Dynamic Threat Range is a strategic evolution of our range capability designed to improve the flexibility, realism, and accessibility of technical exercising.
Developer
Nebula Bank: MITRE ATLAS
Nebula Bank: MITRE ATLAS is a developer AI range that puts you in the shoes of a software engineer at Nebula Bank. After a recent update revamping the application, your AI SOC has reported a slew of suspicious behaviour. Your team's job is to respond to the crisis by triaging vulnerabilities, implementing fixes locally, and pushing them live.
Learning Outcomes:
- Analyze a reported vulnerability across a microservice backend to pinpoint the vulnerable code
- Prioritize a backlog of reported issues by actual risk, without relying on given severity labels
- Remediate flaws and ship the fixes through a branch, pull request, peer review, and CI/CD deploy
- Evaluate the output of AI coding assistants and catch fixes that look correct but leave the security hole open
- Verify a fix by reproducing the original exploit against the live application
Orchid Blossom: OWASP Top 10
Orchid Corp: Blossom is a developer AI range that puts you in the shoes of a software engineer at Orchid Corp. After the recent release of Orchid's new HR platform, Blossom, users have reported a number of vulnerabilities in the application. Your team's job is to respond to the crisis by triaging vulnerabilities, implementing fixes locally, and pushing them live before the company's reputation declines any further.
Learning Outcomes:
- Analyze a reported vulnerability across a microservice backend to pinpoint the vulnerable code
- Prioritize a backlog of reported issues by actual risk, without relying on given severity labels
- Remediate flaws and ship the fixes through a branch, pull request, peer review, and CI/CD deploy
- Evaluate the output of AI coding assistants and catch fixes that look correct but leave the security hole open
- Verify a fix by reproducing the original exploit against the live application
Blue Team - Threat Hunting
Agentic Intrusion
Orchid Labs, an Artificial Intelligence/Machine Learning (AI/ML) platform company, is facing a sophisticated intrusion targeting its machine learning infrastructure and internal development systems. As a security team member, you'll need to use the chosen Security Information and Event Management (SIEM) to detect the attack sequence. You'll trace the attacker's actions across the network, from initial access through to final impact.
Learning Outcomes:
- Identify indicators of credential misuse on external-facing internal services
- Use an SIEM platform to correlate data across multiple log sources – spanning Linux, Kubernetes, Windows, and application layers – to reconstruct a multi-hop attack chain
- Explain cloud-native attack techniques including server-side request forgery, container-based privilege escalation, and CI/CD pipeline poisoning
- Reconstruct lateral movement paths from a compromised ML platform into corporate infrastructure
Nebula Banking: Event Horizon
A multi-stage intrusion exploiting an AI-powered chatbot to gain initial access, escaping containerised infrastructure, and escalating through Active Directory certificate (ADCS) abuse to achieve domain compromise and financial fraud.
Learning Outcomes:
- Identify indicators of compromise associated with AI/LLM exploitation and prompt injection attacks
- Use a SIEM platform to correlate data across web application, database, Linux process, and Windows event logs
- Understand container escape techniques including Docker socket abuse and namespace breakout
- Trace lateral movement from compromised Linux infrastructure to Windows Active Directory environments
- Recognise Active Directory Certificate Services (ADCS) ESC1 exploitation patterns
Orchid Corp: Akira
Orchid Banking Group, a critical financial market infrastructure operator, is facing a sophisticated multi-extortion attack by the Akira RaaS group. As a member of the security team, you'll need to use a SIEM to apply threat intelligence, methodically detect the entire attack sequence, and trace the attacker's actions across the entire network, from initial access to final impact.
Learning Outcomes:
- Identify IoCs associated with Akira's ransomware activity and tactics
- Correlate data across multiple log sources using a SIEM and reconstruct the multi-stage attack timeline
- Discuss Akira's TTPs
- Develop effective TTP detection rules
Orchid Corp: Keiki
You're a threat hunter at Orchid Corp, a financial services company operating a managed file transfer platform for client data exchange. Intelligence reports indicate Cl0p ransomware operators are actively targeting file transfer applications to gain initial access before chaining credentials and deploying encryption domain-wide. Your task is to proactively hunt for indicators of this tradecraft across your environment.
