Live SIEM · ATT&CK-mapped

Get real blue-team reps on live, breached networks.

PlayForge Cyber spins up a real Active Directory environment, runs a real attack against it, and drops you into the SOC to detect, investigate, and respond — all in your browser. No lab to build. No $8,000 course. No enterprise price tag.

elastic-security — live session
14:32:07T1566.001Phishing attachment opened
14:32:41T1558.003Kerberoasting — svc_sqlFOUND
14:33:02T1021.002Lateral movement → FILE-SRV01
14:33:55T1048Exfiltration attemptBLOCKED
14:34:12T1078Valid accounts — persistence
14:34:48T1003.001LSASS memory accessFOUND
14:32:07T1566.001Phishing attachment opened
14:32:41T1558.003Kerberoasting — svc_sqlFOUND
14:33:02T1021.002Lateral movement → FILE-SRV01
14:33:55T1048Exfiltration attemptBLOCKED
14:34:12T1078Valid accounts — persistence
14:34:48T1003.001LSASS memory accessFOUND

Certs teach theory. Attacks don't care what you memorized.

Most training tops out at slides and multiple-choice. The one thing that actually builds a defender — working a live incident with real telemetry in front of you — is locked behind expensive courses or enterprise platforms priced per seat. So analysts learn to detect breaches for the first time during an actual breach.

PlayForge Cyber closes that gap.

How it works

01

Launch a scenario.

Pick a scenario and hit go. We deploy a real Windows/AD network wired to an Elastic SIEM — no setup, no VPN, straight in your browser.

02

A real adversary strikes.

An automated threat actor runs a genuine attack chain against the environment — phishing, credential theft, lateral movement, exfiltration — generating authentic telemetry, not canned logs.

03

You defend, and get scored.

Hunt through the SIEM, reconstruct the kill chain, identify what was hit, and contain it. Every detection and objective is graded automatically against exactly what the attacker did.

Why PlayForge

Blue-team first

Purpose-built for detection, investigation, and incident response — not just capture-the-flag hacking. The reps employers actually hire for.

Real telemetry, auto-graded

The attack is scripted, so we know precisely what happened. You get an objective score and a breakdown of what you caught and what you missed — no waiting on a human grader.

Mapped to ATT&CK

Every scenario is built on real MITRE ATT&CK techniques, so your practice maps to the framework the whole industry speaks.

Priced for humans

Enterprise realism without enterprise pricing. Start free; go pro for less than the cost of one course textbook.

From commodity intrusions to nation-state campaigns.

Operation Silverfish

Intermediate

A phished workstation leads to AD recon, a Kerberoasted service account, lateral movement to the file server, and payroll exfiltration. Reconstruct it from Elastic and contain patient zero.

First Light

Beginner

Your first live incident: catch a suspicious logon and a malicious macro before they spread.

Deep Harbor

Advanced

A slow, low-and-slow intrusion that hides in normal traffic. Can you find it before exfil?

New scenarios added regularly. Premium tier: on-the-fly generated campaigns attributed to distinct threat actors — a new landscape, a new way in, and new TTPs every time.

Start free. Upgrade when you're hooked.

Real breaches. Real telemetry. Real reps.

Free

Trying it out

$0

  • · 1 starter scenario
  • · Unlimited replays of the starter scenario
  • · Auto-graded scoring
  • · Basic progress tracking

Pro

Serious individual practice

$29/mo

  • · Full scenario library
  • · Unlimited sessions*
  • · Auto-graded scoring
  • · Full progress & ATT&CK tracking
  • · Generated campaigns (add-on)

Team

SOC & CSSP teams

$25/user/mo

  • · Everything in Pro
  • · Private scenarios
  • · Team dashboard
  • · Admin controls & SSO

Built by people who run real SOCs.

PlayForge Cyber is early — every scenario is authored by an active CSSP practitioner, not licensed from a template library. Beta feedback and case studies land here as they come in.

Your next incident shouldn't be your first.

Spin up a live breach and start defending in minutes.