

When an incident hits your SOC, your analysts will be investigating, analyzing and acting directly in the SIEM they use every day, with the queries, user interface, and workflows specific to that tool. Train them on the concepts alone and the readiness you signed off on describes an environment they will never really work in. So the question worth asking about any blue team exercise is: does the score at the end tell you how your team will perform when the attack succeeds?
If your organization runs on CrowdStrike, your defenders can now exercise directly there. Starting now, CrowdStrike Falcon Next-Gen SIEM is available in Dynamic Threat Ranges, alongside Splunk, Elastic and Microsoft Sentinel. Teams provision their own instance and work through detection and investigation exercises in a dedicated environment, on the platform their organization has already standardized on.
How an exercise builds resilience for your team
Each range is built against a specific live-fire scenario or sector, and is set up for either incident response or threat hunting. Teams open on a briefing that covers the attack and how it moves through the environment, what the exercise is focused on, and how they'll be measured, with the adversary techniques mapped to MITRE ATT&CK. From that point they get no feedback at all, so they have to read the behaviors in front of them in the SIEM and decide for themselves whether what they're seeing is a live threat actor.

The team is measured on things like mean time to investigate, escalation and accuracy within each range. Set a baseline, put the same people against a different attack chain in the same CrowdStrike environment, and you can see whether the gap closed. Compare across teams and you can tell which shifts are ready for a real attack and which need another pass.
Testing teams under real conditions
Every team is provisioned with a fresh range before the exercise starts, and each team's environment is isolated. Several teams can work the same scenario at the same time without access to each other's data, so what comes back reflects how that specific team performed rather than a blended picture.

Within that range, escalating ends the exercise, and that’s what separates this type of readiness from classroom training. Escalate early on thin evidence and the exercise closes before the picture is complete. Hold out for certainty that isn't coming and the clock runs out. Your analysts have to judge when they have enough to raise it, which is the judgment that decides how a real incident goes.
The facilitator keeps visibility over team progress throughout and can see every response each participant submits. The debrief is then grounded in what people did in the tool, not what they remember doing.
Align exercising with the platform decision you already made
Choosing a security platform is a long, expensive decision. Running blue team exercises in a different SIEM only gets you part of the way, because the hours your defenders spend practicing go into a console they'll never encounter in normal operations.
Bringing CrowdStrike into Dynamic Threat Range puts those hours back into the environment you're paying for and the one your team is measured in. For Security Team Leads, that means understandable metrics like MTTI and accuracy scores that describe readiness in your real stack.
Get started
- Already working with Immersive? Get in touch to enable CrowdStrike Falcon Next-Gen SIEM for your teams.
- Exploring Immersive for the first time? Book a demo and see Dynamic Threat Range run end to end.

See how to prove readiness with one platform.
See how Immersive One helps technical teams and leaders prove readiness, close capability gaps, benchmark progress, and report cyber resilience with confidence.
