New — Rogue Oracle: the AI built into the platform designs and builds your range end-to-end. Or bring your own via MCP. See how it works →

Agent VM Harness — point Claude, Codex, or your own agent at a live range over 150+ MCP tools. Explore the harness →

Train with your team — shared scenarios, live cursors, and mock simulations shoulder to shoulder. See Team Hub →

AI model testing — deny-all multi-host ranges scored by Inspect. See model testing →

Build your enterprise lab from a prompt.

Write a prompt and Rogue Oracle builds a full “lived-in” enterprise network — small scenarios in minutes, sprawling multi-forest ranges while you grab lunch.

Now you’re ready for AI model testing or your own team training.

Built on the same trusted platform that's served our Red Team customers for years.

Platform Features

Build any lab you want. We do it all.

Red team, blue team, tool testing, or AI agent evals. Spin up the exact enterprise network you need and put anything through its paces.

01 — Rogue Architect AI

Type a Prompt. Get a Scenario

Describe what you want; your favorite LLM builds it. Topology, AD forests, characters with backstories, seeded files, multi-hop exploit chains — all drafted from a single prompt and provisioned through Architect. Curriculum and plugins, same way.

Explore Architect AI
02 — Tool Test Harness

Agent VM Harness

Agents fan out across your range with everything they need to fully control a VM: click, type, screenshot, upload and download files, run scripts, and query logs. Point them at blue team TTPs, red team TTPs, or full model evals.

Explore the AI Red Team Lab
03 — Window System

Persistent Desktop Access, Zero Friction

Full graphical console access to every machine in your scenario. Resize, rearrange, simultaneously view with a teammate, and multitask across VMs like native desktops — no RDP clients, no janky VNC.

Explore the Window System
04 — File Management

Drag. Drop. Done.

Drag payloads, scripts and 3GB+ files straight into any VM, and download files just as easily. Browse the full hard drive of any machine in your scenario from one file browser. No SCP gymnastics. Team and personal vaults included.

Explore File Management
05 — VPN Access

Your Tools. Their Network.

Connect your local machine directly into any Rogue Arena scenario via OpenVPN. Run Burp, Ghidra, Bloodhound, or any tool from your own setup — routed straight into the target environment.

Learn About VPN Access
06 — Curriculum Browser

Guided Learning, Built Into the Range

Follow structured courses and walkthroughs right inside the live range. No tab-switching between docs and labs — learners work where the lesson happens.

Ready to build your own? Drag and drop it together, or let Rogue Oracle author the whole course — chapters, questions, diagrams, and images.

Browse Curriculum
07 — Team Hub

Train with your Team

Build together with live cursors and presence, then share scenarios and run mock training simulations shoulder to shoulder for training or certification. A team dashboard tracks who's on what machine, skill growth, and weekly progress.

Explore Team Features
Operate

Point an agent at the range. Walk away.

Hand your deployed cyber range scenario to an agent driving 150+ MCP tools. It runs commands, screenshots, moves payloads, and grinds long-horizon tasks across every VM while you make the calls.

Bring any agent. We're the harness.

Claude, Codex, Grok, or an offline model. Connect it over the open MCP harness and drive the whole fleet. No lock-in, no built-in model tax.

One harness, every VM.

The same MCP interface drives Windows, Linux, and AD boxes across the range. Drive in-browser when you want to, headless when the agent does.

Automate everything.

  • Red team tool dev against live, instrumented targets
  • Deploy and test internal products in realistic scenarios
  • Overnight TTP loops and multi-host attack chains
  • Detection regression runs on every rule change

What's in the box.

Build the range. Then operate inside it with agents.

HoverTap any tile for the details.

// HOVERTAP TO FLIP

Build by prompt or canvas.

+

Build by prompt or canvas

Describe it in a prompt or drag-and-drop on the canvas, and Architect provisions the topology, AD forests, and exploit chains.

VLANs & firewall control.

+

VLANs & firewall control

Design multi-subnet topologies with VLAN segmentation and unified firewall rules across the whole range.

Plugin & playbook library.

