Cyberswarm — Build the range. Break the system. Learn what survives.
CYBERSWARM
Platform Scenarios Competitions Security Open core Access
CYBER RANGE CONTROL PLANE

Build the range.
Break the system.
Learn what survives.

Cyberswarm turns infrastructure you already own into isolated, disposable security environments — explicitly defined, continuously observed, verified against intent, and destroyed without residue.

See how a range is built
PROXMOX — FIRST ADAPTER SELF-HOSTABLE CORE RANGES ARE DISPOSABLE BY DESIGN
ASSEMBLY — CONTAINERS DOCKED 00/09
PRODUCT SIMULATION — NOT LIVE INFRASTRUCTURE SCROLL — BUILD · BREAK · LEARN
01 / WHAT A RANGE IS

A controlled place
to break things.

A cyber range is a working replica of real infrastructure — machines, networks, vulnerable software — built so attacks can be practiced without consequences.

Cyberswarm is the control plane that builds them. It converts an explicit definition into a running, isolated environment on your infrastructure, proves the environment matches the definition, and deletes it when the exercise ends.

01
Define

Every range begins as a versioned definition. Nothing undeclared gets created.

02
Isolate

Boundaries decide what may communicate — enforced and checked, not assumed.

03
Observe

The platform records what infrastructure actually reports, not what was requested.

04
Destroy

Teardown is verified. Residue is treated as a failure, not a footnote.

02 / RANGE ASSEMBLY — SCROLL TO BUILD
01 / INTENT
Define what must exist.

A range begins as an explicit, versioned definition: machines, networks, vulnerable state, lifecycle rules.

02 / BOUNDARY
Constrain what may communicate.

Isolation planes seal the environment before it becomes dangerous. Undeclared paths are severed; one controlled gateway remains.

03 / EVIDENCE
Prove what actually exists.

The platform inspects the running environment and records facts. Configuration is not accepted as proof.

04 / RESULT
A verified range.

The range is trusted only when intent, boundary, and evidence agree. Then the exercise begins.

RANGE R-0198 — STATE COMPOSING FACTS OBSERVED 00/38 PATHS SEVERED 0/5 GATEWAY PENDING
A DEPLOYMENT REQUEST IS A PROMISE — AN OBSERVATION IS EVIDENCE
03 / CONTROL PLANE

Infrastructure you can
reason about.

One surface for inventory, composition, isolation, observation, and teardown. The platform always knows three things: what exists, what it intends to change, and what was actually observed.

The control plane maps what already exists before it is allowed to change anything.

CONTROL / INFRASTRUCTURE / DISCOVERY LIVE
NODES 04
GUESTS 38
NETWORKS 12
pve-cluster-01verified
range-fabricobserved
scenario-storehealthy
lab-spare-02offline
READ-ONLY DISCOVERY interface model — demonstration data
PROVIDER MODEL

One control language. Adapters translate.

Ranges keep the same identity, topology, policy, lifecycle, and observation model regardless of substrate. Only the adapter changes.

FIRST ADAPTERACTIVE
Proxmox

Discovery, planning, gated apply, and observed-state verification against Proxmox VE clusters.

ADAPTERROADMAP
Kubernetes

Container workloads under the same range contract: identity, policy, lifecycle, teardown.

ADAPTERROADMAP
AWS

Cloud accounts mapped into range concepts instead of a second control plane.

ADAPTERROADMAP
Azure

Tenant resources with the same distinction between intended and observed state.

ADAPTERROADMAP
GCP

Provider-native discovery and execution; portable intent, provider-specific evidence.

ONLY THE PROXMOX ADAPTER IS IN ACTIVE DEVELOPMENT — EVERYTHING MARKED ROADMAP IS DIRECTION, NOT A SHIPPING CLAIM.

THE OPERATING PRINCIPLE
A deployment request is a promise.
An observation is evidence.

Cyberswarm keeps intended state and observed state as separate records, and treats verification as a first-class step. A configuration that exists is not proof the environment behaves as intended.

CONFIGURATION ≠ PROOF INTENT ≠ OBSERVATION DEPLOYMENT ≠ VALIDATION
04 / SCENARIOS

A scenario is an
environment contract.

Not a CVE number on a card. A scenario packet declares everything a repeatable exercise needs — and the control plane compiles it into a running range.

SCENARIO PACKET — eternalblue-lab · v1.4.2 EXAMPLE CRITICAL
softwarewindows-server-2008-r2 serviceSMBv1 — port 445 exposed vulnerabilityCVE-2017-0144 · KEV topologyattacker · edge · 2 targets / 3 networks prerequisitesSMB reachable from attacker subnet validationprobe confirms vulnerable state before arming attackerkali-01 @ 10.0.66.0/24 exploitationguided path — lateral movement via SMB resetsnapshot rollback ≤ 90 s teardownfull destroy + residue check objectiveexploit, pivot, extract — explain what survived
The packet compiles into an isolated environment. If validation cannot prove the vulnerable state, the scenario never arms.
IDPACKETENVIRONMENTRESETSTATE
0198eternalblue-lablegacy windows · SMBv1 · 4 hosts≤ 90 sVALIDATED
0241web-chain-02linux · multi-stage web chain · 5 hosts≤ 120 sVALIDATED
CUSTOMyour-exercisecomposer — turn an internal lab into a packetdeclaredDRAFT

DEMONSTRATION PACKETS — THE PACKET FORMAT IS THE PRODUCT; THE PUBLIC LIBRARY IS BEING CURATED.

