how it works

One target. One attacker. One defender. Every move on the record.

DuelSec turns a purple-team exercise into a 1v1 match. Red tries to own a Windows Active Directory domain; Blue tries to catch them doing it. The same telemetry that scores the attack also scores the defense — so at the end you can see exactly where each side won and lost.

the core loop

Every technique runs the same circuit.

  1. 01
    Red attacks

    Runs techniques against the AD target

  2. 02
    Target emits

    Endpoints log every process, connection, and auth

  3. 03
    Elastic ingests

    Telemetry and alerts land in Elastic Security

  4. 04
    Blue responds

    Hunts, confirms, and contains the threat

  5. 05
    Both score

    Attacks and detections correlate on MITRE ATT&CK

→ the loop repeats every few seconds for the length of the match

play a match

Five steps, thirty to sixty minutes.

  1. 01

    Create or join

    One player creates a match and picks a scenario; the other joins with the 8-character match code from the lobby.

  2. 02

    Pick your side

    Choose Red (attacker) or Blue (defender). Both players ready up to start — you have a few minutes in the lobby to sort it out.

  3. 03

    Connect

    Red downloads a locked-down WireGuard config that reaches only the target subnet. Blue opens the Elastic Security console. The clock starts.

  4. 04

    Attack & defend

    Red works the kill chain from their own box; Blue hunts the telemetry and responds. The scoreboard and technique feed update live for both sides.

  5. 05

    Review

    When time runs out, the results page shows the full timeline, an attack replay, and a detection report — every technique, caught or missed.

the playbooks

What each side actually does.

RED · ATTACKER

Your job is to take the domain, and to do it quietly.

  • Connect your own Kali box (or C2) over the match VPN.
  • Work the kill chain: recon, Kerberoasting, credential theft, lateral movement, DCSync.
  • Complete scenario objectives for points — and earn a stealth bonus for anything Blue never detects.
BLUE · DEFENDER

Your job is to see the attack coming and shut it down.

  • Hunt the endpoint telemetry in Elastic Security as it streams in.
  • Confirm real attacks against the noise — false positives cost you.
  • Respond from the in-app panel: isolate a host or kill a process, against a limited budget.
scoring

How points are won — and lost.

ATK

Red, attack. Each technique and objective that lands scores. Deeper kill-chain moves (credential dumping, DCSync) are worth more than recon.

STL

Red, stealth. A bonus for every technique that expires undetected — staying quiet is the core offensive skill.

IMP

Red, impact. Disrupting a mission-critical service — ransomware, service stop — takes it offline and earns an impact bonus. The endgame of a real intrusion.

DET

Blue, detection. Catching an attack scores — scaled by two things real SOCs are graded on: how fast you caught it (dwell time / MTTD) and how severe the alert.

CTN

Blue, containment. Isolating a host the attacker is actually on cuts their access — their next moves there are blocked — and earns a bonus. Precision beats panic.

−AVL

Blue, availability penalty. Isolating or killing on a clean business-critical host is collateral damage — you bleed points until you release it. You can't win by locking everything down.

−FP

Blue, false positive. Chasing benign activity costs you. Confirm before you escalate.

every attack and detection is tagged with a MITRE ATT&CK technique — an attack and its detection correlate on the same ID, and that's what the scoreboard is built on.

the range enforces discipline

You can't cheese it. Neither side.

The scoring rewards the way real operators actually work — so the shortcuts that would break a live engagement don't win here either.

STAY IN SCOPE

Attacks against out-of-scope infrastructure — the range gateway, the scoring stack, your opponent — score nothing and are flagged as a foul. Hit the target, not the referee.

NO FARMING

Replaying the same technique on the same host for easy points doesn't work — credit decays sharply on repeats. Progress the intrusion; don't grind one move.

DON'T BLIND THE SENSOR

Killing the EDR or clearing logs to farm stealth backfires: tampering earns no stealth bonus, auto-alerts Blue, and is flagged. Evade detection — don't disable it.

what you need

Bring a friend.

A match is 1v1, so you need a second player — one on Red, one on Blue. Decide who takes which side in the lobby. Red should have a Kali box (or preferred offensive tooling) ready to connect over the VPN; Blue just needs a browser for the Elastic console and the response panel.

DUELSEC · cyber range train like you fight