A cyber range inside your own jurisdiction
RangeAX gives agencies, CERTs and academies a range that runs on their own premises. Live-fire exercises, capture-the-flag and attack–defence events, OT/ICS digital twins, threat-intelligence and digital-forensics tracks all run on isolated cyber terrain, and every action is recorded in an audit ledger.
Three surfaces, one core
The Range Console is the web cockpit for tenant operators: exercise planning, curriculum, sandbox pools and reporting. The Control Plane is the administrator and operator view across tenants, host fleet, licensing and ledger height, showing aggregates only and never tenant content. The Participant Workspace is a progressive web app that follows trainees onto laptops and phones. Beneath all three sit orchestration, identity with role-based access, the scenario store and the audit ledger.
EXCON: live exercise control
Exercise controllers work from one view that holds phase control, the inject queue, a safety panel and the state of every team. Defenders work in a blue-team workspace with the SOC stack in front of them, and the after-action review replays the exercise from the record.
Sandboxes as code
Hosts, networks and sensors are defined as signed, pinned code. Each team receives its own sandbox on its own VLAN, with a jump host, user endpoints, domain identity, the target application and a SOC stack with SIEM and network intrusion detection. Sandboxes clone from a reserved pool at exercise start and are wiped at the end.
Multi-tenant, isolated by design
One deployment serves several tenants, with identity, access control, scenario store and audit ledger scoped per tenant. An agency, a CERT and an academy can share a host fleet without sharing terrain or records.
Curriculum with entry gates and exit artefacts
Twelve teaching tracks take participants from foundations to live-fire defence. Each track states what a participant must show to enter and what artefact they leave with, so assessment rests on evidence rather than attendance.
Air-gapped, no egress
A public internet link is optional and never required. There is no telemetry egress, identity can run on local accounts or federate with yours, and break-glass access needs two people. The range, its scenarios and its records stay on your premises.