Learning Outcomes:
- Proactively hunt for web application abuse patterns indicating initial access through file transfer platforms
- Identify anomalous process execution from non-standard directories using hypothesis-driven investigation
- Detect credential harvesting techniques through LSASS memory access pattern analysis
- Uncover lateral movement infrastructure by correlating WinRM fan-out activity across domain hosts
- Discover ransomware delivery mechanisms through SMB admin share mapping and archive extraction patterns
- Identify pre-encryption service disruption and execution confirmation artifacts across the domain
Orchid Corp: Mustang Panda
You're a threat hunter at Orchid Corp, a financial services company managing sensitive data. Your job is to assume the breach has already occurred and proactively hunt for subtle, living-off-the-land behaviors that allow sophisticated adversaries to hide in plain sight. Your hypotheses have already been laid out in the questions. Good luck!
Learning Outcomes:
- Identify IoCs associated with Mustang Panda malware and infrastructure
- Correlate data across multiple log sources to reconstruct the attack timeline
- Analyze DLL side-loading and "living-off-the-land" execution chains
- Detect credential theft, token impersonation, and WMI lateral movement
- Develop an understanding of Mustang Panda's TTPs
Orchid Emporium: Lazarus Group
Orchid Emporium, a medium-sized e-commerce retailer, has been targeted by Lazarus Group (also known as HIDDEN COBRA or Zinc). As a threat hunter, you'll use threat intelligence on Lazarus Group's supply-chain attack methodology to proactively search for indicators of compromise within the organization's developer infrastructure, CI/CD pipeline, and cloud environment.
Learning Outcomes:
- Apply threat intelligence to develop hunt hypotheses targeting developer-focused attack chains
- Use a SIEM platform to proactively search for supply chain compromise indicators across multiple log sources
- Recognize Lazarus Group's TTPs
Orchid Fusion: APT33
Orchid Fusion, a critical energy infrastructure operator, is facing a targeted intrusion campaign by the advanced persistent threat group APT33. As a security team member, you'll need to use the chosen SIEM to apply threat intelligence, methodically detect the entire attack sequence, and trace the attacker's actions across the network, from initial access to final impact.
Learning Outcomes:
- Identify IoCs associated with APT33's activity and tactics
- Correlate data across multiple log sources using an SIEM and reconstruct the multi-stage attack timeline
- Discuss APT33's TTPs
- Develop effective TTP detection rules
Blue Team - Incident Response
Nebula Banking: Event Horizon
A multi-stage intrusion exploiting an AI-powered chatbot to gain initial access, escaping containerised infrastructure, and escalating through Active Directory certificate (ADCS) abuse to achieve domain compromise and financial fraud.
Learning Outcomes:
- Identify indicators of compromise associated with AI/LLM exploitation and prompt injection attacks
- Use a SIEM platform to correlate data across web application, database, Linux process, and Windows event logs
- Understand container escape techniques including Docker socket abuse and namespace breakout
- Trace lateral movement from compromised Linux infrastructure to Windows Active Directory environments
- Recognise Active Directory Certificate Services (ADCS) ESC1 exploitation patterns
Orchid Corp: Akira
Orchid Banking Group, a critical financial market infrastructure operator, is facing a sophisticated, multi-extortion attack by the Akira RaaS group. As a security team member, you'll need to use the chosen SIEM to apply threat intelligence, methodically detect the entire attack sequence, and trace the attacker's actions across the entire network, from initial access to final impact.
Learning Outcomes:
- Identify IoCs associated with Akira's ransomware activity and tactics
- Use an SIEM platform to correlate data across multiple log sources and reconstruct the multi-stage attack timeline
- Understand Akira ransomware TTPs and apply this knowledge to develop effective detection rules
Orchid Corp: Anthesis
You're a DFIR analyst at Orchid Corp, a financial services company managing sensitive client data. Your SOC has received critical alerts indicating file transfer exploitation, rapid lateral movement, and Cl0p ransomware deployment across the domain. Threat intelligence has linked this campaign to an autonomous AI agent framework targeting financial services infrastructure. Your task is to investigate these alerts, trace the attack path, and document the full scope of the incident.
Learning Outcomes:
- Investigate file transfer application compromise executed by an autonomous attack agent through web server log correlation
- Trace automated credential chaining across application configs, linked SQL servers, and memory dumps
- Identify programmatic LOLBin abuse for credential extraction without dropping external tools
- Detect autonomous lateral movement through WMI and PowerShell remoting across a Windows domain
- Recognize automated ransomware propagation patterns, including admin share mapping and remote payload extraction
- Analyze post-encryption anti-forensic techniques deployed as part of an autonomous attack workflow
Orchid Corp: Keiki
You're a DFIR analyst at Orchid Corp, a financial services company managing sensitive client data. Your SOC has received critical alerts indicating the exploitation of a file transfer application, followed by rapid lateral movement and the suspected deployment of Cl0p ransomware across the domain. Your task is to investigate these alerts, trace the attacker's path, and document the full scope of the incident.
