Cybersecurity training is no longer simply about placing participants in a simulated environment and asking them to solve a technical challenge. Effective exercises need to reflect real-world conditions, including changing situations, time pressure, collaboration, and decision-making. That is why CDeX continues to evolve beyond the traditional cyber range experience.

Recent updates have introduced new ways to build and manage scenarios, support participants, connect practical exercises with learning content, and analyse results. From hands-on technical challenges and dynamic scenarios to tabletop exercises focused on decision-making, CDeX now supports a broader range of training approaches. Together, these developments make the platform more flexible, realistic and better suited to how organisations need to prepare for cyber incidents. Let’s discover CDeX’s new features and scenarios. 

A Better Experience for Participants 

The training experience has been redesigned to give participants greater visibility, interaction and support throughout an exercise. The new player view replaces the classic interface with a redesigned experience that includes training cards, an improved training summary, PDF export and an observer mode for users who want to follow an exercise without actively participating.

For more competitive exercises, live leaderboards show participant or team rankings, points and remaining time. Instructors can choose whether the leaderboard is visible in real time, after a delay or only when the exercise ends.

Participants can also use hints attached to CTF flags and scoring categories. Hints can carry configurable point penalties, allowing teams to get support without removing the challenge.

Finally, collaborative notes give teams a shared workspace directly inside the training. Participants can create multiple notes, use SITREP and CTIREP templates, while additional templates can be used for different reporting exercises. Notes can include comments and screenshots, track changes and be saved as PDFs. These reports can also form part of the exercise assessment, allowing participants to practise producing operational reports while instructors evaluate the quality of their work.

Together, these improvements make the participant experience more interactive while giving teams better tools to communicate, collaborate and document their work during an exercise.

From CTFs to Decision-Making: Introducing Tabletop Exercises

Not every cyber incident can be solved with a command line or a vulnerability scan. In a real incident, teams also need to decide what to do, when to escalate and how to respond as a situation develops. CDeX now supports this side of cyber preparedness with Tabletop Exercises (TTX) - a dedicated training type focused on decision-making.

Unlike infrastructure-based technical exercises, TTX scenarios do not require a simulated technical environment. Instead, a decision-making team receives events and possible response options. Their choices can then trigger new events or create tasks for a technical team, allowing the exercise to develop based on the decisions participants make. TTX scenarios can include:

  • Scheduled or triggered events that introduce new developments during the exercise
  • Time limits that add pressure to decision-making
  • Hidden escalation paths that allow scenarios to evolve based on participant choices
  • Tasks for technical teams generated by decisions made by the decision-making team
  • Judge Evaluation through a dedicated assessment board
  • Detailed reporting showing the decisions made, their consequences and the full decision path

This makes TTX useful for practising the organisational side of cyber incidents, where the quality and timing of decisions can be just as important as technical expertise. By adding tabletop exercises alongside hands-on technical training, CDeX can support a broader range of cyber exercises, from testing how teams investigate and respond to an attack to assessing how they make decisions as an incident unfolds.

Building More Realistic and Flexible Scenarios

Creating a realistic cyber exercise is only half the challenge. It also needs to be practical to build, modify and reuse. CDeX introduces several improvements that give scenario authors more control over how training environments are designed and maintained.

Build the network visually

The Visual Topology Editor replaces a previously read-only topology view with an interactive canvas. Authors can build infrastructures, networks and machines using drag and drop, draw connections, copy machines and create reusable templates. The editor also validates IP/CIDR addressing and hardware settings as scenarios are built. This makes scenario creation more visual and reduces the need to prepare every element manually outside the platform.

Keep different versions of a scenario

Scenario development does not always follow a straight line. A training may need to be adapted for different audiences, updated after a previous exercise or tested in several variations.

With scenario versioning, authors can maintain multiple independent versions of the same scenario, give them names and switch between them when needed. The approach is similar to working with branches in software development, making it easier to experiment without losing previous work.

Make CTF challenges dynamic

CTF flags can now be more than static values. Dynamic flags can be generated or changed during deployment or while a training is running. For example, an action could modify a flag following an event such as a leak, with changes recorded in the logs.

Together, these features give scenario authors greater flexibility: they can visually build an environment, maintain different versions of it and introduce changes while an exercise is underway. The result is a scenario-building workflow designed not just to create an exercise once, but to keep adapting it as training needs change.

Making Every Training Run Less Predictable

Repeating the same exercise can be useful for measuring progress, but it can also make a scenario predictable. Once participants know exactly when an action will happen, which user will be targeted or what a particular payload will look like, they may start relying on memory rather than responding to the situation in front of them. CDeX introduces more ways to vary what happens during a training through an improved random traffic generator and the Action Randomizer. Authors can define pools of possible values or rules for attributes such as:

  • users
  • payloads
  • delays
  • file names

The platform selects the values when the training starts and records them in the logs. This means different groups can experience variations of the same scenario while the underlying exercise remains consistent. CDeX also provides greater control over automated actions. Actions can be scheduled for an exact date and time, automatically retried after a failure and tracked through an execution history showing the parameters actually used during the run.

The result is a more dynamic training environment. Instead of simply repeating the same sequence, instructors can deliver exercises that retain their core objectives while introducing enough variation to keep participants focused on responding to the situation rather than memorising the solution.

More Options for Machines, Infrastructure and Automation

A realistic cyber exercise may require different machines, network configurations and automated events. CDeX has expanded the options available to scenario authors, making it easier to build diverse environments and control what happens during training.

