MAD20
MAD20 is a MITRE ATT&CK cybersecurity training and certification platform that spun out of MITRE Engenuity in 2024, serving enterprise security teams and individual practitioners with a six-certification curriculum and hands-on cyber range simulations.
- Company typePrivate
- Founded2021
- HeadquartersCharlotte, United States
- Headcount11–50
- GTM typeB2B and B2C
- OfferingSoftware
What MAD20 does
MAD20 is a cybersecurity training and certification platform built on the MITRE ATT&CK framework, spun out of MITRE Engenuity in 2024 as an independent for-profit entity (MAD20 Technologies LLC, headquartered in Charlotte, NC). The company certifies enterprise security teams and individual practitioners across six core programs—ATT&CK Fundamentals, Cyber Threat Intelligence, SOC Assessment, Adversary Emulation, Threat Hunting & Detection Engineering, and Purple Teaming—plus advanced topic courses on techniques such as Access Token Manipulation. Course content is developed by MITRE's own ATT&CK subject matter experts, and hands-on capability development is delivered through the MAD20 ARENAS cyber range, powered by a partnership with CYBER RANGES.
The platform operates on a four-tier subscription model: Lite ($990/month, self-paced Skills Hub), Basic ($5,798/year, adds Living Certifications), Advanced ($24,996/year, adds priority support and full ARENAS cyber range access), and Enterprise (custom pricing, 10+ participant minimum, with live in-person exercises and custom IT/OT range offerings). Go-to-market combines self-serve online enrollment for individuals, enterprise field sales for team deployments, and channel partnerships—including Trainocate, which serves as the authorized training partner across the ASEAN region. Certifications integrate with Credly and LinkedIn for professional credential display, and the company claims 171,500+ certified defenders across 3,815+ organizations in 36 countries, with named enterprise customers spanning financial services (Citi, Mastercard, Morgan Stanley), Big Tech (Google, Microsoft), telecom (AT&T, Verizon), and security vendors (Fortinet).
MAD20 originates from the MITRE ATT&CK Defender training program, which was transferred from the nonprofit MITRE Engenuity to MAD20 Technologies LLC in 2024 to scale commercial access to the curriculum. The company maintains close operational ties to MITRE, including access to the Center for Threat Informed Defense (CTID) adversary emulation library. It is a privately held LLC with 11-50 employees, no disclosed external funding, and revenue is generated entirely through subscription licensing and enterprise custom training contracts. No revenue figures, funding rounds, or financial performance metrics have been disclosed.
MAD20 firmographics
Firmographics- Name
- MAD20
- Legal name
- MAD20 Technologies LLC
- Website
- https://mad20.io
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- MAD20 is a MITRE ATT&CK cybersecurity training and certification platform that spun out of MITRE Engenuity in 2024, serving enterprise security teams and individual practitioners with a six-certification curriculum and hands-on cyber range simulations.
- Ownership category
- akta.pro rank
MAD20 industry classification
Industry- Product category
- Cybersecurity Training and Certification
- NAICS
- Computer Training (611420), Computer Training (61142)
- akta.pro primary industry
- Cloud & SaaS Security Awareness (e.g., M365/Google Workspace) (EDABAGAG)
Keywords
Where MAD20 is headquartered
LocationHeadquarters
- HQ city
- Charlotte
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
MAD20 business model
Business model- GTM type
- B2B and B2C
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Subscription Licensing: Recurring subscription revenue from tiered plans (Lite, Basic, Advanced) providing access to training content, certifications, and cyber range scenarios. Annual and monthly billing options available.
- Enterprise Custom Training: Custom live in-person exercises tailored to enterprise environments with minimum team size requirements, priced based on organizational needs and scope.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Lite - Self-paced training access for individuals |
| Subscription | Annual | Basic - Certification-focused annual plan |
| Subscription | Annual | Advanced - Comprehensive training with cyber range access |
| Other | Multi-year contract | Enterprise - Customized team training with expert instruction |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels5 records
MAD20 product offering
Product offeringCore offering
MAD20 provides subscription-based training and certification programs built on the MITRE ATT&CK framework, with six core certification tracks covering Fundamentals, Cyber Threat Intelligence, SOC Assessment, Adversary Emulation, Threat Hunting & Detection Engineering, and Purple Teaming. The Advanced and Enterprise tiers include hands-on cyber range scenarios delivered through the MAD20 ARENAS platform in partnership with CYBER RANGES. Certifications are issued as digital badges shareable via Credly and LinkedIn.
Product overview
MAD20 is a comprehensive MITRE ATT&CK training and certification platform that spun out of MITRE Engenuity. The platform offers a curriculum of six core certification programs (Fundamentals, Cyber Threat Intelligence, SOC Assessment, Adversary Emulation, Threat Hunting & Detection Engineering, and Purple Teaming) plus advanced topic courses on Access Token Manipulation. All training is delivered through a subscription-based model (Lite, Basic, Advanced, and Enterprise tiers) with the Advanced and Enterprise tiers including access to MAD20 ARENAS cyber range scenarios powered by CYBER RANGES. Users can earn and showcase certifications via Credly and LinkedIn integrations. The platform focuses on threat-informed defense training with courses developed by MITRE ATT&CK subject matter experts.
