Platform new features and enhancements

  • Image files now supported for live action event document uploads: You can now upload .jpg, .jpeg, .png, and .gif image files to the Documents section of a live action event (LAE). The Documents section previously accepted only non-image file types. (PRTL-5286)
  • Updated NetSpec Wizard: The NetSpec Wizard now uses updated virtual machine (VM) templates and configuration modules. This update removes GRR Rapid Response, Nessus, and Wormhole from the Wizard to reflect current supported configurations. (PRTL-5315, PRTL-5314)

New content

New attack scenarios

  • New ransomware attack scenarios: Scenario: Ransomware Attack (ENCRYPT) provides an attack sequence that ends with a ransomware deployment against an internal asset. The complementary scenario, Scenario: Ransomware Attack (DECRYPT), decrypts the asset for further range reuse.

New individual training content

    • IoT Device Analysis: Firmware Extraction Challenge: Extract the root filesystem from firmware on an IoT device.
    • Analyzing Compromised Exchangeable Image File Format (EXIF) Files: Analyze a Windows system to identify files with compromised EXIF data.
    • Cyber Threat Emulation: APT34 Exercise: This exercise challenges students to emulate APT34’s tactics, techniques, and procedures (TTPs).
    • Cyber Threat Emulation: APT34 Workshop 1: Workshop 1 teaches students to emulate APT34’s tactics, techniques, and procedures (TTPs).
    • Cyber Threat Emulation: APT34 Workshop 2: Workshop 2 teaches students to emulate APT34’s tactics, techniques, and procedures (TTPs).
    • DLL Manipulation – Challenge: Identify the dynamic link library (DLL) manipulation techniques used by an adversary in a noisy network.
  • DLL Manipulation – Exercise: Using Kibana fed with Sysmon data, analyze and identify malicious traffic created by an actor for DLL manipulation attempts.
  • DLL Manipulation – Workshop: Explore the types of DLL manipulation attacks that adversaries can use to gain remote code execution on a Windows host.
  • AI-Assisted Security Operations: Practical LLM Integration for Detection Engineering and Threat Hunting: Learn AI-assisted security operations by leveraging large language models (LLMs) for detection engineering and threat hunting while maintaining data security. Through hands-on labs, develop queries, reconstruct attack chains, and apply a proven workflow that prevents AI hallucination and ensures accurate results.

