Home Services Cyber Range About Research Contact
Cyber Range/Breach Live Fire
Live fire — real time

Someone is already inside.

A beacon called home eleven minutes ago. There is a person on the other end of it, and they are working through your network right now — hunting credentials, moving sideways, heading for the database. They do not stop while you think.

A safe, fictional simulation — nothing on your machine is touched. The attack path mirrors real intrusions: phished credentials, a beaconing implant, credential dumping, lateral movement and staged exfiltration over HTTPS.

How to play

No multiple choice. Just the console.

Read

The logs hold the answer

The event stream names the compromised account and the C2 address if you are watching. Everything you need to act correctly is in there before the attacker uses it.

Cut

Sever what they're using

Revoke the account, kill the beacon process, isolate the host they landed on, and block the exfil IP. Each one removes a capability they were relying on.

Type

Or drive it from the terminal

revoke j.mehta, kill 4471, isolate WS-FIN-03, block 185.220.101.44, status. Type help for the full list.

Prefer your disasters encrypted?
Ransomware Live Fire gives you three minutes before the estate is gone.
Play Ransomware Live Fire