Enterprise

Train a SOC that outpaces
the threats they haven’t seen yet.

Fresh DFIR scenarios every night, calibrated to each analyst’s skill vector, with session replay and MITRE-mapped telemetry your auditors can read. One platform for security leadership buying skills uplift and training managers buying content.

Early design partners
Pilot · BFSI SOCPilot · IR consultancyPilot · University CTF
cohort.blue-rotation-q2 · live
// 24 analysts · 8 week rotation · Purple + Blue
cohort: blue-rotation-q2
seats:  24 / 30
sso:    saml · enabled

assignments:
 week 1   triage fundamentals  22/24 done
 week 2   dfir evidence chain     18/24 done
 week 3   malware static           12/24 active
 week 4   threat-hunt pivot       scheduled

squad avg ELO:
 dfir        1642 ▲ +88 this month
 malware    1324 ← gap
Five products

One platform. Five ways to deploy it.

LevelUp for enterprise isn’t a single SKU. Pick the product that fits your buyer — or combine two. Every product runs on REACTOR, so the content is always AI-generated, fresh, and non-leakable.

PRODUCT 01

Enterprise Training

DFIR scenario training for your SOC. Multi-stage campaigns with per-user variants, platform-side grading against MITRE ATT&CK, and a REACTOR-generated challenge stream that stays fresh.

  • Private challenge libraries per tenant
  • Per-analyst ELO + 13-axis skill vector
  • SSO / SAML against your IdP
  • Compliance reporting — GDPR · SOX · PCI-DSS · NIST mappings
  • Behavioural telemetry + session replay for auditors
PRODUCT 02

CTF Event Hosting

Run a branded competition on LevelUp. AI-generated, fresh per event — no writeup leakage, no shared answers between attendees.

  • Whitelabel branding — your domain, your logo
  • Full competition stack (scoreboard, teams, hints, replay)
  • AI-generated challenge set per event
  • Handled end-to-end or self-run on our platform
from $2K / event
See event pricing →
PRODUCT 03

AI Agent Evaluation

REST API for evaluating autonomous security agents against REACTOR-generated challenges. Real-world sandboxes, not stale benchmarks.

  • Developer tier free — 1K API calls / month
  • Commercial + Enterprise tiers with advanced analytics
  • Fresh challenges every night — no benchmark memorisation
  • Agent vs par metrics (solve time, tool use, retries)
Free for developers
See the API tiers →
PRODUCT 04

Government & Education

National cyber talent programmes and university CTF curricula. Split-infra — LevelUp generates, you deploy on your own cloud.

  • National-scale rollout (1K – 10K seats)
  • Split-infra — REACTOR runs in our cloud, delivery runs in yours
  • Deployable on your AWS or GCP tenant
  • Curriculum alignment for universities
  • Multi-year terms with volume discounts
Custom pricing
Contact sales ↓
PRODUCT 05

OT Readiness

Train your OT defenders on calibrated Modbus, DNP3, S7, OPC-UA, and EtherNet/IP scenarios. Anomaly hunts, IR triage, safety-violation detection — fresh every week, no writeups.

  • Modbus, DNP3, S7, OPC-UA, EtherNet/IP coverage
  • Anomaly hunts, IR triage, safety-violation detection
  • Asset discovery and protocol forensics
  • Simulators only — never real PLC firmware
  • Calibrated to your skill, fresh every week
Custom pricing
Contact sales ↓
DFIR scenario campaigns

Multi-stage DFIR scenarios. Different for every analyst.

Not isolated challenges — narrative campaigns. Seven-plus stages flowing from ticket triage through evidence analysis, MITRE mapping, onchain tracing, and executive write-up. Platform-side grading throughout.

Per-user variants via ScenarioInstance mean two analysts see the same campaign with different IOCs, actors, and timestamps. No shared answers, no writeup cribbing.

Mixed grading modes — ticket triage (verdict + IOCs + MITRE ATT&CK techniques, F1-scored) and question bank (one-answer-at-a-time, hash-compared). The analyst work that SOC teams actually do.

