Enterprise · the product suite

Train, compete, evaluate, defend — against threats that didn’t exist yesterday.

Upskill a SOC, run a branded CTF, benchmark autonomous agents, stand up a national programme, or harden your OT defenders: it’s the same foundation of AI-generated, validated, never-repeated scenarios underneath all six products. Pick the one that fits your needs — or combine two.

PRODUCT 01

Enterprise Training

DFIR scenario training for your SOC — multi-stage campaigns, per-analyst calibration, audit-ready telemetry.

  • Per-analyst ELO + 13-axis skill vector
  • Private challenge libraries per tenant
  • SSO/SAML · GDPR · SOX · PCI-DSS · NIST
from $25 / seat / mo
Details ↓
PRODUCT 02

DFIR Range / Incident Reconstruction

Landmark incidents, defanged into multi-stage DFIR investigations your SOC and blue teams can work end-to-end.

  • Real-incident-inspired, fully fictionalized
  • Alert triage → forensic question-banks
  • 3 campaigns live · ELO-matched per analyst
Custom pricing
Details ↓
PRODUCT 03

CTF Event Hosting

Run your own branded competition using LevelUp — AI-generated and fresh per event, with zero writeup leakage.

  • Whitelabel — your domain, your logo
  • Full stack: scoreboard, teams, hints, replay
  • Handled end-to-end or self-run
from $2K / event
Details ↓
PRODUCT 04

AI Agent Evaluation

A REST API for benchmarking autonomous security agents against fresh, real sandboxes — not stale benchmarks.

  • Developer tier free — 1K calls / mo
  • Fresh nightly — no benchmark memorisation
  • Agent-vs-par: solve time, tool use, retries
Free for developers
Details ↓
PRODUCT 05

Education / Curriculum Integration

Ready-made curriculum sets for university programmes and national cyber-talent initiatives — with split-infra to deploy on your own cloud.

  • Institutional or national-scale rollout (1K – 10K seats)
  • Split-infra — deploy on your AWS / GCP
  • Curriculum alignment · multi-year terms
Custom pricing
Details ↓
PRODUCT 06

OT Readiness

Train OT defenders on calibrated industrial-protocol scenarios — fresh every week, simulators only.

  • Modbus · DNP3 · S7 · OPC-UA · EtherNet/IP
  • Anomaly hunts, IR triage, safety-violation
  • Simulators only — never real PLC firmware
Custom pricing
Details ↓
Product 01 · Enterprise Training

Scenario training that calibrates to every analyst.

Multi-stage campaigns with per-user variants and platform-side grading against MITRE ATT&CK, on a REACTOR-generated stream that stays fresh. Built for security leaders buying skills uplift and training managers buying content.

from $25 / seat / moBook a pilot →
CALIBRATION
ELO + 13-axis skill vector

Per-analyst rating across every category, so difficulty meets each learner at the right stretch.

CONTENT
Private challenge libraries

Hand-curated scenarios to your brief plus REACTOR-generated challenges, visible only to your team.

ASSURANCE
Behavioural intel + session replay

Keystroke cadence, tool use, AI-vs-human signatures — every keystroke replayable for instructor review.

COMPLIANCE
SSO + audit reporting

SAML 2.0 with your IdP, training-hour attestations and mappings to GDPR, SOX, PCI-DSS, NIST.

cohort.blue-rotation-q2 · live
// 24 analysts · 8 week rotation · Purple + Blue
seats: 24 / 30   sso: saml · enabled

assignments:
 week 1   triage fundamentals  22/24
 week 2   dfir evidence chain     18/24
 week 3   malware static           12/24 active

squad avg ELO:
 dfir        1642 ▲ +88
 malware    1324 ← gap
Product 02 · DFIR Range / Incident Reconstruction

Real incidents, defanged into investigations your team can work.

Narrative DFIR campaigns — seven-plus stages from ticket triage through evidence analysis, MITRE mapping, on-chain tracing and executive write-up. Per-user variants mean two analysts see different IOCs, actors and timestamps on the same campaign. For IR consultancies and breach-readiness programmes that think in incidents. Three campaigns run today.

Campaign 01 · Supply-chain

Trace a poisoned software update.

A trusted build pipeline ships a tampered update and a quiet beacon wakes across the estate.

  • Beacon alert triage — verdict, IOCs, MITRE
  • Host forensics — find the tampered artifact
  • Network & DNS — map the C2 channel
  • Lateral movement & forged-token abuse
Defanged
Campaign 02 · Crypto

Follow a multisig drain on-chain.

A malicious signing flow tricks approvers into a hostile upgrade; a custody wallet empties in minutes.

  • Drain alert triage — verdict, IOCs, MITRE
  • Transaction analysis — the subverted signature
  • First-hop fund tracing — follow the outflow
  • Cross-chain timeline — mixers, bridges
Defanged
Campaign 03 · OT/ICS

Catch a rogue command on a water plant.

An exposed remote-support tool lets an actor pivot from IT and write a rogue Modbus setpoint to a dosing PLC.

  • SCADA alarm triage — verdict, MITRE ICS
  • IT→OT pivot — the dual-homed host
  • Modbus forensics — the rogue FC6/FC16 write
  • Containment — segment, lock remote access
Defanged
How a campaign runs
01 · ALERT TRIAGE
Opens on a SOC ticket

Verdict, IOCs, MITRE techniques and a containment call — scored platform-side, not on the honour system.

02 · QUESTION-BANKS
Staged forensic banks

Over logs, on-chain traces and supply-chain artifacts. One answer at a time, hash-compared.

03 · ELO-MATCHED
Right stretch per analyst

A junior and a lead work the same incident at the level matched to their skill vector.

