A one-page guide for executives and exercise leads: pick a scenario, open a room, invite your team with a join code, run the rounds and see what lands in the evidence record.
Exercise lead: Opens, starts, advances and closes rooms; invites the team; sees the live tally of decisions. Participant: Joins with the room code and chooses one decision per round. A recorded decision cannot be changed. Observer: Joins with the room code and watches the exercise and the running tally, without voting.
A live room is a real-time exercise with your own team, inside your organisation's own Cyber Range. Only exercise leads can open a room, so start by confirming who in your organisation holds that role.
Sign in to VulnTrek and open Cyber Range. If you are an exercise lead, the Live rooms button at the top right opens the room panel. Participants and observers see the same panel, but with the join box only.
One lead runs the room: they start it, move it on round by round and close it. Organisations with several leads can each open their own room, for example one per department or one per board session.
A room runs round by round, and each round is one decision point for the team. Allow time for the discussion after each round — the debrief is where the value is, not the voting itself.
The scenario decides what your team is reacting to. Every scenario is built around a real, publicly reported incident, and uses fictional organisations and illustrative loss figures so the decisions feel real without naming victims.
In the Live rooms panel, open a new room and pick a scenario from the list. Each entry names the real incidents it draws on — for example the MOVEit breach, the Bangladesh Bank SWIFT fraud or the CrowdStrike outage. Scenarios switched off for your organisation by the VulnTrek team do not appear in the list.
Type a room name of at least three characters — something your team will recognise, such as “Board drill Q4”. The Open room button unlocks once the name is typed.
Opening the room gives it a join code and puts it in the open state. Nothing has started yet: the room waits until you press Start, so you can gather people first.
On the Cohort invites tab, name the group (for example “Executive board”), paste the email addresses and pick the role. People already in your organisation get access at once; anyone outside it gets access automatically once they accept your organisation invitation. Each person receives a Cyber Range invitation email.
The join code is how the rest of the room gets in. It is a short code shown on the room card — share it in your own channel or read it out at the start of the session.
Everyone signs in to VulnTrek with their own account and opens Cyber Range, then Live rooms. No separate Cyber Range account or password exists.
Paste or type the join code into the “Join with a code” box and press Join. The Join button becomes available once the full code is entered.
If the room is still open rather than live, you will see “Waiting for the lead to start.” — you are in the room, and the exercise begins when the lead presses Start.
Codes are specific to your organisation and to that room. A closed room cannot be joined, and a code from another organisation will not open a room in yours.
Once started, the room moves in rounds. Each round is one decision point, and the team votes before the lead moves on.
Each round shows the decision options for that stage of the incident. A participant picks one option; the choice is recorded immediately and cannot be changed, and each person gets one decision per round.
The running count of the team's decisions is visible to the lead and to observers as votes come in, so the room can see where the team is split before the discussion.
The lead presses Next round to move on, and Close room to end it. Closing stops further decisions; decisions already recorded are never removed.
When a round completes, the debrief is written to your organisation's evidence record with the decisions and the reasoning captured at that point. Corrective actions raised from the discussion are recorded separately and close only when a retest passes.
Everything that happens in a live room that counts as evidence is written once and cannot be edited afterwards — so an exercise can be shown to a reviewer months later.
Two things: debriefs recorded when an exercise round completes, and decisions voted in live rooms. Each one is linked to an entry in VulnTrek's append-only evidence record and carries its own evidence fingerprint.
Live room messages stay in the room and are not part of the evidence record. Only decisions and debriefs are linked to it.
Organisation admins export debriefs and evidence-linked decisions, with their evidence fingerprints, as CSV or JSON from Admin → Cyber Range → Evidence record.
This is training evidence: a record that exercises happened and what your team decided. It is not certification and VulnTrek does not claim it proves compliance. Decisions recorded before evidence linking was enabled are not included as evidence-linked decisions.
Confirm who holds the exercise lead role in your organisation Pick a scenario and name the room, then open it Share the join code, or invite a named cohort by email Start the room, let each round be decided, then move on Close the room when the session ends Export debriefs and decisions from Admin → Cyber Range → Evidence record