Dynamic Threat Ranges puts teams inside realistic, on-demand enterprise environments and tests them against real attacks from any angle — hunt them, respond to them, run them, or fix what let them in.
Overview
Dynamic Threat Ranges (DTR) is a technical exercising product built around realistic, on-demand enterprise environments. It's designed for security and development teams who want to test their skills against genuine attack scenarios and critical incidents — not guided walkthroughs.
Where standard lab exercises lead you through steps and tell you when you're right, DTR drops you into a live environment and asks you to figure it out. There are no in-session hints and no right-or-wrong notifications while you work. You do the job with real tools, submit your findings based on the evidence you uncover, and get your results in the debrief afterwards.
The environments mirror actual enterprise networks — the same infrastructure, the same attack paths, the same code. That means the scenarios aren't contrived, whether you're defending the network, attacking it, or repairing the software running on it.
Exercise types
DTR offers four exercise specializations, each with a different starting point, objective, and toolset.
Incident Response
Incident Response (IR) exercises are alert-driven. The attack completes before participants join the environment. Your job is to respond to triggered alerts, investigate what happened, and reconstruct the attack timeline. You're working from the aftermath — piecing together the full picture from the evidence left behind.
Threat Hunting
Threat Hunting exercises are hypothesis-driven. You start from threat intelligence rather than alerts, and the attack runs live during the session. Your goal is to proactively hunt for indicators of compromise across the environment before automated systems catch them — or confirm they haven't.
Red Team
Red Team exercises put you on the offensive. You're dropped into a pentesting engagement with a set of target machines and a deadline, and no inside knowledge of where the weak spots are. Your job is to work through the network the way a real attacker would and prove access by recovering the tokens hidden across each machine. You work from a Kali attack box that gives you a choice of approaches — AI-assisted or fully manual — so you can see for yourself where AI speeds offensive work up and where it slows you down.
Developer
Developer exercises are about remediation. You're handed a real application carrying real vulnerabilities and asked to fix them in a browser-based development environment. The platform validates each fix automatically — your task completes when the flaw is closed and the feature still works. It's the defender's-eye view of the same weaknesses the other specializations exploit.
Tools by exercise type
What you work in depends on the specialization.
- Incident Response and Threat Hunting run in a SIEM — Elastic, Splunk, or Microsoft Sentinel. CrowdStrike NG SIEM support is coming later in 2026. Your facilitator selects the SIEM when setting up the exercise, so you'll always be working in the tool your team has been assigned.
- Red Team gives you a dedicated Kali attack box inside the client network, surfaced in your browser as three tabs: OpenWebUI (chat with an AI wired into a Kali toolkit), PentAGI (a fully autonomous AI agent that plans and runs the job itself), and the Kali Desktop (a normal Linux desktop with no AI at all). You switch between them freely as you work.
- Developer gives you a browser-based VS Code editor with AI coding assistants in the terminal, a ticket board of the issues to triage, and a Git repository to clone, edit, and push.
Teams and performance measurement
Exercises support up to five teams with up to 15 participants per team, so you can run multiple groups through the same scenario simultaneously — or put different teams head-to-head.
The platform tracks performance throughout the session, but you won't see your scores while you're working. Metrics are available in the debrief. What gets measured depends on the specialization:
- Threat Hunting: Time to Detect (TTD), Time to Escalate (TTE), Tasks Completed, and Accuracy
- Incident Response: Time to Investigate (TTI), Tasks Completed, and Accuracy
- Red Team: Time to Complete, Accuracy, and Tasks Completed
- Developer: Time to Complete, Accuracy, and Tasks Completed
For AI-assisted exercises, the debrief also reports Total Token Cost, with a Token Cost Breakdown showing spend per model — so you can weigh what the AI actually cost against what it delivered.
The debrief includes a full submission review too — a chronological log of every answer submitted, showing which were correct and which weren't.
Who it's for
DTR is built for teams who want to test and develop their skills in a realistic environment rather than a guided training context: SOC analysts, threat hunters, and incident responders on the defensive side; red teamers and penetration testers on the offensive side; and developers and application security engineers on the remediation side. It works well for team exercises, internal benchmarking, and exercises run by a facilitator who wants to observe and measure performance in real time.
Next steps
If you're setting up and running an exercise, start with the Facilitator Guide. If you're joining one as a participant, go to the Participant Guide. You can browse available scenarios in the Catalog.