2026.08
This new version of M&NTIS Platform focuses on three axes: a brand-new cloud attack scenario, a completely redesigned live lab interface, and the opening of the public REST APIs with generated references and developer guides.
Scenarios also become configurable: a lab can now be parameterized at launch time (credentials, tenant, use case), which makes it possible to replay the same scenario against different environments without rebuilding it.
New Scenario: Nebulyx
- Introduction of Nebulyx, a new cloud / Microsoft Azure attack scenario, covering the full chain from initial provisioning to credential theft on cloud-joined workstations.
- New Azure baseboxes and a set of dedicated redteam workers for cloud-oriented techniques.
- A complete preparation guide is available, describing the Azure account to create, the role to assign, the mapping between scenario parameters and accounts, and the cleanup required before replaying the scenario.
Test tenant only
Nebulyx interacts with a real Azure tenant. It must only be run against a dedicated test tenant, never against a production one.
Lab Experience
- New live lab interface, redesigned around the ongoing exercise.
- New interactive view page, with a streamlined layout for the interaction viewer.
- The quiz can now be disabled on a lab, for use cases where assessment is not relevant.
Scenario Configuration and Status
- Introduction of scenario parameters: a scenario can now declare configurable inputs (accounts, tenants, targets) that are provided at lab creation and propagated to provisioning, user activity and redteam workers.
- Lab configuration now carries an explicit use case, aligning the lab with its training intent.
- Renaming of the evaluation concept to assessment across the platform, for consistency between the API, the models and the interface.
- Notifications: added a notification reporting the execution duration of a lab content; attack details are no longer disclosed to learners in notifications.
REST APIs and Documentation
- Publication of the Scenario API and Redteam API reference documentation, generated automatically and browsable directly from the documentation site.
- New REST API developer guides, available in English and French, covering authentication, lab execution and redteam operations. See REST API.
- The Scenario and Redteam APIs now enforce strict input and output validation, producing clearer and more predictable error messages for API consumers.
Content Updates
- New provisioning playbooks and user activities, including improved proxy configuration (dynamic node targeting, conditional GPO deployment, Windows filtering and bypass lists).
- Added Kibana and Graylog signatures for the Lumidus scenario.
- Numerous redteam worker improvements: new credential-related capabilities, better handling of lateral movement, and more reliable secret extraction.

