Platform

Everything a cyber training operation needs, in one system

Onyxium is not a video library with a quiz engine. It is training infrastructure: content, practice, live environments, assessment, and organizational control, designed together so every skill claim traces back to demonstrated work.

Structured curriculum

Courses → modules → sessions with objectives, prerequisites, theory, textbook chapters, slides, podcasts, and video. The flagship CSRP program spans 40 sessions and 160 hours, from foundations to AI security.

Interactive simulators

23 purpose-built browser consoles: packet inspection, firewall policy, IAM, IDS triage, DLP, Linux hardening, Active Directory, LLM defense, and more. Stateful, validated, instantly graded.

Real lab environments

Live Linux containers and full Windows Server machines, one per learner, provisioned on demand in the browser (terminal or full desktop) and torn down automatically.

Challenges with real flags

Capture-the-flag validation in real environments. Flags are generated per attempt, stored as salted hashes, compared in constant time, and every submission is recorded. Answer sharing is detectable.

Assessment & skill badges

Scenario quizzes, validated lab checks, and challenge solves roll up into skill badges with NICE Framework work-role codes: a credential earned by demonstration, not attendance.

Instructor command center

A live roster-by-session matrix, per-learner timelines, live environment monitoring, at-risk flags, and instructor-only walkthroughs for every lab and challenge.

Organization management

Multi-school tenancy, scoped roles (manager, instructor, content creator, recruitment), cohort groups, enrollment approval, and magic-link onboarding.

Audit & cost accounting

Every admin and content mutation logged with previous values. Live infrastructure cost per lab session, rolled up by day, week, and month.

Content API

Author and maintain lesson content programmatically through a governed API with a hard structural boundary: content tools can never touch lab code, images, or flags. Every write is audited.

The instructor side

Run a class, not a helpdesk

Instructors see the whole cohort live: who finished which lab, who is stuck, whose environment is running, and where flag submissions cluster. Hints are built in, full step-by-step solutions stay instructor-only, and every challenge ships with a walkthrough for session prep.

Judge it by using it