Our first flagship reconstructs a 2025 crypto-exchange compromise — supply-chain JS tamper, multisig delegatecall takeover, cross-chain laundering. Fictional brand, real technique fidelity.

Hand-curated campaigns built to your brief today. URL-to-scenario ingestion on the roadmap.

Flagship campaign · 7 stages
  1. Ticket triage — verdict, IOCs, MITRE
  2. Evidence analysis — 3 questions
  3. JS bundle reversing — 5 questions
  4. MITRE mapping — 10 questions
  5. Onchain first-hop laundering — 4 questions
  6. Cross-chain timeline — 3 questions
  7. Executive write-up — free-form ticket
What you get

Enterprise-grade, SOC-grade.

Every capability tied to a real buyer requirement — not a bullet on a slide.

01 · DFIR CAMPAIGNS
Multi-stage scenario campaigns

Narrative DFIR scenarios — ticket triage, evidence analysis, MITRE mapping, executive write-up. Per-user variants via ScenarioInstance mean two analysts see different IOCs, actors, and timestamps on the same campaign. No shared answers.

02 · PRIVATE LIBRARIES
Private challenge libraries

Hand-curated scenarios built to your brief today. REACTOR-generated challenges against your category mix. Visible only to your team.

03 · BEHAVIOURAL INTEL
Behavioural intel + session replay

Keystroke cadence, tool usage, retry patterns, AI-vs-human model-specific signatures — plus every terminal keystroke and tool invocation replayable for instructor review. You can tell a learner apart from a prompt.

04 · TEAM ANALYTICS
Team analytics dashboard

Per-analyst skill vector across every category. Cohort coverage maps, solve-rate trends, par ratios, time-in-category.

05 · SPLIT-INFRA
Split-infrastructure deployment

For sovereignty or on-prem requirements. REACTOR runs in our cloud, delivery runs on your AWS or GCP tenant — your data never leaves your infrastructure.

06 · SSO + COMPLIANCE
SSO and compliance reporting

SAML 2.0 integration with your IdP. Training-hour attestations and control mappings aligned to GDPR, SOX, PCI-DSS, and NIST.

Incident reconstruction

Roadmap: any published breach report becomes training content within days.

A planned REACTOR capability will ingest a real breach write-up and reconstruct it as a multi-stage scenario in a Docker sandbox. Not yet shipped — today we ship hand-curated, real-world-inspired campaigns.

On the roadmap · ingestion module in development

The planned flow: paste a public breach report URL, REACTOR will read the advisory, extract the attack chain (initial access → lateral movement → exfiltration → impact), and reconstruct each stage as a deterministically-varied sandbox your analysts can actually work.

Today the Designer agent generates from category + skill-vector targets. The ingestion extension hands it a structured attack-chain brief instead. Same downstream pipeline (Validator, Calibrator, Deploy) — different front end.

Written up in a rekt.news post, a CISA advisory, a vendor PIR, or a DFIR retrospective. All fair game.

Preview · incident.ingest (roadmap)
STAGE 01
Initial Access
STAGE 02
Lateral Movement
STAGE 03
Exfiltration
STAGE 04
Impact
REACTOR

Nine agents. One pipeline. The moat is the tech.

There’s no logo strip on this page because we’re early and we don’t fake reference customers. What we do have is a 9-agent pipeline running in production against every challenge you’ll ever see on the platform.

Designer
drafts the brief
Narrative
stamps the story
Static Analysis
deterministic lint
Validator
builds + solves
REACTOR
orchestrator
Calibrator
sets par time
Repair
patch, don’t regen
Deploy
signed image
Evolution Worker
nightly · 4 loops

Designer drafts. Static Analysis lints. Validator builds and proves solvability end-to-end. Calibrator scores difficulty. Repair patches on stage failure. Deploy hardens and ships. The Evolution Worker reruns the whole catalogue nightly. No stage is LLM-alone — every agent reads and writes to SAGE, the open-source memory framework underneath, so one agent’s lesson becomes the next agent’s starting context.

