Files, folders, accounts, permissions, firewall rules and saved network recordings — all of it inside the browser tab. Students type real commands and watch the machine change.
No virtual machines to build. No lab images to maintain. No cloud accounts, no licenses, nothing running on a server. A student opens the page and starts working.
A gateway recorded ten minutes of traffic. Two machines opened doors they were not allowed to. This is an actual activity from AP Cybersecurity Practice Problems.
A scripted walkthrough of a range activity — not a live range on this page. The terminal, the Script and the grading panel are the ones students work in.
A cyber range normally means virtual machines, lab images and a network somebody has to keep isolated. This one is a web page.
The machine builds itself when the activity loads — a second or two, and the prompt is waiting. No accounts to create, no VM to boot, no lab to book. A substitute teacher can run the lesson.
The range cannot reach the internet or anything on your network — it exists only in that browser tab. Students can try the risky thing, break it, and put it back exactly as it started with one click. That freedom is what makes the lesson stick.
Each exercise builds its own machine, already set up for that task — the accounts, permissions, files and recordings that question needs are in place before the student types anything. Two exercises on the same page are two separate machines, and each student’s copy is their own, in their own browser. One class or two hundred is the same amount of work for you: none.
A managed Chromebook is a first-class device here — no admin rights, no installs, no special network access. It works the same on an iPad or a laptop, at school or at the kitchen table.
Real commands against a machine that answers the way a machine does — not multiple choice about what a machine would do.
Read who may do what, then change it. Set modes and ownership, move between accounts and groups, and find out the hard way that copying a protected file makes a new one that is not protected.
Ask whether a connection is allowed and get told which rule decided it. Read a rule table in the order it is read, add a rule at the position that matters, and see the answer change.
Open a saved recording of real-looking traffic and narrow it down until the answer falls out — which machine opened a connection it should not have, and to which port.
Make a key pair, seal a file so only one person can open it, sign something and check a signature — and learn why sealing to your own public key protects nobody.
Every command that ran is kept in a Script beside the terminal — including the ones the machine refused, which is often where you can see what a student was reasoning about.
One click grades the machine as it stands and reports a row per requirement, saying which one is not met yet. Checking costs nothing and never disturbs their work.
The range is emulated — it models a Linux-like machine rather than running one. That is the trade that makes it instant, free and impossible to break.
| Feature | Alps cyber range | A virtual machine lab |
|---|---|---|
| Files, folders, permissions, owners and groups | ||
| Accounts and groups to move between | ||
| Firewall rules and a network to reason about | ||
| Saved packet captures to read and filter | ||
| Keys, signatures and sealed files | ||
| Ready for a lesson | When the page opens | Built and maintained by someone |
| Runs on a managed Chromebook | ✓ through a remote-desktop gateway | |
| Something running on a server or in the cloud | Nothing at all | A VM per student, or one they share |
| The work happens on the student’s own device | ✗ — it runs on the remote machine | |
| A machine per exercise, per student | One box, shared and reset | |
| Running programs, and editors like vi or nano | ||
| root, sudo and a real privilege boundary | ||
| Internet access and live traffic capture | ||
| Pipes, loops, several commands on a line |
The first five rows are what an introductory cybersecurity course actually asks students to do. Type something the range does not have and it says so, and usually points at what to use instead — nothing breaks, and nothing is silently wrong.
Students are not limited to the exercises, either. They can open a blank range in the Coding Sandbox whenever they like — as many as they want — just to try something out.
Teaching cybersecurity from your own material? Alps can onboard a book as an interactive course — we work with publishers and support licensed editions. Get in touch.
A cyber range that needs no virtual machines, no lab images and no admin rights — just a browser. Start with the free Educator Basic tier.