clearer options for setting an explicit overdue completion window and for explicitly including past progress when creating or editing assignments. We've also improved the clarity around the "Assign To Whole Organisation" option and added a confirmation step for large assignments to prevent unintended distribution. Furthermore, you'll see a readable summary of the assignment before it's deployed, and importantly, closed assignments will now be removed from learners' launchpads, providing a cleaner and more relevant view of their active tasks.
Error Assist / Question Uplift
We're continuously working to improve the quality and user experience across all of our lab content. As part of this ongoing effort, we're conducting a broad analysis of individual questions within labs, using data to identify areas that may be causing lower success rates or potential frustration for our users. This initiative involves a comprehensive uplift of these identified questions to ensure greater clarity and effectiveness. This behind-the-scenes work is aimed at providing a smoother and more successful learning experience for all platform users.
Crisis Simulation - Presentation Mode UI Uplift
For our Crisis Simulation users, we're excited to announce an update that will enhance the facilitation experience. We're introducing new, highly requested functionality to the presentation mode, including an optional timer for injects to help manage the flow of the simulation.
Facilitators will also now have the ability to navigate back to previous injects in a read-only mode for review. Furthermore, participants using the companion app will now have full visibility of all information displayed on screen, including static media. Alongside these new features, we're also giving the presentation mode a modern look and feel, incorporating the latest Immersive branding to ensure a more engaging and user-friendly experience for both facilitators and participants. These improvements will help make your Crisis Sim exercises even more impactful and reflective of real-world scenarios.
As part of ongoing improvements to the Crisis Sim user experience, we have temporarily removed the ability to run the ‘Dual Screen Facilitator’ view. We are working hard to ensure that every element of Crisis Sim is optimized for the best user experience and will be returning with a revamped version of this feature - so keep your eyes peeled!
Advanced Notice - Cyber Capability Score being Replaced on the Platform
At the end of June 2025 we will be replacing the Cyber Capability Score report within the platform. The majority of the information currently included here will be replaced with updated and improved data and insights in a new report. The overall cyber capability score itself will be retired. If you have any questions, please contact your Immersive representative.
New and Updated Content
Immersive Labs
Introduction to Active Directory Attacks
We’re pleased to announce the Introduction to Active Directory Attacks collection. This new offensive coach collection is designed to guide users through various fundamental attacks targeting Active Directory environments.
Created to complement our intermediate Pen Test Program and address customer demand for introductory offensive AD content, this collection will explore tools and techniques such as password dumping, Pass-The-Hash attacks, lateral movement, and forest attacks. Learners will gain hands-on experience using tools like Mimikatz, PsExec, Bloodhound, Sharphound, and Chisel. While primarily aimed at offensive security professionals, this content will also be valuable for system administrators and SOC analysts looking to understand the basics of Active Directory attack methodologies. You can find this intermediate-level Immersive Labs content within the Infrastructure Hacking section.
Microsoft Sentinel: Threat Hunting with Notebooks & Workbooks
We're adding this new collection to help your teams develop hands-on skills in threat hunting within Microsoft Sentinel. This content will focus on utilizing workbooks and notebooks, essential tools for analysts conducting investigations in Microsoft Sentinel environments. Addressing a growing customer need for more advanced Sentinel content and aligning with areas covered in the official Microsoft Sentinel (SC-200) certification, this collection will include labs such as "Microsoft Sentinel: Threat Hunting with Notebooks," "Microsoft Sentinel: Security Analysis with Workbooks," "Microsoft Sentinel: Introduction to Notebooks," and "Azure Workbooks: Monitoring Metrics."
This content is ideal for SOC analysts, incident responders, forensics specialists, and cloud/security engineers who use Microsoft Sentinel as their SIEM.
Application Security
AppSec Cyber Range Exercise (Team Sim)
We're excited to announce the launch of our new AppSec Cyber Range Exercises for 2025, designed to provide immersive and practical application security training for your teams. These exercises, including the "Blossom" simulation, go beyond traditional labs to offer repeatable, real-world scenarios that encourage collaboration between development and security teams.
Participants will engage with realistic challenges, such as patching vulnerabilities identified in a penetration test, and utilize familiar tools like Kanban boards, GitLab for version control and CI/CD, and automated verification servers.
The "Blossom" exercise features a modern technology stack, including Javascript/React, Python/FastAPI, microservices, and Docker/GitLab, providing hands-on experience with secure development practices throughout the SDLC. These exercises are primarily targeted at development teams looking to enhance their secure coding skills and engineering managers aiming to facilitate team collaboration in vulnerability remediation.
Crisis Simulation
AI-pril Fools: The Return of the Puppetmaster
We're adding a new seasonal crisis simulation, AI-pril Fools: The Return of the Puppetmaster, to our catalog. This simulation, which will be run as a live event on April 3rd before its official release, throws users into a scenario where the Puppetmaster leverages AI to disrupt communication and manipulate information. Participants will face a complex, AI-driven crisis, testing their skills in crisis communication, security breach management, and decision-making under pressure. This simulation is designed to enhance understanding of AI vulnerabilities and information warfare, offering valuable learning outcomes for all users across various roles and skill levels.