← Back to built

Home Lab

Active Directory practice environment

VMware Workstation lab used since 2018 for AD attacks, vuln-box practice, malware dev, EDR tuning, and report-quality documentation.

VMwareActive DirectoryKaliElastic EDR

VMware inventory

Attack platform

Primary Kali Linux box for enumeration, exploitation, and post-exploitation against lab targets.

  • Kali Linux

Home Lab (domain)

Windows Server domain controller plus member workstations for AD privilege escalation, lateral movement, credential abuse, and command-and-control testing.

  • Windows Server
  • Spiderman
  • ThePunisher
  • BOF Windows
  • SquirrelGirl

Vuln

Intentionally vulnerable VMs for standalone box practice — web, Linux, and legacy Windows targets with write-ups.

  • Academy
  • blackpearl
  • Blue
  • Dev
  • Butler
  • Kioptrix Level 1

Malware development

Isolated MalDev segment for malware development and initial-access tradecraft experiments.

  • MalDev

Elastic EDR

Detection engineering sandbox — Elastic stack with Windows endpoints for tuning alerts and validating evasion against operator-style traffic.

  • Elastic stack (Ubuntu)
  • Windows 11 endpoint

MacDev

macOS development and cross-platform tooling tests.

  • macOS

How it's used

  • Practiced AD attack paths (Kerberoasting, delegation abuse, certificate attacks) against the domain lab before applying them on engagements.
  • Ran vuln-box scenarios end-to-end with professional-grade reporting — recon, exploitation, privilege escalation, and remediation notes.
  • Developed and tested loaders, beacons, and BOF workflows in isolated segments without touching production networks.
  • Tuned Elastic detection rules against realistic attack traffic from lab endpoints, then validated evasion trade-offs.
  • Maintained long-running infrastructure since 2018 so techniques stay current as tooling and mitigations evolve.

Continuous hands-on practice across offensive, defensive, and reporting workflows.