2025.1
This release enhances training with an interactive quiz, improves visibility on attack indicators, and introduces a brand-new attack scenario.
Lab Enhancements
- Interactive quiz interface within labs, to support self-paced learning. It challenges learners on their understanding of the attack they just analyzed, making training sessions more dynamic and engaging.
- New IoC view in each lab, providing clear visibility into the traces left by an attack (IP addresses, files, registry keys, and more). This makes it possible to compare what defenders understood with the actual indicators left by the adversary emulation engine.
- Added a confirmation prompt before stopping a lab.
- Renamed Attack graph to Attack report, and General information to Information.
- Removed the Stop button from the learner (public) view.
- Removed attack infrastructure nodes from the learner view.
Scenarios
- New attack scenario Certifombre, built on a Windows environment with a domain controller and ADCS (PKI) components at its core.
Adversary Emulation
- Improved stealth of generated binaries, with more realistic naming.
- Updated internet IP ranges across several scenarios, for better variability.
User Activity
- Improved life orchestrator, which now continues life actions after an attack scenario ends and better handles virtual machine reboots.
Platform Upgrades
- New
/statuspage displaying API version information, for better transparency and operational visibility.