More flexibility with machine images

CDeX now supports Docker images as machines, while disk images can be automatically converted to QCOW2. Supported formats include VDI, OVA, VMDK, VHD, VHDX, QCOW2, ISO and IMG, as well as common archive formats such as ZIP, 7Z, TAR and GZ.

Greater control over automated actions

Actions can now be scheduled for an absolute date and time, rather than only relative to the start of a training. Failed actions can also be retried automatically after a configurable delay, helping automated sequences continue after an unsuccessful execution. Execution history records the settings used when an action actually ran, providing a clearer picture of what happened even if the action is later modified.

More visibility into network activity

Traffic monitoring can enable port mirroring on a machine interface, allowing subnet traffic to be copied for analysis in tools such as Wireshark. Internet access can also be connected or disconnected for a running machine.

Together, these improvements give scenario authors greater control over the machines, actions and network activity that make up an exercise.

AI Agent: Supporting Scenario Authors, Not Replacing Them

One of the newest capabilities in CDeX is the AI Agent, designed to support the people building and managing training scenarios. Available in the Visual Topology Editor and Player view for users with Operator, Editor or Admin roles, it can help with both scenario creation and understanding how the platform works. The AI Agent can:

  • Generate scenario and topology XML, providing a working starting point that authors can refine.
  • Suggest scenario structures based on uploaded examples and the application guide.
  • Explain the platform, including topology elements, XML syntax and training logic, in plain language.
  • Review authored content, identifying errors and inconsistencies and suggesting improvements.
  • Answer questions about CDeX functionality and good practices for building scenarios.

Importantly, the AI Agent does not make scenario authors redundant. Generated XML is a starting point, not a finished scenario, and still requires refinement by the author. Its role is to help scenario teams work more efficiently, explore ideas faster and lower the barrier to creating and adapting exercises. In this sense, AI becomes another tool within the scenario-building workflow - helping authors spend less time on repetitive work and more time designing meaningful training experiences.

Connecting Theory With Hands-On Practice

Cybersecurity training is most effective when theory can be tested in practice. CDeX now makes it easier to connect LMS-based learning with hands-on exercises, creating a more continuous journey from learning a concept to applying it in a live training environment. A lesson in the LMS can include a CDeX scenario code, giving learners a direct way to move from theoretical content into the corresponding exercise. This can connect:

Theory → Quiz and learning materials → CDeX scenario → Hands-on practice

The integration can also trigger an action in the linked CDeX scenario after a defined period from the start of the lesson. This means practical events can be introduced as learners progress through the learning experience, rather than requiring the instructor to manage them separately.

The connection also extends to reporting. When the course is identified on the CDeX training, the theoretical and practical results can be brought together into one report, giving instructors a more complete view of the learner's performance.

The result is a closer connection between learning and doing: participants can move directly from understanding a concept to applying it in a realistic environment, while instructors gain a more unified view of the outcome.

Training at Scale: From Individual Exercises to Multi-Tenant Environments

A tenant in CDeX represents a single, isolated CDeX instance. Organisations can operate multiple CDeX instances within one larger structure, with each tenant maintaining its own users, scenarios, networks and training environments.

These tenants are managed centrally through the Global Panel (GP), which acts as a common management layer across the CDeX instances. The tenants remain isolated from one another, while the Global Panel provides visibility and central management across the entire structure.

The Global Panel provides central management across tenants, including resource usage, event logs, notifications and scenario distribution. For example, a scenario can be exported to the Global Panel and then distributed to a selected CDeX instance within the structure. This makes it possible to reuse training content across multiple isolated environments without having to recreate it separately in each tenant.

The Global Panel also enables federated training between tenants. This allows participants from different CDeX instances to take part in the same exercise, while their environments remain isolated outside the training. For example, teams using separate CDeX instances can be brought together for a joint exercise and interact with each other only for the duration of that training.

In this model, the individual CDeX instances remain separate, while the Global Panel provides the common point for managing and coordinating them. This makes it possible to scale training across multiple environments while maintaining isolation and central oversight.

Integrations and Access: Connecting CDeX to Existing Environments

CDeX is also designed to work alongside existing infrastructure and tools, making it easier to incorporate cyber range exercises into established environments. Key integrations include Keycloak SSO, with permissions linked to existing user groups, and optional WireGuard-based remote access for training outside the local environment. Scenarios and training content can also be imported and exported using standard packages, while CTFd compatibility makes it possible to reuse existing CTF content.

CDeX can also connect to remote infrastructure from another cyber range, allowing participants to access external machines through VPN without having to copy those machines into CDeX. These capabilities give organisations more flexibility in how they build, connect and deliver exercises, while allowing CDeX to fit into existing technical environments.

Measuring What Actually Happened

CDeX has expanded its reporting capabilities with a wider range of data and new report sections, including time to detect, hint usage and TTX results. Reports can also map exercises to MITRE ATT&CK techniques and sub-techniques, providing a clearer view of the capabilities tested during training.

Scoring has also moved to a 0–100 scale, making results easier to interpret as percentages. Instructors can manually correct scores when needed, with changes recorded through an audit trail and previous report versions preserved for reference.

From Features to a Better Training Experience

The latest CDeX developments are not just a collection of individual features. Together, they support a more complete training workflow - from building and adapting scenarios to running exercises, collaborating during incidents and analysing the results.

Scenario authors have more flexibility when creating and varying training environments. Participants have more ways to interact, collaborate and make decisions. Instructors can connect practical exercises with learning content and gain deeper insight into performance through expanded reporting. The result is a cyber range that supports more than the exercise itself. CDeX is evolving into a more complete environment for designing, delivering, managing and evaluating realistic cybersecurity training. 

Find Out More About CDeX

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Table of contents