Self-hosted topology.
Where the labs actually run.
A documented self-hosted lab - Active Directory, SIEM, EDR, identity, and network components - used for safe offensive practice and detection-engineering work. Open-source where possible, tuned for reproducibility.
Cyber Range
3 componentsProxmox VE
Hosts the AD lab, target VMs, and isolated attack-surface segments.
Windows AD (2-DC, 6-host)
Two-domain Active Directory with realistic GPO and service-account misconfigurations.
Linux target stack
Web app, DB, message bus, and SSRF/SSRF-adjacent edge surfaces for lab work.
Detection
3 componentsElastic Stack
Centralised log ingestion, detection-as-code rules, and lab telemetry visualisation.
Wazuh
Endpoint telemetry across the lab - process trees, file integrity, syscalls.
Sigma rule library
Hand-written rule set covering the techniques exercised in the lab tracks.
Identity
2 componentsNetwork
2 componentsTooling
2 componentsOpen-source lab repositories
CuratedRepositories are curated and published as their content stabilises - links are added to each module page as they go live.