Cybrary / SOC Range

Cyber resilience starts here.

Pick your environment, choose a scenario from the library, or talk it through with the range advisor. Every shell, tool and filesystem behaves like the real operating system — nothing here is a live machine.

Scenario library

Loading labs…

Spot the Failure

Ten short agent outputs, each carrying one classic failure artifact — hallucination, drift, bias, scope error, blast radius, injection — plus one that is simply correct. Build the vocabulary the rest of the Optiv path assumes.

foundationaloptiv custom Optiv windows + linux validatedAssessment

The Validation Gauntlet

You join the day shift of an MSSP tenant mid-stream. A triage agent fleet closed 30 cases overnight. Twenty-two are sound; eight are wrong in instructive ways, and one of the wrong ones is an active intrusion closed as benign.

intermediateoptiv custom Optiv windows + linux validatedAssessment

The Poisoned Queue

An adversary is writing to your triage agent, not to you. Instructions embedded in log fields and file metadata are closing true positives, and a decoy flood is eating the review budget. Recognise it, halt it at the right scope, and scope the campaign.

advancedoptiv custom Optiv windows + linux validatedAssessment

Surge

Six thousand alerts, two analysts, an agent fleet with degraded confidence, and an executive who wants a number. You will not review everything. You are graded on how you choose what not to review — and on whether the real incident hiding in the flood gets found.

advancedoptiv custom Optiv windows + linux validatedAssessment

Range Guide

Ask or talk about the labs — I'll suggest where to start.

Tell me your experience level and what you want to get better at — brute force triage, beaconing, lateral movement, exfil — and I'll pick a lab and launch it for you.

OOptivCustom track

Optiv Custom Scenarios

Human-in-the-loop oversight of AI security agents — catch hallucinated evidence, scope drift, bias and prompt injection, then hold the line with a moody virtual team.

  • CP1-L0Spot the Failure

    Ten short agent outputs, each carrying one classic failure artifact — hallucination, drift, bias, scope error, blast radius, injection — plus one that is simply correct. Build the vocabulary the rest of the Optiv path assumes.

    foundational 60 min10 cases
  • CP1-L1The Validation Gauntlet

    You join the day shift of an MSSP tenant mid-stream. A triage agent fleet closed 30 cases overnight. Twenty-two are sound; eight are wrong in instructive ways, and one of the wrong ones is an active intrusion closed as benign.

    intermediate 240 min30 cases
  • CP1-L3 / SP3-L1The Poisoned Queue

    An adversary is writing to your triage agent, not to you. Instructions embedded in log fields and file metadata are closing true positives, and a decoy flood is eating the review budget. Recognise it, halt it at the right scope, and scope the campaign.

    advanced 180 min46 cases
  • CP4-L2Surge

    Six thousand alerts, two analysts, an agent fleet with degraded confidence, and an executive who wants a number. You will not review everything. You are graded on how you choose what not to review — and on whether the real incident hiding in the flood gets found.

    advanced 150 mincommand sim

Optiv custom scenario · delivered on Cybrary SOC Range

Cybrary SOC Range · Simulated environment · No real systems are touched