VM template updates

  • Security Onion 2.4.200 VM template:
    • VM hardware compatibility is now version 19.
    • Names for the VM Template Object in vCenter are now consistent with other templates.
    • Security Onion is now version 2.4.200.
  • Elgg Server: (LC-250)
    • VM hardware compatibility is now version 19.
    • Open VM Tools is updated to 10.2.0.
    • The facebook.com certificate is up to date.
    • You can now swap random access memory (RAM) while the system is running.
  • P7 SimSpace Management: (LC-197)
    • VM hardware compatibility is now version 19.
    • Open VM Tools is updated to 11.3.0.
    • The facter script at /opt/puppetlabs/facter/facts.d/range_service.sh is updated with default values for on-premise appliances.
  • P7 Kali 2025.4: (LC-236)
    • VM hardware compatibility is now version 19.
    • Open VM Tools is updated to 12.2.5.
    • You can now swap RAM while the system is running.
    • Kali Linux is now version 2025.4.
    • Added the local simspace admin account.
    • Networking is normalized to use the networking module.
  • P7 Exchange 2013: (LC-201)
    • VM hardware compatibility is now version 19.
    • You can now swap RAM while the system is running.
    • VMware Guest Tools is now version 13.0.5.
    • Windows Server 2012 is up to date with all available patches.
  • P7 Windows Server 2019 2 Disk: (LC-202)
    • VM hardware compatibility is now version 19.
    • You can now swap RAM while the system is running.
    • VMware Guest Tools is now version 13.0.5.
    • Windows Server 2019 is up to date with all available patches.
  • P7 Nagios: (LC-203)
    • VM hardware compatibility is now version 19.
    • You can now swap RAM while the system is running.
    • Open VM Tools is updated to 10.0.7.
  • P7 Splunk 10:
    • P7 Splunk 10 is a new VM template running Debian 13.
    • Splunk Enterprise Security 10.0.1 is installed, with additional configuration required.
    • The Splunk Add-on for Windows, Splunk Add-on for Sysmon, Splunk Add-on for Linux, Splunk Add-on for Squid, and Splunk Add-on for Zeek technology add-ons are all installed.
    • Splunk indices for windows, linux, vyatta, pfsense, onion, zeek, proxy, ids, and strelka are created.
    • Listeners on transmission control protocol (TCP) port 9997 and user datagram protocol (UDP) ports 514 and 5514 are configured for syslog streams.
    • The VM is configured with Puppet to work with Linux networking and hostname configuration modules.
  • P7 Ubuntu 18.04 Desktop: (LC-205)
    • VM hardware compatibility is now version 19.
    • Open VM Tools is updated to 11.0.5.
    • You can now swap RAM while the system is running.
  • P7 Ubuntu 18.04 Server: (LC-206)
    • VM hardware compatibility is now version 19.
    • Open VM Tools is now version 11.0.5.
    • You can now swap RAM while the system is running.
  • P7 Ubuntu 20.04 Server with Docker: (LC-207)
    • VM hardware compatibility is now version 19.
    • Open VM Tools is now version 11.3.0.
    • You can now swap RAM while the system is running.
  • P7 Ubuntu 22 Desktop: (LC-208)
    • VM hardware compatibility is now version 19.
    • Open VM Tools is now version 12.3.5.
    • You can now swap RAM while the system is running.
  • P7 Windows 10: (LC-209)
    • VM hardware compatibility is now version 19.
    • VMware Guest Tools is now version 13.0.5.
    • You can now swap RAM while the system is running.
    • Windows 10 is up to date with all available patches, including required certificates and the Azure Code Signing patch.
  • P7 Windows 11: (LC-210)
    • VM hardware compatibility is now version 19.
    • VMware Guest Tools is now version 13.0.5.
    • You can now swap RAM while the system is running.
    • The VM supports Azure Code Signing.
  • P7 Windows 7: (LC-211)
    • VM hardware compatibility is now version 19.
    • You can now swap RAM while the system is running.
  • User emulation 14 server: (LC-199)
    • User emulation is now version 14.7.3.
    • VM hardware compatibility is now version 19.
    • Open VM Tools is now version 11.3.0.
    • You can now swap RAM while the system is running.
  • P7 Windows FlareVM: (LC-212)
    • P7 Windows FlareVM is a new VM template based on Windows 11.
    • The template uses the latest packages from the FLARE VM repository and is configured for Puppet.
    • The following tools are pre-installed:
      • Volatility (accessible using the volatility alias)
      • FTK Imager
      • MemProcFS
  • P7 Linux DFIR: (LC-214, LC-213)
    • P7 Linux DFIR is a new VM template based on Ubuntu 24.
    • REMnux is installed on a SIFT Workstation and configured for Puppet.
  • User emulation traffic visualization: (LC-215)
    • VM hardware compatibility is now version 19.
    • Open VM Tools is now version 11.0.5.
    • You can now swap RAM while the system is running.
  • P7 Vyatta 1.5: (LC-216)
    • VM hardware compatibility is now version 19.
    • You can now swap RAM while the system is running.
  • P7 Vyatta 1.5 Control DHCP: (LC-217)
    • VM hardware compatibility is now version 19.
    • You can now swap RAM while the system is running.
  • Chimera 3.12: (LC-218)
    • VM hardware compatibility is now version 19.
    • You can now swap RAM while the system is running.
  • CraftyRabbit 3.12: (LC-219)
    • VM hardware compatibility is now version 19.
    • You can now swap RAM while the system is running.
  • P7 SimSpace Internet Server w/ Docker: (LC-198)
    • VM hardware compatibility is now version 19.
    • Open VM Tools is now version 12.3.5.
    • You can now swap RAM while the system is running.
    • VM ulimits are removed.
    • Docker container images for Malware Information Sharing Platform (MISP) and is-inet are corrected.
  • P7 DMZ DNS w/Docker: (LC-200)
    • VM hardware compatibility is now version 19.
    • Open VM Tools is now version 12.3.5.
    • You can now swap RAM while the system is running.
    • VM ulimits are removed.
    • Local Docker container images for Unbound are corrected.
    • The VM is configured to use Puppet with the preexisting modules.

