Spot the Failure
Ten short agent outputs, each carrying one classic failure artifact — hallucination, drift, bias, scope error, blast radius, injection — plus one that is simply correct. Build the vocabulary the rest of the Optiv path assumes.
Pick your environment, choose a scenario from the library, or talk it through with the range advisor. Every shell, tool and filesystem behaves like the real operating system — nothing here is a live machine.
Scenario library
Loading labs…
Ten short agent outputs, each carrying one classic failure artifact — hallucination, drift, bias, scope error, blast radius, injection — plus one that is simply correct. Build the vocabulary the rest of the Optiv path assumes.
You join the day shift of an MSSP tenant mid-stream. A triage agent fleet closed 30 cases overnight. Twenty-two are sound; eight are wrong in instructive ways, and one of the wrong ones is an active intrusion closed as benign.
An adversary is writing to your triage agent, not to you. Instructions embedded in log fields and file metadata are closing true positives, and a decoy flood is eating the review budget. Recognise it, halt it at the right scope, and scope the campaign.
Six thousand alerts, two analysts, an agent fleet with degraded confidence, and an executive who wants a number. You will not review everything. You are graded on how you choose what not to review — and on whether the real incident hiding in the flood gets found.
Range Guide
Ask or talk about the labs — I'll suggest where to start.
Tell me your experience level and what you want to get better at — brute force triage, beaconing, lateral movement, exfil — and I'll pick a lab and launch it for you.
Human-in-the-loop oversight of AI security agents — catch hallucinated evidence, scope drift, bias and prompt injection, then hold the line with a moody virtual team.
Ten short agent outputs, each carrying one classic failure artifact — hallucination, drift, bias, scope error, blast radius, injection — plus one that is simply correct. Build the vocabulary the rest of the Optiv path assumes.
You join the day shift of an MSSP tenant mid-stream. A triage agent fleet closed 30 cases overnight. Twenty-two are sound; eight are wrong in instructive ways, and one of the wrong ones is an active intrusion closed as benign.
An adversary is writing to your triage agent, not to you. Instructions embedded in log fields and file metadata are closing true positives, and a decoy flood is eating the review budget. Recognise it, halt it at the right scope, and scope the campaign.
Six thousand alerts, two analysts, an agent fleet with degraded confidence, and an executive who wants a number. You will not review everything. You are graded on how you choose what not to review — and on whether the real incident hiding in the flood gets found.
Optiv custom scenario · delivered on Cybrary SOC Range
Cybrary SOC Range · Simulated environment · No real systems are touched