Differentiator
Problem solved
Functional benefit
Brands
- MAD20 ARENAS: Cyber range platform powered by CYBER RANGES for hands-on training scenarios including Red Team Challenges, ATT&CK Fundamentals, and Adversary Emulation exercises.
- MITRE ATT&CK Defender
Products and services
- ATT&CK Fundamentals Entry-level course introducing the MITRE ATT&CK framework as a globally accessible knowledge base and cyber adversary behavior model, covering framework structure, philosophy, and operational use cases for defenders. Includes 18 lectures, one hands-on lab, one range scenario, and 2 CPE hours.
- ATT&CK Cyber Threat Intelligence Certification Intermediate-level certification affirming ability to identify, develop, analyze, and apply ATT&CK-mapped intelligence. Includes 18 lectures, a full defensive recommendation walkthrough, and 13 CPE hours across narrative reporting, raw data analysis, storage and analysis, and defense recommendations.
- ATT&CK SOC Assessment Certification Intermediate-level certification for conducting Security Operations Center assessments that are rapid, low-overhead, and comprehensive. Covers SOC fundamentals, analysis, and synthesis with 17 lectures, heatmap and defensive recommendation walkthroughs, and 9 CPE hours.
- ATT&CK Adversary Emulation Methodology Certification Intermediate-level certification validating ability to conduct adversary emulation activities based on real-world threats. Covers TTP research, planning, implementation, and execution with 30 lectures, 7 hands-on labs, 60+ range scenarios via ARENAS, and 21 CPE hours.
- ATT&CK Threat Hunting & Detection Engineering Certification Intermediate-level certification affirming ability to leverage adversary TTPs from the ATT&CK framework to develop, test, tune, and employ analytics for detecting malicious cyber activity. Includes 28 lectures, a full analytics walkthrough, 60+ range scenarios via ARENAS, and 9 CPE hours.
- ATT&CK Purple Teaming Methodology Certification Intermediate-level certification validating understanding of leveraging purple teaming to emulate adversarial behavior and deliver actionable defensive recommendations. Includes 32 lectures, planning and execution walkthroughs, and 13 CPE hours.
- ATT&CK Detecting Access Token Manipulation Advanced topic course applying the TTP Threat Hunting Methodology to detecting T1134.001: Token Impersonation and Theft. Covers using Windows Sysinternals Suite for detection and implementing analytics for specific technique detection engineering. Includes 16 lectures, dozens of example walkthroughs, and 2 CPE hours.
- ATT&CK Emulating Access Token Manipulation Advanced topic course analyzing real-world examples of adversaries performing Access Token Manipulation, including token impersonation/theft sub-techniques from FIN8 and Shamoon, with walkthroughs and supplemental materials. Includes 16 lectures, dozens of example walkthroughs, and 2 CPE hours.
- MAD20 ARENAS Cyber Range Scenarios Hands-on cyber range scenarios delivered through the MAD20 ARENAS platform powered by CYBER RANGES. Includes MITRE ATT&CK Fundamentals (8 scenarios, 12 hours), Atomic Red Team (10 scenarios, 21 hours), Red Team Easy (15 scenarios, 60 hours), Red Team Medium (15 scenarios), and Red Team Advanced (14 scenarios, 56 hours) playlists. Enterprise customers receive custom range offerings in IT or OT environments.
Quantifiable outcome
- Organizations implementing purple teaming report 40% reduction in incident response times, 30% increase in detection of advanced persistent threats, and 25% improvement in overall security posture
- +5 more outcomes
Companies that use MAD20
Customer profileNamed customers11 records
Segments4 records
Ideal customer profiles2 records
MAD20 technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
Feature5 records
MAD20 partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and regional.
- CYBER RANGEScoreCYBER RANGES is MAD20's simulation-based cyber security capability development platform partner powering the MAD20 ARENAS cyber range. This partnership provides hands-on range scenarios for training, including MITRE ATT&CK Fundamentals exercises, Red Team challenges at multiple difficulty levels, and Adversary Emulation Atomic Red Team scenarios. Enterprise customers receive custom range offerings in IT or OT environments.
- TrainocateregionalTrainocate, a global leader in enterprise training, has partnered with MAD20 as the authorized training partner across the ASEAN region. Trainocate delivers MAD20's MITRE ATT&CK Defender training and certification programs to organizations in Singapore and surrounding markets.
- MITRE CorporationcoreMAD20 was originally developed by MITRE Corporation with training and assessments developed by MITRE's own ATT&CK subject matter experts. The program was spun out from MITRE Engenuity to MAD20 Technologies LLC to expand reach and help more defenders learn MITRE ATT&CK. The company maintains close ties to MITRE's Center for Threat Informed Defense (CTID) for adversary emulation library access.
