We’re pleased to announce M&NTIS Platform v26.9, a release built around two axes: Wazuh joins the detection loop, with signatures deployed and alerts collected automatically; and a new GoAD-Mini topology, a ready-made vulnerable Active Directory to attack.
Lab creation has also been redesigned.
⭐ Key Highlights
Wazuh Joins the Detection Loop
Since v26.6, M&NTIS deploys the detection signatures of a lab’s attacks to Kibana, Splunk and Graylog, then collects the resulting alerts and correlates them with the attack steps. Wazuh now works the same way.
- Before the attacks run, the lab’s detection signatures are
deployed automatically as Wazuh local rules,
grouped under the name
mantisso their alerts stand apart from those raised by the default ruleset. - The alerts they raise are collected back into M&NTIS and correlated with the attack steps, just as they are for the other SIEMs.
- The first Wazuh signatures are available for the Venopie, Vesperlyn and Lumidus scenarios.
- The Wazuh manager basebox moves to Wazuh 4.14.7.
Alert correlation is also stricter. An alert is now linked to an attack step only when the two overlap in time and concern the same host, and each link states how it was established, so a confirmed detection can be told apart from a coincidence in time.
Redesigned Lab Creation
Creating a lab from a scenario, an attack, a topology or a basebox now follows a single, redesigned flow:
- a breadcrumb showing where the lab comes from, and an address that matches it;
- a flat step-by-step layout, with no nested cards;
- option cards for the choices that matter: use case, execution mode and defensive stack.
New Topology: GoAD-Mini
- Introduction of GoAD-Mini, a topology
built on Game of
Active Directory: a domain controller for
sevenkingdoms.local, preconfigured with the users, groups, ACLs, ADCS templates and planted weaknesses of the upstream lab, alongside a Kali machine to attack it from. - It serves trainees following an Active Directory attack walkthrough, and red teams or tool developers who want to test offensive techniques and capabilities against a realistic, deliberately vulnerable domain. Both the target and the machine to attack it from are provided.
- A new Kali 2026.2 (Xfce) attacker basebox is also available.
📋 Other Release Changes
Interface
- A lab’s closing notification now appears without reloading the page.
- Signatures with several implementations (one per telemetry stack) are now displayed as soon as one of them matches the lab’s stack. Until now, such a signature could not be shown by any lab.
- The lab list polls every watched status in a single request instead of one per status, which removes most of the traffic on that route.
Red Team
- An attack session marked down because its beacon was busy on a long command now comes back up as soon as the beacon checks in again, instead of staying down for the rest of the lab.
Scenarios and Content
- More reliable Active Directory provisioning: transient WinRM faults are retried, stale computer accounts are removed before a domain join, and the proxy GPO waits for Active Directory to be ready.
- Guacamole RDP connections keep the desktop wallpaper.
- User activity fixes on French Windows desktops.
For API Consumers
- The lab list now accepts a repeated
statusparameter (?status=A&status=B), so several statuses can be listed in one request. A singlestatuskeeps working as before. - Each alert in the lab report carries a new
correlated_attacks_confidencefield, giving per attack step eitherhost_time(time windows and host both matched) ortime_only(no host information on either side). Count onlyhost_timeas a confirmed detection.
M&NTIS v26.9 extends automated detection to Wazuh, so the alerts raised by its rules now sit next to the attack steps that triggered them, and GoAD-Mini adds a vulnerable Active Directory for both training and offensive testing.