RANGE-07 IS LIVE · 214 active sessions

A live-fire cyber range for SOC, Red Team & Blue Team

SocXRange rebuilds real enterprise infrastructure — servers, network gear, endpoints and log data — so security teams can attack, defend and investigate inside an isolated, safe, fully monitored environment.

Uptime 99.94% API Endpoint api.SocXRange.io/v2 Region AP-SOUTHEAST-1
TOPOLOGY // RANGE-07-ENTERPRISE-SEG LIVE CAPTURE
GW-EDGE-01 DC-AD-01 WEB-DMZ-02 DB-SQL-03 FILE-SRV-04 WKST-07 WKST-11
0
Active attack scenarios
0
SOC engineers trained
0
Simulated network segments
24/7
Session monitoring & logging
Threat Intelligence

Live Attack Map

Every scan, brute-force, and exploitation attempt against the Range is captured and streamed below — this data feeds directly into MSS investigation and incident-response training.

GLOBAL THREAT RADAR LIVE
THREAT LEVEL
0%
APAC SA-BR AF-NG SA-AR NA-WEST EU-WEST RU-EAST CN-EAST RANGE-07
EVENT STREAM 0 events
0
Attacks today
0
Source IPs
0
Countries observed
0%
Auto-contained
Platform

A range built like a real enterprise

Every component in the Range is built from real system images — not empty VM shells — so attack behavior and defensive response mirror actual SOC operations.

01

Full-fidelity infrastructure

Active Directory, web DMZ, database, file server and user endpoints — built to match real enterprise architecture.

02

Comprehensive logging

Every packet, process, registry change and login session is captured to support investigation after each exercise.

03

SIEM integration

Forward logs directly into your own SIEM via Syslog, Beats, or API to line up with real-world MSS workflows.

04

MITRE ATT&CK-mapped scenarios

Every lab maps to a specific tactic/technique, with completion reporting and detection scoring.

05

Fully isolated network

The range runs on a dedicated VLAN with no route out — safe to exercise real offensive tradecraft.

06

Purple Team mode

Red Team and Blue Team run side by side in the same session, with a shared timeline of detection events.

Scenario library

Open attack scenarios

Pick a range to spin up privately for your team. Each session gets its own isolated network.

IDScenarioSeverityDuration
RG-014
Internal Active Directory compromiseKerberoasting, lateral movement, privilege escalation
Critical4–6 hrs
RG-021
Web DMZ & SQL Injection chainFrom web app foothold to backend database access
High3 hrs
RG-033
Ransomware detection in the SOCReal-time Blue Team incident response
Critical5 hrs
RG-040
Phishing & endpoint exploitationPayload delivery, C2 beacon, persistence
High2–3 hrs
RG-052
Infrastructure recon & service enumerationEntry-level exercise for new SOC engineers
Medium1 hr
Access

Client Portal

Log in to your range account or request demo access.

Start your range session

Once logged in, you'll get a private VPN config file to connect to the isolated network segment of your chosen range.

  • OpenVPN config issued per session
  • Dashboard tracking progress & detection score
  • Full action log to support post-exercise reporting
  • Live support through the SOC operations channel
POST /api/v2/auth/session
Forgot password?
or continue with
Resources

Docs & tools

Download connection configs, browse API docs, or open the admin console for range coordinators.

VPN
Download OpenVPN config
/downloads/client-config.ovpn
2.1 KB
API
SIEM integration API docs
/docs/api/v2/siem-forwarding
v2.4.1
ADM
Range coordinator console
/admin/range-console
restricted
SUP
Support & ticket center
/support/tickets
24/7

Put your SOC team in a real fight

Request a demo to run a sample scenario alongside our deployment team.