Docs
GraphLattice Range documentation
How Range works and how to get the most out of it: guides for new users, reference for admins, and a glossary of the attacks you will train on.
Get started
Getting started with GraphLattice Range
What GraphLattice Range is, who it is for, and how to run your first incident-response scenario.
Read →How Range works: the incident-response loop
Every scenario runs the full IR loop, detection through recovery, plus the leadership decisions. Here is what each phase asks of you.
Read →Using Range
How scoring works: the identity and cloud graph
Range scores your decisions on the same identity and cloud graph model used to detect these attacks in production. Here is what that means.
Read →The scenario library
What Range covers today: identity-first attacks across AD, Entra ID, M365, Intune, AWS, Azure, GCP, Okta, and Snowflake, drafted from documented incidents.
Read →Team and presenter modes
Run Range solo, as a team exercise, or led from the front of the room. Here is how the multi-user modes work.
Read →Certificates and badges
What you can show after completing Range scenarios: enterprise-class certificates, competency badges, and team tracking.
Read →Reference
Platform security and data handling
How the Range platform protects your data, and why training never requires connecting it to your production identity systems.
Read →Frequently asked questions
Quick answers about what Range is, what it covers, how scoring works, and how to get access.
Read →Glossary of identity and cloud attacks
Plain-language definitions of the attacks and terms you will meet in Range, from DCSync to Golden SAML to managed identity abuse.
Read →