
RONIN66 provides professional offensive security labs that simulate real enterprise environments for red team training. The platform offers standalone vulnerable machines and complex Active Directory chains with multiple attack paths, rabbit holes, and active EDR/SIEM defenses to build practical offensive security skills. With over 50 real targets across five sectors, the labs emphasize realistic engagement over simple CTF-style challenges.
Funding
Funding not disclosed
Founders
Product
Problem
Traditional cybersecurity training often relies on simplified, single-path labs that fail to prepare professionals for the complexity of real enterprise environments. These sanitized exercises do not expose learners to active defenses, multi-domain Active Directory trusts, or the ambiguity of real-world attack surfaces, leaving them under-equipped for actual red team engagements.
Solution
RONIN66 provides professional offensive security labs that replicate true enterprise environments, complete with multiple attack paths, intentional rabbit holes, and decoy hosts. The platform challenges users to weaponize vulnerabilities against active EDR and SIEM defenses, navigate complex multi-domain Active Directory trusts, and distinguish viable attack paths from dead ends. Labs are designed to mirror real-world engagements rather than simple games, with standalone machines for targeted skill development and full Active Directory chains for practicing lateral movement and escalation. The Active Directory environments feature a single final flag, ensuring learners focus on the attack path itself rather than hunting for CTF-style flags.
Target Audience
Primary users are offensive security professionals, penetration testers, and red team operators seeking realistic enterprise-grade training environments to build and validate advanced exploitation and lateral movement skills.
Features
- 50+ real targets spanning Windows and Linux platforms across five sectors
- Active Directory chain labs with multi-domain trusts and complex lateral movement paths
- Standalone CTF-style machines for honing specific exploits and tactical skills
- Active EDR and SIEM defenses that respond to attacker actions in real time
- Multiple viable attack paths alongside intentional rabbit holes and decoy hosts
- Single-flag design in AD environments to emphasize attack path execution over flag hunting