- Center for Threat Informed Defense (CTID)coreCTID is a non-profit, privately funded research center operated by MITRE that provides the adversary emulation library used in MAD20's Adversary Emulation Methodology course. MAD20 curriculum familiarizes learners with the CTID emulation library for research, planning, TTP implementation, and execution.
Scale indicators3 records
Recent moves7 records
Expansion highlights5 records
MAD20 competitors and assessment
Company assessmentEmerging players
- CyberDefenders: CyberDefenders is a blue team-focused cybersecurity training platform offering hands-on labs, challenges, and certifications for SOC analysts, threat hunters, and DFIR practitioners. Comparable as a niche training provider targeting the same blue team defender persona MAD20 serves, though with a different content library and pricing model.
- Antisyphon Training: Antisyphon Training offers subscription-based cybersecurity training covering blue team, red team, and management topics, founded by SANS instructor John Strand. Comparable in subscription-based practitioner training and blue team focus, though smaller scale and broader topic coverage than MAD20's ATT&CK specialization.
Broad incumbents
- Pluralsight: Pluralsight is a large-scale technology skills platform offering subscription-based training across cloud, security, software development, and IT operations. Comparable as a subscription-based tech skills training provider with enterprise team plans, though with a much broader catalog spanning beyond cybersecurity.
- SANS Institute: SANS Institute is the largest and most established cybersecurity training and certification provider globally, offering GIAC certifications across blue team, red team, and cyber defense disciplines. Directly comparable as MAD20 competes for the same enterprise cybersecurity training budget, though SANS has a much broader catalog and longer market tenure.
Direct peers
- RangeForce: RangeForce delivers enterprise-grade cybersecurity skills development through interactive cyber range scenarios, with modules for SOC analysts, threat hunters, and incident responders. Comparable in B2B enterprise focus, cyber range-based delivery model, and blue team defender audience.
- Hack The Box: Hack The Box is a subscription-based cybersecurity upskilling platform offering hands-on labs, ranges, and certifications for individual practitioners and enterprise teams. Highly comparable business model, target buyer (enterprise security teams and individuals), and product category (hands-on cyber range training), with significant overlap on the blue team segment MAD20 serves.
- OffSec (Offensive Security): OffSec is a leading cybersecurity certification provider best known for the OSCP credential, with subscription-based training (Learn One/Unlimited) targeting offensive and defensive security professionals. Comparable to MAD20 in subscription-based training model, certification-led positioning, and enterprise cybersecurity practitioner audience.
- TryHackMe: TryHackMe is a gamified cybersecurity training platform offering subscription tiers for individuals and teams covering offensive, defensive, and general security topics. Directly comparable as a PLG-driven, subscription-based cybersecurity training platform targeting similar practitioner and small-team audiences.
- Cybrary: Cybrary is a cybersecurity skills development platform offering individual and enterprise subscription plans covering hands-on labs, certification prep, and team assessments. Comparable in subscription-based training model, target buyer (individual practitioners and enterprise security teams), and broader cybersecurity upskilling positioning.
- Immersive Labs: Immersive Labs provides a cyber resilience platform with hands-on labs, exercises, and assessments for enterprise security teams covering threat-informed defense, blue team, and crisis response. Comparable as a B2B enterprise cybersecurity skills development platform focused on measurable team capability uplift.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
MAD20 social profiles
Digital presenceMAD20 financial estimates
Financial estimateRevenue estimate
Valuation estimate
MAD20 leadership team
Management profileNumber of profiles
Profiles1 record
MAD20 funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
MAD20 M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about MAD20
What does MAD20 do?
MAD20 provides subscription-based training and certification programs built on the MITRE ATT&CK framework, with six core certification tracks covering Fundamentals, Cyber Threat Intelligence, SOC Assessment, Adversary Emulation, Threat Hunting & Detection Engineering, and Purple Teaming. The Advanced and Enterprise tiers include hands-on cyber range scenarios delivered through the MAD20 ARENAS platform in partnership with CYBER RANGES. Certifications are issued as digital badges shareable via Credly and LinkedIn.
Is MAD20 a public or private company?
MAD20 is a private company. It is classified as unknown and is currently operating.
When was MAD20 founded?
MAD20 was founded in 2021. It employs 11 to 50 people.
Where is MAD20 based?
MAD20 is headquartered in Charlotte, United States, in the North America region.
How does MAD20 make money?
Two revenue lines are on record. Subscription Licensing is the primary driver. The others are enterprise Custom Training.
Who are MAD20's main competitors?
Emerging players on record are CyberDefenders and Antisyphon Training. Broad incumbents are Pluralsight and SANS Institute. Direct peers are RangeForce, Hack The Box, OffSec (Offensive Security), TryHackMe, Cybrary and Immersive Labs.
Does MAD20 have an API?
No public API is recorded for MAD20.
What industry is MAD20 in?
MAD20's product category is Cybersecurity Training and Certification. Its primary akta.pro industry code is EDABAGAG, Cloud & SaaS Security Awareness (e.g., M365/Google Workspace). Its NAICS code is 611420.