DuelSec turns a purple-team exercise into a 1v1 match. Red tries to own a Windows Active Directory domain; Blue tries to catch them doing it. The same telemetry that scores the attack also scores the defense — so at the end you can see exactly where each side won and lost.
Runs techniques against the AD target
Endpoints log every process, connection, and auth
Telemetry and alerts land in Elastic Security
Hunts, confirms, and contains the threat
Attacks and detections correlate on MITRE ATT&CK
→ the loop repeats every few seconds for the length of the match
One player creates a match and picks a scenario; the other joins with the 8-character match code from the lobby.
Choose Red (attacker) or Blue (defender). Both players ready up to start — you have a few minutes in the lobby to sort it out.
Red downloads a locked-down WireGuard config that reaches only the target subnet. Blue opens the Elastic Security console. The clock starts.
Red works the kill chain from their own box; Blue hunts the telemetry and responds. The scoreboard and technique feed update live for both sides.
When time runs out, the results page shows the full timeline, an attack replay, and a detection report — every technique, caught or missed.
Your job is to take the domain, and to do it quietly.
Your job is to see the attack coming and shut it down.
Red, attack. Each technique and objective that lands scores. Deeper kill-chain moves (credential dumping, DCSync) are worth more than recon.
Red, stealth. A bonus for every technique that expires undetected — staying quiet is the core offensive skill.
Red, impact. Disrupting a mission-critical service — ransomware, service stop — takes it offline and earns an impact bonus. The endgame of a real intrusion.
Blue, detection. Catching an attack scores — scaled by two things real SOCs are graded on: how fast you caught it (dwell time / MTTD) and how severe the alert.
Blue, containment. Isolating a host the attacker is actually on cuts their access — their next moves there are blocked — and earns a bonus. Precision beats panic.
Blue, availability penalty. Isolating or killing on a clean business-critical host is collateral damage — you bleed points until you release it. You can't win by locking everything down.
Blue, false positive. Chasing benign activity costs you. Confirm before you escalate.
every attack and detection is tagged with a MITRE ATT&CK technique — an attack and its detection correlate on the same ID, and that's what the scoreboard is built on.
The scoring rewards the way real operators actually work — so the shortcuts that would break a live engagement don't win here either.
Attacks against out-of-scope infrastructure — the range gateway, the scoring stack, your opponent — score nothing and are flagged as a foul. Hit the target, not the referee.
Replaying the same technique on the same host for easy points doesn't work — credit decays sharply on repeats. Progress the intrusion; don't grind one move.
Killing the EDR or clearing logs to farm stealth backfires: tampering earns no stealth bonus, auto-alerts Blue, and is flagged. Evade detection — don't disable it.
A match is 1v1, so you need a second player — one on Red, one on Blue. Decide who takes which side in the lobby. Red should have a Kali box (or preferred offensive tooling) ready to connect over the VPN; Blue just needs a browser for the Elastic console and the response panel.