Loading...
Cybersecurity. Redefined.
Loading...
Loading services...
Apsispoint AI-CyberRangeX
A hands-on program in two disciplines: building defensive AI agents that investigate and respond to incidents, and building offensive red team agents that emulate the adversary. Cyber range exercises put a student's own attack agent against their own defense — and grade the result.
Apsispoint
AI-CyberRangeX
Cyber Range Platform
Two engineering disciplines and the exercise that tests them. Students who only ever build the defense never learn what the offense actually produces.
Defensive
Students build the agents that carry an incident: triage an alert, gather and weigh evidence, reconstruct what happened, and propose containment. The engineering discipline is the point — how you define an agent's tools, ground it in real evidence, and bound what it is allowed to decide alone.
Offensive
Students build agents that emulate adversary tradecraft — chaining reconnaissance, credential access, movement, and objective under their own direction. Building the offense is how you learn what it actually produces, and therefore what a defender can catch.
Exercised
The two builds meet under exercise conditions: a student's red agent runs while their defensive agent works the incident it creates. Facilitated, time-boxed, and debriefed — the exercise is where agent engineering stops being theory and gets graded.
Before any security work: what an agent actually is. Tool definitions, the investigate-decide-act loop, grounding output in verifiable evidence, handling uncertainty, and where autonomy must stop. Students who skip this build agents that sound confident and are wrong.
Students develop their defensive IR agents module by module — alert triage and enrichment, evidence collection, timeline reconstruction, and a containment recommendation a human can audit and overrule.
The same students then develop red team agents: planning an emulation against a MITRE ATT&CK-mapped objective, chaining techniques, and documenting the detection opportunity each step leaves behind.
Facilitator-driven cyber range exercises put the builds head to head. Red agents execute, defensive agents respond, instructors observe and inject pressure. Everything is recorded for the debrief.
A hot-wash immediately after, then a formal after-action review. Students close the loop by writing the detections their own attack evaded, then re-running the attack to prove the detection fires.
Every module ends with a working agent the student built and defended in an exercise. Curricula are tailored per cohort; these are the core modules.
Build an agent that takes a raw alert, enriches it with host, identity, and network context, and returns a verdict with cited evidence. Students learn to make the reasoning auditable — and to recognise a confident wrong answer.
Move from single-alert triage to reconstructing an incident: correlating events across sources, establishing sequence and root cause, and assembling the narrative an analyst or executive can act on.
Response is where autonomy gets dangerous. Students build agents that recommend and stage containment, with explicit human-approval gates, blast-radius checks, and rollback — plus the judgement to know which actions must never be automated.
Develop red team agents that pursue an objective rather than replay a script — selecting the next technique from what they discover, and mapping every action to MITRE ATT&CK so the exercise produces a usable coverage record.
The loop that closes the two disciplines: take the telemetry a student's own red agent produced, write the analytic that catches it, then re-run the attack to prove the detection fires and measure what it still misses.
Prompt injection, poisoned evidence, over-broad tool permissions, and unsafe autonomy. Students learn to attack their own agents — because an agent inside your SOC is itself an attack surface.
Emulation plans and detections are mapped to technique IDs students can cite
Incident-handling lifecycle the defensive agent modules follow end to end
Preparation through Lessons Learned — the loop each exercise closes
Agent safety, prompt injection, and autonomy limits taught alongside the build
Three things, in this order. First, defensive IR agent development: building AI agents that triage alerts, gather and weigh evidence, reconstruct an incident, and propose containment. Second, offensive red team agent development: building agents that emulate adversary tradecraft against an authorized target. Third, cyber range exercises that put the two against each other — a student's own attack agent runs while their own defensive agent works the incident it creates. The program is agent engineering taught through security work, not a tools course.
Because you cannot reliably detect what you have never watched operate. Adversaries are already using AI to accelerate reconnaissance, credential access, and lateral movement, and defenders who have only ever built the blue side tend to write detections for the attack they imagined rather than the one that runs. Building the offense is what makes the defense credible: every offensive module ends by documenting the detection opportunity each step leaves behind, and the exercise phase forces the student to catch their own attack.
No AI experience is required — the program starts with agent foundations from first principles: tool definitions, the investigate-decide-act loop, grounding output in verifiable evidence, handling uncertainty, and where autonomy has to stop. Comfort with a scripting language helps, since students are genuinely writing and debugging agents rather than configuring one. We calibrate depth and pacing to the cohort during scoping.
Yes, and it is a design constraint rather than a policy note. Offensive agents only ever run against the isolated targets assigned to that student's exercise, never against production or third-party systems, and never against another student's work without an explicit exercise design. Authorization is acknowledged before any offensive module, actions are recorded, and instructors supervise the exercise phase. Students also learn where the boundaries come from — legal, ethical, and operational — because that judgement is part of the discipline.
A tools course teaches you to operate someone else's agent. This teaches you to build one that holds up under incident conditions: what its tools are allowed to do, how it cites evidence, how it behaves when the data is ambiguous or poisoned, which decisions must route to a human, and how it fails. A dedicated module has students attack their own agents — prompt injection, poisoned evidence, over-broad tool permissions — because an agent inside a SOC is itself an attack surface.
Three audiences. University and college programs teaching security operations who want students building real agents rather than reading about them. SOC teams upskilling analysts on agent-assisted investigation and response before adopting it in production. And organizations onboarding new security hires who need investigative instincts and AI fluency at the same time. Cohort size, discipline mix, and schedule are set per engagement.
The defensive and offensive agents they built, the detection analytics they wrote and then proved against a live attack, a MITRE ATT&CK-mapped record of the techniques they emulated and detected, and their exercise results. For academic cohorts we also provide instructor-facing progress visibility and a completion summary per student.
Different goal. A cyber range exercise engagement validates an existing IR team's response capability against a scenario — an assessment for practitioners already doing the job. AI-CyberRangeX is a development program: it teaches individuals to engineer defensive and offensive AI agents, and uses exercises to test what they built. Teams often do both — train the analysts here, then pressure-test the team with a full live-fire exercise.
30-minute call to scope your cohort. You leave with a curriculum outline across the three disciplines, a schedule, and a fixed price — whether you're training a university class, a SOC team, or new hires.