Hack The Box is expanding what cyber readiness means with Threat Range, a team-based simulation platform built to mirror live attack conditions and measure how well defenders perform under pressure. Instead of running isolated labs or step-by-step exercises, Threat Range drops SOC and DFIR teams into a live-fire environment where they need to triage alerts, escalate incidents, and manage response workflows in real time.
Gerasimos Marketos, Chief Product Officer at Hack The Box, described the platform as more than just another training environment. He told MSSP Alert, "Hack The Box Threat Range is designed to give SOC and DFIR teams more than just another ‘range.’ It is a live-fire simulation that reproduces the full incident-response lifecycle – from triage to management oversight – in a controlled, realistic environment.”
This shift is important because traditional training often ends once an alert is identified. Threat Range forces teams to dig deeper - reconstructing attack paths, investigating intent, and coordinating across roles. “Unlike other cyber ranges focusing on individual performance or technical replicas, Threat Range emulates attack paths and behaviors – with the goal of growing an attack-ready mindset rather than relying on tools,” Marketos explained.
Every action - from dismissing alerts to confirming compromises - is logged, scored, and converted into performance metrics. Teams receive immediate feedback through indicators like detection speed, false-positive rates, and investigation accuracy. At the center of this is the Threat Resilience Index (TRI), which quantifies how effectively a team detects, escalates, and resolves incidents during an exercise.
Marketos said the approach closes several key readiness gaps. “Traditional up-skilling often stops at ‘did they see the alert?,’ whereas Threat Range reconstructs the full investigative narrative, highlights missed steps, and gives leaders actionable data to improve staffing, tooling, or processes.”
For MSSPs, it also means benchmarking shifts, validating playbooks under stress, and showing clients measurable improvement over time.
Facing AI-Driven Attacks with Real Data
As attackers weaponize AI, defenders need training environments that reflect that speed and complexity. Threat Range brings those AI-driven tactics into simulation - ransomware, social engineering, malware, and APTs - so teams can see how fast they detect and contain new threats.
“Threat Range scenarios are meticulously created by experts in the defensive field, demonstrating techniques and procedures used by adversaries,” Marketos said. “We leverage AI to reduce friction and improve the user experience, while accurately evaluating analysts and emulating attack scenarios that are now enhanced by AI-driven techniques.”
Executives and boards can finally see how those drills translate into real outcomes. Each exercise generates a board-ready report with the TRI, MTTR, MTTD, and investigation accuracy metrics. “Because these metrics feed into a board-ready report with the Threat Resilience Index and security performance metrics, executives can clearly see whether AI-accelerated attacks are being detected and contained faster over successive exercises,” Marketos said.
That level of transparency turns what used to be anecdotal into verifiable progress - evidence leaders can trust when assessing program maturity or investment ROI.
Integrating LetsDefend and Expanding the Community
For Hack The Box,
the recent acquisition of LetsDefend adds depth to Threat Range’s content and community. “The acquisition of LetsDefend brings a vast library of SOC simulations and a vibrant blue team community to Hack The Box. LetsDefend’s labs include simulated SIEM alerts, threat intel feeds, and forensic telemetry aligned with frameworks like MITRE ATT&CK,” Marketos explained.
By merging these capabilities, Threat Range can generate dynamic, AI-augmented scenarios that evolve based on analyst behavior. “As the integration progresses, the platform will generate lifelike attack patterns that adapt to a defender’s decisions and will use AI to analyze player performance and provide adaptive feedback,” he added.
That integration is fueled by a practitioner base of over four million members, combining red and blue team expertise to continuously shape new content. “The unified platform remains community-inspired, and that content will continue to be aligned with industry frameworks like MITRE and NIST, ensuring that enterprise training stays relevant to real-world adversary tactics,” Marketos said.
MSSP Differentiation
For MSSPs, Threat Range isn’t just an internal training tool - it’s a performance differentiator. Continuous simulations allow providers to benchmark across shifts, validate processes, and present hard evidence to customers.
“MSSPs running 24/7 SOC operations can run live-fire drills to validate readiness, stress-test their own playbooks and tooling, and benchmark performance across shifts or regions,” Marketos explained. “Because every simulation produces metrics such as our new Threat Resilience Index and MTTD/MTTR, MSSPs can present data-driven evidence of how their analysts respond to emerging threats and how quickly they meet customer SLAs.”
That kind of proof can make the difference in competitive bids. “A provider that can demonstrate faster detection times, lower false-positive rates, and continuous improvement has a compelling advantage over rivals that offer only anecdotal assurances,” he said.
Proving ROI and Resilience to Clients
One of the toughest challenges for MSSPs is showing midmarket clients that their investment is paying off. Threat Range bridges that gap by translating technical metrics into clear, MITRE-aligned dashboards that track progress over time.
“Threat Range addresses this by translating technical performance into executive-friendly dashboards,” Marketos said. “After each exercise, the platform’s reports highlight MTTR, MTTD, and other key metrics, with dashboards structured around MITRE ATT&CK tactics and techniques.”
This structure lets MSSPs show not just that alerts were handled, but where detection improved and how response times are trending. “By running periodic exercises, providers can demonstrate a decline in dwell time and an increase in TRI scores over time, giving clients tangible evidence of improving resilience,” Marketos added.