FAQ

Frequently asked questions

What GraphLattice Range is, what it covers, and how it works. Still have a question? Ask us.

What is GraphLattice Range?

GraphLattice Range is a hands-on incident-response simulation, a cyber range, where security teams rehearse real, documented identity and cloud attacks end to end. Every scenario runs the full incident-response loop, detection, containment, eradication, forensics, and recovery, and includes the decisions a CISO makes under pressure.

Who is GraphLattice Range for?

SOC and incident-response teams, blue teams, and MSSPs training analysts, plus the security leaders who run the response. Scenarios suit both hands-on responders and CISO-level decision-makers.

What identity and cloud platforms does Range cover?

Active Directory, Entra ID, Microsoft 365, Intune, AWS, Azure, GCP, Okta, Snowflake, and GitHub. Range is identity-first: it starts with the identity attack and follows it into the cloud and SaaS it unlocks.

What identity attacks can Range simulate?

Documented, real-world techniques including Kerberoasting, DCSync, AdminSDHolder abuse, Golden Ticket and Golden SAML forgery, pass-the-hash and pass-the-ticket, AD CS abuse, device-code phishing, primary refresh token theft, OAuth consent abuse, service-account and app-credential persistence, and cloud privilege escalation. Every scenario is mapped to MITRE ATT&CK.

How does a Range scenario work?

You work a documented attack through the full incident-response loop, making the same calls a real response demands at each phase, from first detection to recovery. Your decisions are scored as you go, and a debrief shows what a strong response looks like.

How are scenarios scored?

Decisions are scored on a real identity and cloud graph model, the way these attacks actually unfold, so you learn the model attackers exploit rather than memorizing answers.

How is Range different from a CTF or a traditional cyber range?

Range is identity-first and response-focused. Instead of flag-hunting or generic network puzzles, you run the incident-response loop on documented identity and cloud attacks, score against a graph model of how the attack really works, and make the leadership calls a live incident forces. The library is drafted from live threat intelligence, so it tracks what is actually being exploited.

Is Range free? How much does it cost?

Range is live and free to start, with free scenarios refreshed every month and no credit card required. Enter your email to create your free account and start your first scenario.

Do I need to install anything?

No. Range runs in the browser. There is nothing to deploy and no agent to install to train.

Can my whole team use it together?

Yes. Range includes team and presenter modes so a facilitator can drive a session while responders work the same scenario, with completion certificates and competency badges.

How current is the content?

Scenarios are drafted from live threat-intelligence feeds and reviewed by a practitioner before publishing, so the library reflects the techniques being exploited now, not a static syllabus.