Home Services Cyber Range About Research Contact
Cyber Range/Ransomware Live Fire
Live fire — real time

The files are encrypting now.

04:12. Someone in Accounts opened an invoice attachment. The payload is already running, and it is spreading across your file share while you read this sentence. Nothing here waits for you. Find the process, kill it, cut its road, get your data back.

A safe, fictional simulation — nothing on your machine is touched. The mechanics mirror how real ransomware behaves: unsigned binaries in AppData, SMB worming, shadow-copy deletion and backup vaults targeted first.

How to play

No multiple choice. Just the console.

Click

Select a host, then act

The estate panel is live. Click any machine to select it, then use Isolate to drop it off the network or Restore to rebuild it from backup.

Kill

The process table is real

Processes run in the right-hand table. One of them does not belong — wrong name, wrong directory, wrong command line. Hit kill on it. Kill the wrong one and your users go offline.

Type

Or just use the terminal

isolate FS-SHARE-01, kill 7731, share off, restore WS-ACCT-02, status. Type help for the full list.

Think you'd spot the intruder instead?
Breach Live Fire puts a human attacker inside your network, moving in real time.
Play Breach Live Fire