Configuration module updates

  • P7-Docker Profile: Configures Docker settings for Chimera and Craft. (LC-200, LC-198, LC-236)
  • P7-NewHole: (LC-218, LC-219)
    • Installs NewHole in ranges, adding attack emulation support to Windows 11.
    • DrainHole and NewHole can be installed side by side without causing conflicts.
    • Attack emulation checks for NewHole first and uses DrainHole if NewHole isn’t available.
  • P7-Unbound DNS: Reverse Record with Pointer 1: Creates a pointer record on Unbound and containerized Unbound. (LC-200, LC-198)
  • P7-Unbound MX Record 1 / 2: Creates MX records on Unbound and containerized Unbound. (LC-200, LC-198)
  • P7-Reverse Proxy: (LC-200, LC-198)
    • Users can now define listening ports.
    • Hard-coded values are removed.
  • P7-Linux: Static IP Address: Includes the built-in netcheck class, which no longer needs to be added manually through the class tabs in Platform. (LC-200, LC-198, LC-236)
  • Ansible: Ansible is now a built-in Puppet class, not an external module. (LC-200, LC-198, LC-236)

Puppet module updates

  • Simspace_install_newhole: Corrects the NewHole installation process to prevent context errors when running attack emulation scenarios. (LC-218, LC-219)
  • Puppet_splunkforwarder: (LC-143)
    • Supports Splunk Forwarder 10.2.1 (build c892b66d163d).
    • Supports newer Linux distributions, including Kali 2025.4.
  • Python: Updates environment variables to support newer Linux distributions, including Debian 13 and Kali 2025.4. (LC-200, LC-198, LC-236)
  • Reverse Proxy: Removes hard-coded values from reverse proxy templates. (LC-200, LC-198)
  • Docker_ansible: docker_ansible is now a built-in Puppet class, and hard-coded values are removed. (LC-200, LC-198, LC-236)

Platform fixes

  • Security update: portal-suite runtime base image (CVE-2025-68973): A security scan found a high-severity common vulnerability and exposure (CVE) in the portal suite runtime base image. This release updates the affected system package to a patched version, reducing the attack surface for Platform services that use this image. (PRTL-5271)
  • CKT tags update correctly in live action events launched from a path: When you launched an LAE from a live action plan (LAP), the associated cyber key terrain (CKT) couldn’t adapt to changes. Platform now correctly updates the CKT when the LAE is part of an LAP. (PRTL-5231)
  • Range shutdown failures now show specific error messages: When a range shutdown failed because a VM power action couldn’t complete—for example, because VMware Tools wasn’t running—Platform showed a generic error that didn’t identify the affected VM. Platform now shows a specific error message that names the VM and explains the cause. (PRTL-2576)
  • Network interface subnet selection now saves correctly: When you configured a VM’s network interface in a range and selected Real Internet as the subnet type, the Range Control value overwrote your selection on save. Platform now saves the selected subnet value correctly. (PRTL-1785)
  • VM console no longer opens duplicate windows: Clicking to open a VM console in a range could open multiple browser windows for the same console. Platform now focuses the existing console window instead of opening a new one when a console is already open for that VM. (PRTL-1718)
  • X button in Clone Deployment dialog now closes correctly: The X button in the Clone Deployment dialog didn’t close the dialog. Platform now closes the dialog when you select X. (PRTL-5083)