One shared Windows Active Directory domain, live around the clock. Attackers race their own kill chains while a lean SOC hunts them in Elastic and fights back — every move scored against MITRE ATT&CK in real time and attributed to you. Rounds reset every 30 minutes. Jump in on either side.
One shared domain, a new 30-minute round on the clock. Jump into the current one — or watch the countdown to the next.
Attack the domain as Red, or defend it as Blue. Many play at once — more attackers than defenders, like the real world.
Red works their own kill chain; Blue and the always-on SIEM hunt and contain. Every move scores live, attributed to you.
Round ends, the board freezes for debrief, the range resets to pristine, a fresh round begins. Your rating follows you.
Work a real kill chain against a live Windows AD lab — recon, Kerberoasting, credential theft, lateral movement, domain dominance.
Watch the breach unfold in Elastic Security. Hunt the endpoint telemetry, confirm real attacks, and respond before Red reaches the domain controller.
Attacks and detections both map to the same MITRE ATT&CK technique, so the scoreboard shows exactly where Red got through and where Blue was watching.
Red earns for every objective and technique that lands on the target.
Blue earns for catching real attacks — and more for catching them fast.
Red earns extra for every technique Blue never detects. Getting in isn't the point — getting in unseen is.