Know where the team stands
Baseline capability against real tasks. See where skills are strong, where gaps sit, and where development needs to start.
Give every analyst the hands-on practice to triage with better judgment, respond under pressure, and take more work off your senior team. Then measure whether MTTR, escalation rates, and L1 resolution are actually improving.

Your junior analysts complete training, but still escalate alerts your senior team could close in minutes.
New hires take months to become useful on the live queue.
Your strongest responders carry knowledge the rest of the team hasn’t built yet.
Runbooks exist, but the team hasn’t rehearsed them together against a realistic attack.
You report training activity, but can’t show the CISO whether the SOC is getting faster or better.
AI agents are taking on more triage, but your analysts haven’t practiced when to trust, validate, or override their output.
The problem isn’t a lack of training.
It’s not knowing whether the team can perform when the alert is real.
HTB Cyber Workforce Development gives your SOC a repeatable way to find gaps, build skills, rehearse response, and measure what changes.
Baseline capability against real tasks. See where skills are strong, where gaps sit, and where development needs to start.
Give people structured, role-based paths from entry to advanced levels. Build the technical depth and judgment analysts need as their responsibilities grow.
Give analysts realistic alert practice on demand, then bring the team together against full attack chains. Rehearse detection, triage, escalation, and response before the real incident.
Track response performance and identify where the team still breaks down. Feed those gaps back into the next round of development and drills.
Then repeat.
SOC Range
Analysts work realistic alerts from backlog to closure using a real SOC workflow.
They investigate malware, phishing, suspicious logins, endpoint activity, email artifacts, and threat intelligence with alert-specific playbooks and a SIEM toolbox.
That means juniors can practice before the first real shift, then keep building judgment between team exercises.
The result
More alerts resolved correctly at L1. Fewer false escalations. More senior time spent on work that needs senior expertise.

Threat Range
Individual skill is only part of SOC readiness.
Threat Range puts SOC and DFIR teams through realistic, full-chain attacks together. Analysts detect, triage, escalate, and resolve the same incident under pressure.
You see where handoffs stall, where decisions break down, and where the team needs more work.
Then run it again.

Threat Resilience Index
Threat Range measures performance across the incident lifecycle.
Track metrics including:
The Threat Resilience Index gives you an objective view of team readiness, while individual contribution remains visible inside the exercise.
Instead of telling the CISO the team is improving, show it.

Analysts work through realistic alerts, investigations, infrastructure, and attack chains rather than relying on theory alone.
SOC Range builds the analyst’s operational judgment. Threat Range tests how the whole team performs together.
Role-based learning, hands-on practice, team exercises, and measurement sit in one continuous program rather than separate training activities.
Move the conversation beyond participation. Track the measures SOC leaders already care about, including MTTR, MTTA, escalation rate, and L1 resolution.
Structured development helps analysts build deeper capability while giving managers a clearer view of where people are ready to take on more.

Since training with HTB, we’ve seen greater agility in addressing any issue that might arise and better detection rates. It’s been a real investment in strengthening our in-house talent. The HTB SOC Analyst pathway has provided a standard skill level that we can expect our defenders to live up to and to be measured against.
The Analysts
Forrester recognition


HTB’s vision for hybrid human-AI readiness is called "compelling."
"Organizations looking to engage cybersecurity talent and prepare them for an agentic future through gamified, challenge-based learning will find Hack The Box a strong fit.
G2 CROWD
We'll show you how to:
Tailored around your incident response priorities, not a generic platform tour.
The point is to reduce the work that keeps landing on the same senior analysts. Scenario-based drills build the judgment that helps juniors resolve more correctly at L1 and cuts unnecessary escalation.
SOC Range also gives individual analysts on-demand practice that can fit around shifts without scheduling a full team exercise.
Certifications can validate knowledge. They don’t show how the team detects, triages, escalates, and responds together during a realistic incident.
HTB connects structured skill development with individual SOC practice, full-team drills, and measured response performance.
Agents can take more of the queue. Your team still owns the consequences when an automated verdict is wrong.
Analysts need the judgment to know what to validate, what to escalate, and when to override automation.
SOC Range gives individual analysts on-demand practice against realistic alerts and SOC workflows.
Threat Range brings the team together against end-to-end attack chains and measures how well they detect and respond as a unit.
They address different parts of the same readiness problem.
SOC leaders can track performance measures including MTTD, MTTA, MTTR, false-positive and false-negative accuracy, SLA adherence, and escalation quality.
Threat Range also provides the Threat Resilience Index for an objective view of team readiness.
The Enterprise Platform includes Single Sign-On and content management, plus APIs and LMS integration, so access, progress, and readiness data can connect with the systems your organization already runs.
Build analyst judgment before the queue tests it.
Drill the team before the attack tests it.
Measure readiness before someone asks you to prove it.
Fill the form to schedule a live product demo and Q&A about our cyber readiness solutions.
Maximum curriculum management flexibility, enhanced skills reporting, and engaging gamification features. Book a demo to get the business results.
Your plan includes:
Product Spotlight
Threat Range helps you prove how well SOC, DFIR, and incident response teams perform when it matters most. Build sharper coordination, expose costly gaps earlier, and give leadership clear evidence of readiness, speed, and resilience.
Whitepaper
This report examines how organizations and cybersecurity professionals are adapting to emerging risks, particularly those driven by artificial intelligence, which are introducing new attack surfaces and reshaping security priorities.