PRACTICE
Cybersecurity cannot be mastered by reading about it alone.
Take the knowledge you have learned systematically through CyBOK, apply it in a hands-on environment, and verify it for yourself.
Cyber Hiroshima connects CyBOK’s 21 Knowledge Areas with hands-on exercises in SudoRange, a cloud-based cyber range provided by Wales-based SudoCyber, creating a learning environment that helps people move from knowing to doing.
You can choose what to practise according to your goals and experience, using Knowledge Area, difficulty, Red Team / Blue Team, Cyber Kill Chain, NIST CSF and MITRE ATT&CK.
FROM KNOWLEDGE TO PRACTICE
CyCyBOK is a body of knowledge for understanding the broad field of cybersecurity in a systematic way.
Rather than learning networks, cryptography, authentication, software, malware, forensics and risk management as isolated topics, it helps you understand how each fits within cybersecurity as a whole.
Understanding knowledge, however, is not the same as being able to use it.
Cyber Hiroshima brings CyBOK and SudoRange together to support a learning cycle between knowledge and practice.
Read the relevant Knowledge Area to understand its underlying principles, terminology and ways of thinking.
Consider why you succeeded or failed, and connect what happened in the lab back to the knowledge.
Use what you have understood as a foundation for related Knowledge Areas or more advanced labs.
CYBOK × SUDORANGE
SudoRange includes hands-on labs mapped to the 21 Knowledge Areas defined in CyBOK.
After understanding the principles and concepts in CyBOK, you can move to labs related to that area and confirm what you have learned through hands-on work.
The number and type of labs vary by area.
11 Labs
Areas relating to organisational risk management, governance and security decision-making.
3 Labs
Laws, regulations, and compliance relating to cybersecurity.
18 Labs
The relationship between people and security, including human behaviour, decision-making and security awareness.
7 Labs
Privacy, personal data and rights in the online environment.
36 Labs
Networks, protocols, communications, and network attacks and defence.
18 Labs
Security of the hardware that makes up computers and electronic devices.
5 Labs
Security in environments where physical systems and digital systems are connected.
18 Labs
Security relating to the physical layer of communications and to wired and wireless telecommunications.
20 Labs
How cryptographic techniques are applied in real systems and protocols.
16 Labs
Fundamental principles of cryptography, including algorithms and keys.
30 Labs
Security of operating systems, access control, privileges and virtualised environments.
41 Labs
Security of environments in which multiple systems interact over networks.
35 Labs
Mechanisms for verifying users, granting appropriate permissions and tracing actions.
5 Labs
Using mathematical and formal methods to analyse and verify system security.
7 Labs
Software vulnerabilities and secure implementation.
74 Labs
Attacks and defence in web applications and mobile environments.
1 Lab
Processes for building software securely from design and development through testing and operation.
49 Labs
Practical study of malware, attack techniques and the exploitation of vulnerabilities.
11 Labs
Understanding adversaries’ objectives, behaviours and tactics.
2 Labs
Security monitoring, detection, response and incident management.
30 Labs
Collecting and analysing digital evidence to investigate what happened.
FIND YOUR LAB
SudoRange labs are organised not only by CyBOK Knowledge Area, but also by difficulty, learning type, attack process and security frameworks.
You can choose exercises that suit you based not only on what you want to learn but also on your current experience, role, and whether you want to work from an offensive or defensive perspective.
DIFFICULTY
Labs can be selected by difficulty to suit your experience and skill level.
| Level | Number of Labs |
| Level 1 | 51 |
| Level 2 | 37 |
| Level 3 | 168 |
| Level 4 | 16 |
| Level 5 | 5 |
| Level 6 | 62 |
| Level 7 | 11 |
| Level 8 | 3 |
LAB TYPE
Understand attack techniques and vulnerabilities from an attacker’s perspective, deepening the knowledge needed for defence.
125 Labs
Learn security from a defensive perspective through monitoring, analysis, detection and response.
66 Labs
Build technical skills and understanding step by step through guided exercises.
278 Labs
Use the knowledge and skills you have learned to solve a given challenge.
75 Labs
CYBER KILL CHAIN
Using labs associated with each phase of the Cyber Kill Chain, you can learn step by step how an attack is prepared, reaches its target and carries out actions within a system.
| Phase | Number of Labs |
| Reconnaissance | 49 |
| Weaponization | 9 |
| Delivery | 13 |
| Exploit | 82 |
| Install | 17 |
| Command & Control | 5 |
| Action On | 36 |
NIST CSF
Labs associated with the Functions of the NIST Cybersecurity Framework allow learners to practise the cybersecurity activities required within an organisation.
They can also be used when planning workforce development focused on specific security functions in businesses, local authorities and educational institutions.
| Function | Number of Labs |
| Identify | 24 |
| Protect | 91 |
| Detect | 27 |
| Respond | 8 |
| Recover | 3 |
MITRE ATT&CK
MITRE ATT&CK is a knowledge base that organises behaviours observed in real-world adversaries.
In SudoRange, labs associated with ATT&CK Tactics allow you to practise specific attack phases and behaviours.
| Tactic | Number of Labs |
| Reconnaissance | 4 |
| Resource Development | 52 |
| Initial Access | 14 |
| Execution | 5 |
| Persistence | 22 |
| Privilege Escalation | 43 |
| Defense Evasion | 12 |
| Credential Access | 16 |
| Discovery | 6 |
| Collection | 3 |
| Command and Control | 1 |
| Exfiltration | 4 |
| Impact | 2 |
* MITRE ATT&CK includes 14 Tactics, including Lateral Movement. This page lists the Tactics for which labs are currently classified in SudoRange.
FOR LEARNERS & ORGANISATIONS
Use CyBOK to understand the broader cybersecurity landscape, then work hands-on in related labs.
You can begin learning systematically even if you are still at the stage of not knowing what to learn first.
Choose exercises relevant to your work or the skills you want to develop through Knowledge Areas, MITRE ATT&CK, Red Team / Blue Team and other classifications.
Design training that combines knowledge with hands-on exercises rather than ending with lectures alone.
Learning topics can also be combined to match different roles and responsibilities.
Introduce practical cybersecurity education without building and operating a large cyber range of your own.
SudoRange can be considered for education tailored to students, teaching staff, local authority staff and other people in the community.
Understand the structure with CyBOK.
Try it for yourself with SudoRange.
Review the outcome, then return to CyBOK.
Cyber Hiroshima is working to create an environment where people can continue learning cybersecurity by moving back and forth between knowledge and hands-on practice.
Already have an account? Log in to SudoRange →