+

Plugin & playbook library

Stand machines up fast from a library of pre-built plugins and configuration playbooks, from Domain Controllers to full attack chains.

Window snapping.

+

Window snapping

Every VM is a native-feeling desktop in the browser. Snap, resize, and multitask across machines, with no RDP and no janky VNC.

Simultaneous VM viewing.

+

Simultaneous VM viewing

Share a live VM console with a teammate and drive it together in real time. Built for mentoring and instructor-led labs.

Full snapshot control.

+

Full snapshot control

Create, revert, and delete per-VM snapshots. A destroyed domain controller is a teaching moment, not a rebuild week.

VM memory capture.

+

VM memory capture

On-demand RAM capture from any running VM. Pull live memory images for forensics and in-memory malware hunting.

Agent harness.

+

Agent harness

Claude, Codex, or your own agent clicks, screenshots, and transfers tools across every VM, long-horizon tasks included.

Automated TTP testing.

+

Automated TTP testing

Hand your LLM a technique class. It runs current TTPs against clean snapshots and shows which Defender and Elastic detections fired.

VM hard drive viewer.

+

VM hard drive viewer

Click through any VM's file system from the browser. Explore the disk, then upload or download straight into place.

Drag & drop file upload/download.

+

Drag & drop file upload/download

Payloads, configs, and 3GB+ files straight into any VM, and loot comes back out just as easily. Team and personal vaults included.

VPN support.

+

VPN support

OpenVPN from your machine straight into the target network, so Burp, Ghidra, and BloodHound work with auto-synced SSH keys.

Author your own curriculum.

+

Author your own curriculum

Courses, CTFs, and walkthroughs authored inside the live range, with images, videos, PDFs, and assessments included.

In-platform chat.

+

In-platform chat

Message your team without leaving the range. Coordinate ops, share findings, and stay in sync right where you're working.

Team Hub analytics.

+

Team Hub analytics

Real-time presence, integrated chat, and weekly progress reports. Know who's on what machine, and watch skills grow.

Enterprise

Enterprise, on your terms.

Opt into a private tenant when you need your own walls, license it the way your team works, and track activity and training across every range. All managed for you, always on.

PRIVATE TENANTS

Your own dedicated copy of Rogue Arena, optionally with ingress IP whitelisting or secured behind a VPN of your choosing. Your team's labs, nobody else's.

FLEXIBLE LICENSING

Per-user or per-deployment license models that size the plan to how your team builds and tests.

ACTIVITY & TRAINING

Track team activity and training progress across every range: who built what, and how they're advancing.

FAQs

Questions? Answers.

Ranges, simplified. Clear answers on running live-fire training without the fuss.

A managed cyber range cloud that does two things well. First, it builds hyper-realistic enterprise labs (machines, VLANs, AD forests, seeded users, and real vulnerabilities) from a prompt or a canvas. Second, you operate inside them yourself or with AI agents driving a whole fleet of VMs. Teams use it for red team, blue team, AI agent and tool testing, and live training.

You don't need one. Rogue Oracle is built into the platform and builds your range from a prompt. Prefer your own model? Connect Claude, Codex, Grok, or an offline model over the open MCP harness, and it will click, screenshot, transfer tools, and run long-horizon tasks across every VM.

Book a demo and we'll walk your team through Rogue Architect and the range, then set you up with a trial where everyone gets full deploy permissions. Enterprise plans add private tenants and flexible per-user or per-deployment licensing.

Every range is segmented with no logical network path to other deployments. Enterprise teams get their own dedicated copy of Rogue Arena, optionally with ingress IP whitelisting or secured behind a VPN of your choosing.

Yes. Point Inspect at a real multi-host range with the inspect-rogue-arena package. Each range is a drop-in, isolated, reproducible sandbox with a scored flag at every stage. See AI model testing →

Everything is authorable: custom machines, vulnerability plugins, attack chains, curriculum chapters, and CTF nodes. Deploy identical per-team instances for a squad or a whole class, with activity and training tracking.

BUILD IT. OPERATE IT.

Hyper-realistic ranges, driven by agents. Book a demo and we’ll walk your team through Architect, then set you up with a trial with full VM deployment.