Loading... Loading...
Grenze Logo
GRENZE International Journal of Engineering and Technology Vol. 12 (2026), Issue 1

VulneraSim: A Modular Cyber Range for Simulated CVE Exploitation and Defense Engineering

Authors

Priyanka Devi, Vikash Upadhyay, Ankur Ambani, Niskarsh Sharma

Abstract

Cybersecurity training requires practical field conditions where and attackers and defenders can exercise strategies without compromising the production systems. Here we present VulneraSim, an open-source modular cyber range built to simulate real-world Common Vulnerabilities and Exposures (CVEs) to provide practical training in both exploitation and defense engineering. The platform ensures that any issues in vulnerability are isolated within well managed experimental units, and it recreates enterprise like systems with targets that include Linux and Windows. In contrast to the current solutions, which dwell more on one side offensive or defensive, VulneraSim combines both red and blue teams workflows with a common workflow. Learners are able to utilize reconnaissance, exploitation, privilege escalation, and persistence at the same time that they implement defensive options monitoring, patching, and hardening of systems. Our analysis shows that VulneraSim boosts the learning of practical skills upon completion compared to conventional Capture-the-Flag (CTF) tasks with 85% of the respondents revealing their increased awareness on how vulnerabilities are addressed in the real world. The modular architecture allows deployment of new CVE scenarios in a short time, thus is adaptable to new threats and could be used in both academic and professional learner settings.