← Docs
Using Range

The scenario library

What Range covers today: identity-first attacks across AD, Entra ID, M365, Intune, AWS, Azure, GCP, Okta, and Snowflake, drafted from documented incidents.

Range scenarios are documented, real-world attacks. Each one is built around the identity attack surface and the cloud and SaaS it unlocks. New scenarios are drafted from live threat intelligence and published after expert review, so the library tracks what is actually being exploited.

Active Directory

DCSync, Kerberoasting, AS-REP roasting, Golden Ticket, Kerberos delegation abuse, NTLM relay, AD CS ESC1 and ESC8, Zerologon, Group Policy ransomware, and post-compromise persistence such as AdminSDHolder and DCShadow.

Entra ID, Microsoft 365, and Azure

Device code phishing, MFA fatigue, OAuth app and consent abuse, Primary Refresh Token theft, Conditional Access bypass, service principal credential persistence, Golden SAML and federation abuse, Entra Connect hybrid abuse, BEC inbox rules, Azure Run Command, Azure RBAC escalation, and managed identity abuse.

AWS, GCP, and SaaS

SSRF to cloud credentials, IAM privilege escalation, S3 exposure and exfiltration, leaked access keys, CloudTrail tampering, GCP service account impersonation, Okta support HAR session theft, Okta Super Admin abuse, and Snowflake stolen-credential data theft.

Cross-cutting

Identity attacks that span surfaces, such as stolen session and token theft, help desk social engineering, and the executive decisions in ransomware and extortion incidents.

How scenarios stay current

Every scenario maps to a documented technique or incident. As new attacks emerge, we draft new scenarios from threat intelligence and review them before they go live. The public writeups for many of these are on the blog.

Want a specific scenario?

If there is an attack your team needs to rehearse, tell us when you request access. We prioritize the library around what responders are actually facing.