Home Lab
Active Directory practice environment
VMware Workstation lab used since 2018 for AD attacks, vuln-box practice, malware dev, EDR tuning, and report-quality documentation.
VMware inventory
Attack platform
Primary Kali Linux box for enumeration, exploitation, and post-exploitation against lab targets.
- Kali Linux
Home Lab (domain)
Windows Server domain controller plus member workstations for AD privilege escalation, lateral movement, credential abuse, and command-and-control testing.
- Windows Server
- Spiderman
- ThePunisher
- BOF Windows
- SquirrelGirl
Vuln
Intentionally vulnerable VMs for standalone box practice — web, Linux, and legacy Windows targets with write-ups.
- Academy
- blackpearl
- Blue
- Dev
- Butler
- Kioptrix Level 1
Malware development
Isolated MalDev segment for malware development and initial-access tradecraft experiments.
- MalDev
Elastic EDR
Detection engineering sandbox — Elastic stack with Windows endpoints for tuning alerts and validating evasion against operator-style traffic.
- Elastic stack (Ubuntu)
- Windows 11 endpoint
MacDev
macOS development and cross-platform tooling tests.
- macOS
How it's used
- Practiced AD attack paths (Kerberoasting, delegation abuse, certificate attacks) against the domain lab before applying them on engagements.
- Ran vuln-box scenarios end-to-end with professional-grade reporting — recon, exploitation, privilege escalation, and remediation notes.
- Developed and tested loaders, beacons, and BOF workflows in isolated segments without touching production networks.
- Tuned Elastic detection rules against realistic attack traffic from lab endpoints, then validated evasion trade-offs.
- Maintained long-running infrastructure since 2018 so techniques stay current as tooling and mitigations evolve.
Continuous hands-on practice across offensive, defensive, and reporting workflows.