Learning Outcomes:
- Investigate file transfer application compromise through web server log correlation
- Trace credential chaining across application configs, linked SQL servers, and memory dumps
- Identify LOLBin abuse for credential extraction without dropping external tools
- Detect lateral movement through WMI and PowerShell remoting across a Windows domain
- Recognize ransomware propagation patterns including admin share mapping and remote payload extraction
- Analyze post-encryption anti-forensic techniques and scope the blast radius across a domain
Orchid Corp: Mustang Panda
You're a digital forensics and incident response (DFIR) analyst at Orchid Corp, a financial services company managing sensitive data. Your SOC has received multiple alerts indicating potential unauthorized access and suspicious activity across your network. Your task is to investigate these alerts, trace the attacker's path through your environment, and document the full scope of the incident.
Learning Outcomes:
- Investigate multi-stage security alerts in a chronological, methodical manner
- Correlate events across multiple systems to trace attacker movement
- Identify DLL side-loading and living-off-the-land (LotL) execution
- Detect credential theft, token impersonation, and lateral movement
- Locate persistence artifacts in the Windows registry and file system
- Analyze anti-forensic techniques used to hinder incident recovery
Orchid Emporium: Lazarus Group
Orchid Emporium, a medium-sized e-commerce retailer, is facing a sophisticated supply chain compromise attributed to Lazarus Group (also known as HIDDEN COBRA or Zinc). As an incident responder, you'll need to use the SIEM to investigate suspicious activity detected on developer infrastructure, trace the attacker's actions across the development and production environments, and assess the scope of the compromise.
Learning Outcomes:
- Identify indicators of compromise associated with Lazarus Group's supply chain attack tactics
- Use a SIEM platform to correlate data across multiple log sources
- Understand developer-focused compromise techniques including npm package manipulation, source code repository poisoning, and CI/CD pipeline exploitation
- Trace lateral movement from developer workstations through build infrastructure to production systems
Orchid Fusion: APT33
You're an incident response (IR) analyst at Orchid Fusion, an energy services company managing sensitive internal data. Your SOC has received multiple alerts indicating potential unauthorized access and suspicious activity across your network. Your task is to investigate these alerts, trace the attacker's path through your environment, and document the full scope of the incident.
Learning Outcomes:
- Investigate security alerts in a chronological, methodical manner
- Correlate events across multiple systems to trace attacker movement
- Identify credential theft, lateral movement, and data exfiltration techniques
- Document evidence of compromise for incident reporting
Red Team
Heist AI: Offensive
AI Readiness: Offensive edition. How prepared is your team for a world where AI can plan, run, and adapt real attacks across a network? This exercise gives you a practical way to find out. You will work through a full multi-stage engagement spanning three separate networks: a Linux prison, a Windows Active Directory environment, and a final locked-down zone with binary reverse engineering. Use different styles of AI support at each step, and see for yourself where AI helps, where it struggles, and where you still need to step in.
Learning Outcomes:
- See where AI speeds up offensive work and where it slows you down
- Build a real sense of what today's autonomous AI agents can and cannot achieve on their own
- Compare AI-assisted work against a full manual approach so you can weigh the trade-offs
- Measure the true cost of an AI-driven task, from token spend to time saved, and decide when the price is worth paying
- Notice which AI models fit which types of work, and start building your own sense of which one to reach for
- Feel the difference between AI on its own and AI working alongside you, and find the mix that suits how you work
- Understand what this means for defenders, so you know how to think about AI-driven threats going forward
Mythical AI: Offensive
AI Readiness: Offensive edition. How prepared is your team for a world where AI can plan, run, and adapt real attacks? This exercise gives you a practical way to find out. You will work through a chain of five machines, using different styles of AI support at each step, so you can see for yourself where AI helps, where it struggles, and where you still need to step in.
Learning Outcomes:
- See where AI speeds up offensive work and where it slows you down
- Build a real sense of what today's autonomous AI agents can and cannot achieve on their own
- Compare AI-assisted work against a full manual approach so you can weigh the trade-offs
- Measure the true cost of an AI-driven task, from token spend to time saved, and decide when the price is worth paying
- Notice which AI models fit which types of work, and start building your own sense of which one to reach for
- Feel the difference between AI on its own and AI working alongside you, and find the mix that suits how you work
- Understand what this means for defenders, so you know how to think about AI-driven threats going forward