Independent, vendor-neutral review for Splunk-centric teams building detection rules and testing coverage against real attack telemetry.
Review date: July 2026 · Rating: 4.0 / 5 · Verdict: Best free option for Splunk shops wanting realistic detection engineering practice.
Splunk Attack Range is an open-source project (Apache 2.0) maintained by the Splunk Threat Research Team. It spins up a complete attack simulation environment in AWS or Azure using Terraform — Windows domain controllers, Linux servers, attack VMs, and Splunk Universal Forwarders pre-configured to ship telemetry into your Splunk instance.
The key differentiator: all attack telemetry feeds directly into your Splunk instance. You are not training in a generic lab — you are training in your Splunk, with your dashboards, using your detection rules against real adversary behavior.
I have deployed Splunk Attack Range for three Splunk-first teams. In every case, the moment an analyst sees their own detection rule fire against Atomic Red Team telemetry in their own Splunk instance, the lightbulb goes on. That is the value — not the lab itself, but the bridge between theory and their actual workflow.
Splunk Attack Range is "free" software but not free to run:
Total first-year cost for a team without spare engineering time: $6,000–8,000 (hosting + labor). Still cheaper than commercial platforms, but not zero.
| Feature | Splunk Attack Range | RangeForce | Security Onion |
|---|---|---|---|
| License cost | $0 | $300–1,200/user/yr | $0 |
| Hosting cost | $50–200/mo | $0 | $50–150/mo |
| SIEM integration | ✅ Splunk-native | ✅ Multi-SIEM | ✅ Elastic/HELK |
| Setup difficulty | Medium | Low | High |
| Team features | ❌ None | ✅ Built-in | ❌ None |
| Scenario updates | Manual (Atomic) | Quarterly | Manual |
Splunk Attack Range is the right choice when your team lives in Splunk and you want detection engineering practice that maps directly to your production workflow. It requires technical skill to deploy and maintain, but the payoff — analysts who understand how their detection rules behave against real attack telemetry — is worth the investment. If you do not use Splunk or lack cloud engineering capacity, look elsewhere. For Splunk shops with an engineer who can spare a day of setup, it is the best free detection lab available.
I help teams match their existing SIEM and skill level to the right training infrastructure — whether that is Splunk Attack Range, a commercial platform, or something in between.
Work With Todd →