GraphLattice Range™, free to start
Rehearse the incident you will actually get.
The breach you get starts with an identity, then pivots into your cloud and data. GraphLattice Range lets your team work those exact incidents end to end, scored on a real identity and cloud graph model.
AI drafts each scenario from live threat intelligence, an expert approves it, and your team trains on it.
New to incident-response training? See how it works →
13 free scenarios, refreshed every month. No credit card.
What Range gives you
Real attacks, full loop
Every scenario is a documented attack across AD, Entra, M365, Intune, AWS, Azure, GCP, Okta, and Snowflake. You run detection, containment, eradication, forensics, and recovery.
Train the way you defend
Decisions are scored on a real identity and cloud graph model, the way these attacks actually unfold, so you learn the model attackers exploit, not a multiple-choice quiz.
Always current
Scenarios are drafted from live threat intelligence and published after review, so the library tracks what is actually being exploited.
How we build
AI-first. Automation-first. Human in the loop.
We build the way we believe security should run. AI and automation do the heavy lifting, and a person makes the call. The work reaches you fast and still earns your trust.
AI-first
AI drafts every scenario from live threat intelligence, so the library moves at the speed attackers do, not the speed of a content calendar.
Automation-first
Drafting, validation, and staging run end to end as a pipeline. A newly exploited technique becomes a trainable scenario in days, not quarters.
Human in the loop
A practitioner reviews and approves every scenario before it ships. Nothing reaches your team unreviewed, and you decide what counts as the correct response.
Free to start
Start free. Stay free.
GraphLattice Range has a free Community Edition that stays free, so anyone can start training today. No credit card, no waiting.
13 free scenarios, a new set every month.
- 13 free scenarios right now - one from every platform, refreshed monthly: AD, Entra, M365, AWS, Azure, GCP, Okta, SaaS, Insider Risk, and more
- The full IR loop: detect, contain, eradicate, investigate, recover
- Decisions scored on the identity and cloud graph model
- Debrief, achievements, and a completion certificate
- Play at your own pace, with progress saved automatically
- No credit card
FAQ
Frequently asked
What is GraphLattice Range?
GraphLattice Range is a hands-on incident-response simulation, a cyber range, where security teams rehearse real, documented identity and cloud attacks end to end. Every scenario runs the full incident-response loop and includes the decisions a CISO makes under pressure.
Who is GraphLattice Range for?
SOC and incident-response teams, blue teams, and MSSPs training analysts, plus the security leaders who run the response. Scenarios suit both hands-on responders and CISO-level decision-makers.
What attacks and platforms does it cover?
Identity-first attacks and the cloud and SaaS they pivot into: Active Directory, Entra ID, Microsoft 365, Intune, AWS, Azure, GCP, Okta, and Snowflake. Every scenario is a documented, real-world technique mapped to MITRE ATT&CK.
How does a scenario work?
You work a documented attack through the full incident-response loop, detection, containment, eradication, forensics, and recovery, making the same calls a real response demands. Your decisions are scored as you go.
How are scenarios scored?
Decisions are scored on a real identity and cloud graph model, the way these attacks actually unfold, so you learn the model attackers exploit rather than memorizing answers.
Is there a free version, and how do I get access?
GraphLattice Range is live and free to start, with free scenarios refreshed every month and no credit card required. Enter your email to create your free account and start your first scenario.
Start free
Create your free account
GraphLattice Range Community Edition is free, no credit card. Enter your email to create your free account and start your first scenario.