← Docs
Get started

Getting started with GraphLattice Range

What GraphLattice Range is, who it is for, and how to run your first incident-response scenario.

GraphLattice Range is a hands-on incident-response simulation. Instead of reading about an attack, your team works it end to end: detect it, contain it, eradicate it, investigate it, and recover, while the clock runs and a decision-maker asks for answers.

Who Range is for

Range is built for the people who respond to real incidents:

  • SOC and incident-response analysts who want repetitions on identity and cloud attacks.
  • Blue teams validating detection and response playbooks against documented techniques.
  • MSSPs training analysts at scale on the attacks they will actually face.
  • Security leaders who want to see how their team performs under pressure before a real incident.

What you train on

Every scenario is a documented, real-world attack across the identity attack surface and the cloud and SaaS it pivots into: Active Directory, Entra ID, Microsoft 365, Intune, AWS, Azure, GCP, Okta, and Snowflake. Identity first, then the pivot into cloud and data. See the scenario library for the full coverage.

Your first scenario, step by step

  1. Request access from the early-access page. Range is in early access and we set up a guided session for your team.
  2. Open the guided demo to see how a scenario and the incident-response loop work before you start.
  3. Pick a scenario that matches a threat you care about, for example a stolen session token or a Kerberoasting incident.
  4. Work the loop. Move through detection, containment, eradication, forensics, and recovery, making the calls the incident demands.
  5. Review your score and the decision-by-decision feedback, then run it again or move to the next scenario.

What you get out of it

A score on each decision, feedback grounded in how these attacks actually behave, and a completion record. See scoring and the graph for how decisions are graded and certificates and badges for what you can show afterward.

Next steps