This guide outlines the streamlined workflow for setting up and managing a Dynamic Threat Range exercise. As a facilitator, your role is critical in ensuring the environment is configured to match your team's real-world requirements.
Setting up an exercise
You configure a DTR exercise in five steps. Work through them in order — each step builds on the previous one.
Step 1: Choose a scenario and specialization
Start by selecting the scenario you want to exercise on, then choose the specialization that matches your objectives for the session.
- Incident Response: an alert-driven specialization focused on in-depth investigation and reconstruction of the complete attack lifecycle for surfaced threats.
- Threat Hunting: a hypothesis-driven specialization focused on proactively detecting attacks that have gone undetected by automated systems.
- Red Team: an offensive specialization where participants work through the target network from a Kali attack box and prove access by recovering the tokens hidden across each machine.
- Developer: a remediation specialization where participants fix real vulnerabilities in application source and the platform validates each fix automatically.
Step 2: Choose a SIEM
This step applies to Incident Response and Threat Hunting. Select the defensive technology your team will use during the exercise. The following SIEMs are currently available:
- Elastic
- Splunk
- Microsoft Sentinel
CrowdStrike NG SIEM is coming later in 2026.
Red Team and Developer exercises have no equivalent selection — their tools (the Kali attack box for Red Team, the development environment for Developer) come preconfigured with the scenario.
Step 3: Name the exercise and set a duration
Give the exercise a clear title, then set how long it will run. The default duration is four hours. You can set any duration up to a maximum of 24 hours.
Step 4: Schedule the exercise or start it manually
You have two options for getting the environment live.
If you want the environment ready at a specific time, use the Scheduled Automated Deployment feature. Set the exact date and time you want provisioning to complete — the environment will be ready when participants arrive, with no wait time during the live session.
If you'd rather start manually, you'll trigger two actions when you're ready: first, select Provision exercise to deploy the range environments. Once provisioning is complete, select Start exercise to begin the timer and grant participants access.
Step 5: Add participants
Organize your users into teams. Any user in your organization with an Immersive account can be added. You can create up to five teams with a maximum of 15 participants per team.
Monitoring the exercise
Once the exercise is running, the facilitator view gives you two tabs for monitoring environment health and tracking team progress.
Range tab
The Range tab shows a real-time visual representation of the exercise environment for each team. It displays scenario details, team environments, and an interactive network diagram of the infrastructure.
For Incident Response and Threat Hunting exercises, the Range tab also tracks the automated attack. Selecting a team brings up their attack progress in the attack stages panel. When a team's attack is actively running, Live Follow Mode automatically tracks the currently executing attack step and highlights the attack path through the network diagram. How the attack is initiated depends on the specialization:
- Incident Response: attacks launch automatically during provisioning and complete before participants are granted access.
- Threat Hunting: use the Launch Attack action to manually initiate the attack across all team environments. This lets you control when the attack begins after participants have joined their ranges.
Red Team and Developer exercises have no automated attack — in a Red Team exercise the participants are the attackers, and a Developer exercise has no attack at all. For these types the Range tab shows environment health and the network diagram, and you track progress from the Teams tab. Environment actions, such as retrying attacks where applicable, are also managed from the Range tab.
Teams tab
The Teams tab focuses on team performance and activity during the exercise. You can track responses and task completion in real time as participants submit their findings, review participant assignments for each team, and view detailed submission history and accuracy for each team's responses.
Post-exercise analysis
Once the exercise concludes, you get access to the full results. The metrics available depend on the specialization.
Metrics and scoring
For Threat Hunting exercises:
- Time to Detect (TTD): the time elapsed between the start of the live attack and accurate evidence of detection being submitted.
- Time to Escalate (TTE): the time elapsed between the start of the live attack and escalation of the incident. This metric requires sufficient evidence of detection to have been submitted first.
- Tasks Completed: the number of tasks with a correct final submission, shown as a ratio (e.g., 8/10).
- Accuracy: the percentage of correct submissions, calculated by dividing the number of tasks with correct final submissions by the total number of tasks.
For Incident Response exercises:
- Time to Investigate (TTI): the time elapsed between the team being able to join the exercise and the conclusion of the investigation.
- Tasks Completed: the number of tasks with a correct final submission, shown as a ratio (e.g., 8/10).
- Accuracy: the percentage of correct submissions, calculated by dividing the number of tasks with correct final submissions by the total number of tasks.
For Red Team and Developer exercises:
- Time to Complete: the time elapsed between the team being able to join the exercise and the completion of the work.
- Tasks Completed: the number of tasks with a correct final submission, shown as a ratio (e.g., 8/10).
- Accuracy: the percentage of correct submissions, calculated by dividing the number of tasks with correct final submissions by the total number of tasks.
For AI-assisted exercises, the results also include Total Token Cost, with a Token Cost Breakdown showing spend per model — so you can weigh what the AI cost each team against what it delivered.
Beyond the top-level scores, you can drill into each team's activity through the Submission Review. This shows a chronological log of every answer and piece of evidence submitted by each team, with a clear Correct or Incorrect result for each submission. It gives you the detail you need to lead an effective post-exercise debrief and identify where each team's work went well or fell short.