Flagship campaign · 7 stages · 2025 crypto-exchange compromise
  1. Ticket triage — verdict, IOCs, MITRE
  2. Evidence analysis — 3 questions
  3. JS bundle reversing — 5 questions
  4. MITRE mapping — 10 questions
  5. On-chain first-hop laundering — 4 questions
  6. Cross-chain timeline — 3 questions
  7. Executive write-up — free-form ticket
Roadmap · engine behind DFIR Range

Incident Reconstruction — any breach report becomes a range in days.

Paste a public breach-report URL. REACTOR reads the advisory, extracts the attack chain, and reconstructs each stage as a deterministically-varied sandbox. A rekt.news post, a CISA advisory, a vendor PIR — all fair game.

Ingestion module in development; today we ship hand-curated campaigns.

Preview · incident.ingest (roadmap)
STAGE 01
Initial Access
STAGE 02
Lateral Movement
STAGE 03
Exfiltration
STAGE 04
Impact
Product 03 · CTF Event Hosting

Run a branded competition — fresh, per event, leak-proof.

AI-generated challenge sets unique to each event mean no writeup leakage and no shared answers between attendees. Whitelabel it on your domain, or let us run it end-to-end.

from $2K / eventTalk to us →
BRANDING
Whitelabel

Your domain, your logo, your colours — attendees never leave your brand.

PLATFORM
Full competition stack

Scoreboard, teams, hints and session replay out of the box.

CONTENT
AI-generated per event

A fresh challenge set every time — no shared answers between attendees.

DELIVERY
Run it your way

Handled end-to-end by our team, or self-run on the platform.

Product 04 · AI Agent Evaluation

Benchmark autonomous security agents on fresh, real sandboxes.

A REST API that evaluates agents against REACTOR-generated challenges that regenerate nightly — so you measure capability, not benchmark memorisation.

Free for developersGet API access →
TIERS
Free → Enterprise

Developer tier free at 1K API calls/mo; commercial and enterprise tiers add advanced analytics.

FRESHNESS
Nightly regeneration

New challenges every night — agents can’t memorise a static benchmark.

REALISM
Real-world sandboxes

Live Docker sandboxes, not multiple-choice — the work agents actually have to do.

METRICS
Agent-vs-par

Solve time, tool use and retries scored against a human/par baseline.

api.levelupctf.com · eval
// POST /v1/eval/run
agent:     "acme-soc-agent-v3"
challenge: reactor:dfir-triage/nightly

solved:     true   par_ratio: 0.74
solve_time: 412s   tool_calls: 18
retries:    2
Product 05 · Education / Curriculum Integration

National-scale talent programmes, on your own infrastructure.

For national cyber programmes and university curricula. Split-infra keeps generation with us and delivery with you — your data never leaves your tenant.

Custom pricingContact sales →
SCALE
1K – 10K seats

National-scale rollout with volume discounts and multi-year terms.

SOVEREIGNTY
Split-infrastructure

REACTOR runs in our cloud; delivery runs on your AWS or GCP tenant.

CURRICULUM
University alignment

CTF curricula mapped to course structure and learning outcomes.

TERMS
Multi-year

Long-horizon agreements built for public-sector procurement.

Split-infra — data residency
REACTOR
our cloud
Delivery
your AWS / GCP

Generation, validation and calibration happen on our side. The signed challenge images are deployed inside your tenant, where all analyst data stays.

Product 06 · OT Readiness

Train OT defenders on calibrated industrial-protocol scenarios.

Anomaly hunts, IR triage and safety-violation detection across the protocols your plant actually runs — calibrated to each defender, fresh every week, simulators only.

Custom pricingContact sales →
ModbusDNP3S7OPC-UAEtherNet/IP
SCENARIOS
Anomaly hunts & IR triage

Safety-violation detection on calibrated, real-protocol scenarios.

FORENSICS
Asset & protocol forensics

Asset discovery and protocol-level investigation across the control LAN.

SAFETY
Simulators only

Never real PLC firmware — calibrated simulators, fresh every week.

CALIBRATION
Matched to your skill

Difficulty ELO-matched to each defender, like every LevelUp product.

The engine behind all six products

Nine agents. One pipeline. The defensibility is the tech.

Every product above runs on REACTOR — a 9-agent pipeline running in production against every challenge on the platform. No stage is LLM-alone: every agent reads and writes to SAGE, the open-source memory framework underneath, so one agent’s lesson becomes the next agent’s starting context. The result: fresh, non-leakable, validated content at a rate a manual authoring team can’t match.

Designer
drafts the brief
Narrative
stamps the story
Static Analysis
deterministic lint
Validator
builds + solves
REACTOR
orchestrator
Calibrator
sets par time
Repair
patch, don’t regen
Deploy
signed image
Evolution Worker
nightly · 4 loops

Designer drafts. Static Analysis lints. Validator builds and proves solvability end-to-end. Calibrator scores difficulty. Repair patches on stage failure. Deploy hardens and ships. The Evolution Worker reruns the whole catalogue nightly.

Talk to us

Book a 30-minute demo.

A solutions engineer walks you through REACTOR against one of your rotations, SSO against your IdP, and a quote shaped to whichever product fits.

You’ll see:

  • → A live REACTOR run — a fresh challenge generated in real time
  • → Cohort setup against one of your rotations
  • → SSO against your IdP (bring a test tenant if you can)
  • → Private-library workflow and review gate
  • → Pricing shaped to your seat count and deployment model
  • → Split-infra architecture for regulated clients

Request a walkthrough

The full intake form captures your team size, compliance requirements, and timeline so the demo is tailored to your stack before we meet. Takes two minutes.

Enterprise | LevelUp