That’s the defensibility: fresh, non-leakable, validated content at a rate a manual authoring team cannot match.

Incident Range

Real incidents, defanged into investigations your team can work.

Incident Range turns landmark security incidents into multi-stage, real-incident-inspired DFIR investigations — fictionalized, defanged, and built on no real victim data. Your SOC and blue teams move through alert triage and forensic question-banks the way they would on a real case, with difficulty ELO-matched to each analyst. Three try-campaigns are ready to run today.

Try campaign 01 · Supply-chain DFIR

Trace a poisoned software update.

Inspired by a real supply-chain intrusion, fully fictionalized. A trusted build pipeline ships a tampered update and a quiet beacon wakes up across the estate. The analyst triages the first alert, reverses the planted artifact, hunts host and DNS telemetry for the backdoor, then chases the lateral movement and identity abuse to its root.

  • Beacon alert triage — verdict, IOCs, MITRE, containment
  • Host forensics — find the tampered artifact
  • Network & DNS analysis — map the C2 channel
  • Lateral movement & identity — forged-token abuse
DFIRSupply chainThreat huntDefanged
Try campaign 02 · Crypto fund-flow

Follow a multisig drain on-chain.

Inspired by a real exchange compromise, fully fictionalized. A malicious signing flow tricks approvers into authorizing a hostile upgrade, and a custody wallet empties in minutes. The analyst triages the drain alert, reconstructs how the signature was subverted, then traces the stolen funds hop-by-hop across mixers and bridges into a laundering timeline.

  • Drain alert triage — verdict, IOCs, MITRE, containment
  • Transaction analysis — how the signature was subverted
  • First-hop fund tracing — follow the outflow
  • Cross-chain timeline — mixers, bridges, cash-out
On-chain DFIRFund tracingMultisigDefanged
Try campaign 03 · OT/ICS DFIR

Catch an unauthorized command on a water plant.

Inspired by a real water-utility intrusion, fully fictionalized. An exposed remote-support tool lets an actor pivot from IT to a flat control LAN and write a rogue Modbus setpoint to a chemical-dosing PLC. The analyst triages the SCADA alarm, reconstructs the IT→OT pivot, reads the malicious Modbus writes off the wire, and maps it to MITRE ATT&CK for ICS.

  • SCADA alarm triage — verdict, IOCs, MITRE ICS, containment
  • IT→OT pivot — the dual-homed engineering host
  • Modbus forensics — the rogue FC6/FC16 write
  • Containment — segment, lock down remote access
OT/ICS DFIRSCADAModbusDefanged
How it works
01 · Alert triage

Each campaign opens on a SOC ticket. The analyst delivers a verdict with IOCs, MITRE ATT&CK techniques, and a containment call — scored platform-side, not on the honour system.

02 · Forensic question-banks

Triage hands off to staged question-banks over logs, on-chain traces, and supply-chain artifacts. One answer at a time, hash-compared, the way real investigations actually unfold.

03 · ELO-matched

Difficulty is matched to each analyst’s ELO and skill vector, so a junior and a lead work the same incident at the right stretch. Real-incident-inspired, defanged, no real victim data.

Today, Incident Range ships as guided investigations. Live, multi-host range emulation is coming soon.

Talk to us

Book a 30-minute demo.

A solutions engineer walks you through REACTOR against one of your rotations, SSO against your IdP, and a pricing quote shaped to your seat count.

You’ll see:

  • → A live REACTOR run — a fresh challenge generated in real time
  • → Cohort setup against one of your rotations
  • → SSO against your IdP (bring a test tenant if you can)
  • → Private-library workflow and review gate
  • → Pricing shaped to your seat count and deployment model
  • → Split-infra architecture for regulated buyers

Request a walkthrough

The full intake form captures your team size, compliance requirements, and timeline so the demo is tailored to your stack before we meet. Takes two minutes.

Enterprise | LevelUp