Doctrine
Three layers. One engagement.
Every CyberRange scenario is organised around the same three doctrine layers. They are not difficulty levels — they are three ways of looking at the same fight: how you think, how you execute, and who you're really up against.
Layer 01 · WAR
Strategy
How you think about the engagement.
WAR is the doctrine layer. Before a single command runs, the engagement is already being won or lost in how you frame it — what you protect, what you're willing to lose, and where you choose to fight. It rewards operators who plan the kill chain instead of reacting to it.
Shows up as
- Kill-chain thinking
- OODA loops under time pressure
- Defence-in-depth and choke-point selection
Layer 02 · Ethical Hacking
Craft
How you execute.
Ethical Hacking is the tactics layer — the hands-on technique that turns a plan into pressure on a real machine. This is where strategy meets the keyboard: enumeration, exploitation, lateral movement, and the defensive counter-moves that blunt them, all on isolated systems against a live opponent.
Shows up as
- Kerberoasting and credential abuse
- IMDSv2 misuse and cloud metadata attacks
- AWS IAM lateral movement and privilege escalation
Layer 03 · Cyber Crime
Threat
Who is doing what, in the real world, right now.
Cyber Crime is the threat layer — the reason any of this matters. Our scenarios are modelled on real adversaries and real incidents, so the muscle you build in a match maps to the campaigns your organisation actually faces. You don't train against an abstraction; you train against the playbook in use this quarter.
Shows up as
- Akira ransomware targeting Veeam consoles
- Volt Typhoon dwelling in US utilities
- The actors and TTPs each scenario is built from
Every scenario carries all three
The six CyberRange domains aren't sorted into layers — each one runs on all three at once. You bring the strategy (WAR), execute the craft (Ethical Hacking), against a threat drawn from the real world (Cyber Crime). The AI Coach reviews your match through the same three lenses.
- IoT & semiconductor
- Digital forensics
- Cloud & zero-trust
- Adversarial AI
- Red & blue automation
- SCADA / ICS
Request access →
See the scenarios
Attack. Defend. Repeat.