Lab
Everything I break, I break here. The rule is simple: nothing I test ever shares a network with anything I care about, and nothing in the lab is expected to survive.
Network segments
- Range
10.10.0.0/24
management
Hypervisor and workstation. The only segment that reaches the others, and nothing reaches it.
- Range
10.10.10.0/24
attack
Tooling, with internet access. Can reach targets; cannot reach management.
- Range
10.10.20.0/24
target
Deliberately vulnerable machines. No outbound route at all — if something in here calls home, the call does not leave.
management ──────► attack ──────► target
▲ ▲ ▲
╎ ╎ ╎
╎ ╎ └── no outbound route at all
╎ └── internet yes, management no
└── reaches everything, nothing reaches itMachines
| Name | OS | Segment | Purpose |
|---|---|---|---|
| hyperviseur | Proxmox VE | management | Runs everything else. Snapshots are the undo button. |
| atk-01 | Kali Linux | attack | Working box. Rebuilt from configuration, never repaired. |
| web-01 | Debian | target | Containerised web targets and my own challenge builds. |
| win-01 | Windows Server | target | Domain-flavoured target for the things Linux cannot teach. |
| dev-01 | Debian | management | HunterFr and HuntCode staging, as close to production as I can make it. |
Principles
- 01
Isolation at the network layer
Not at the application layer, and not by convention. A target with no route out cannot exfiltrate, no matter what I get wrong inside it.
- 02
Disposable by default
Every target is a snapshot away from clean. I never debug a compromised box back to health; I revert it and move on.
- 03
Reproducible from configuration
If rebuilding the lab requires remembering something, the lab is already broken. Scripts and compose files are the source of truth.
- 04
Off unless in use
The lab is not infrastructure, it is a workbench. It runs when I am at it and it is down the rest of the time.