05 / COMPETITION OPERATIONS

Run the event.
Not the fire drill.

Competitions are the stress test for range infrastructure: dozens of isolated environments, live resets, zero tolerance for cross-team interference. The operator surface is being designed around that reality.

01
Team-scoped isolation — one boundary per team, enforced at the network plane.
02
Reset without collateral — one range rolls back; the other 143 never notice.
03
Live range health — state, drift, and lifecycle for every environment at a glance.
04
Scenario pinning — every team runs the same versioned packet, with an audit trail.
OPERATOR VIEWPacific Security Games SIMULATED EVENT DATA 24 TEAMS / 144 RANGES

EACH CELL IS AN ISOLATED RANGE — A RESET TOUCHES EXACTLY ONE ROW.

Talk to us about an event
06 / TRUST MODEL

Automation is
not assurance.

Every mutation moves through the same pipeline, and each step produces its own record. No step is allowed to impersonate the ones after it.

STEP 01
PLAN

Intended state is declared explicitly — a reviewable artifact, not a side effect.

STEP 02
AUTHORIZE

Changes pass a gate before they are allowed to touch infrastructure.

STEP 03
DEPLOY

Enrolled, constrained workers execute the plan — nothing executes ambiently.

STEP 04
OBSERVE

Infrastructure reports what actually exists, as a separate record from intent.

STEP 05
VALIDATE

Intent and observation must agree before a range is trusted — or the range is not trusted.

01
PLAN BEFORE APPLYMutations are derived from explicit intended state. There is no "just run it" path.
BOUND
02
ISOLATION VERIFICATIONBoundary checks probe the running network. Configuration alone is not accepted as proof.
PROBED
03
WORKER IDENTITYExecution happens through enrolled, constrained workers with pinned identity.
PINNED
04
RESIDUE DETECTIONAfter teardown, the platform looks for what should not exist anymore — and says so if it does.
CHECKED

These are design commitments, stated so they can be held against us. Security guarantees appear here only after they have been validated — the same rule the platform applies to your ranges.

Read the security model
07 / OPEN CORE

Run the control plane on
infrastructure you own.

OPEN COREYOURS

The orchestration core is being built to be self-hostable: your hardware, your hypervisor, your data. It is the part that runs your ranges — so it stays under your control.

Self-hosted orchestration core
Provider adapters — Proxmox first
Range + scenario APIs
Open scenario packet format
Follow on GitHub
COMMERCIAL LAYERPLANNED

Commercial capabilities are planned as a layer above the core — content, intelligence, and operations. They accelerate the core; they never own the range.

Curated vulnerability + scenario library
Managed scenario intelligence
Competition operations at scale
Enterprise identity + governance

THE SPLIT IN ONE SENTENCE: THE CORE THAT RUNS YOUR RANGES IS YOURS. WHAT WE SELL SITS ON TOP.

08 / ACCESS

Start with the core.
Add what accelerates you.

Clear paths for builders, teams, and competition organizers. Early access — capabilities land in the order the roadmap above describes.

COMMUNITY

Core

For builders running their own environment.

Free
Self-hosted control plane
Proxmox adapter
Core range + scenario APIs
Open scenario packet format
MOST CAPABLE TEAMS

Swarm Cloud

Curated content and managed capability on top of the core.

Talk to us
Everything in Core
Curated vulnerability library
Managed scenario intelligence
Team collaboration
Priority support
ORGANIZATIONS

Enterprise

For competitions, institutions, and larger environments.

Custom
Competition operations
Enterprise identity
Governance + audit
Deployment architecture support
09 / QUESTIONS

Before you
enter the range.

Serious questions, answered without sales copy. For everything else: docs, security, or contact.

No. Competition operations are one mode. The same control plane supports vulnerability research, classroom labs, security validation, and repeatable training environments.

That is the direction of the product: a self-hostable orchestration core with provider adapters, and optional managed capabilities layered on top. Proxmox is the first supported substrate.

A scenario is broader than an image. It declares the environment, prerequisites, vulnerable state, network context, validation expectations, attacker position, reset behavior, and teardown behavior a repeatable exercise needs.

Intended state and observed state are separate records. Isolation, constrained execution, verification, teardown, and residue detection are first-class concerns — not assumptions inherited from configuration.

Active development today: the control-plane core and the Proxmox adapter. Roadmap: Kubernetes and cloud adapters, the curated scenario library, and competition operations at scale. This page labels each accordingly, on purpose.

THE BOUNDARY

Enter Cyberswarm.

The public site ends here; the control plane begins. Create an account to follow early access, or bring us the event you need to run.

EARLY ACCESS — THE PLATFORM IS IN ACTIVE DEVELOPMENT

CYBERSWARM

Cross the boundary.

The control plane sits behind this surface.

PREVIEW BUILD — AUTHENTICATION IS NOT CONNECTED YET