Enterprise Cybersecurity Home Lab
A self-hosted lab connecting identity, network attacks and defensive controls.
- Context
- Personal, self-hosted lab
- My role
- Lab builder and investigator
- Status
- Built and used for simulated security scenarios
- Deliverable
- Virtual infrastructure, attack-path notes and defensive recommendations
Decision & evidence
Connect the attack path to the evidence
I combined identity infrastructure, network boundaries and investigation tools in one lab. That makes it possible to relate an access-control scenario to both network traffic and security telemetry.
The useful deliverable is an explainable path from observed behavior to a defensive improvement, rather than a list of tools run.
Overview
Built a self-hosted lab with Windows Server, Ubuntu, Kali Linux, Active Directory and pfSense to explore how enterprise infrastructure and security controls work together.
Objective
Create a practical environment for simulating infrastructure and offensive / defensive security workflows, connecting attack behavior with observable evidence and defensive controls.
My contribution
- Built the enterprise-style lab and configured its core infrastructure components.
- Tested Active Directory exploitation, privilege escalation, network attacks and access-control scenarios.
- Investigated network traffic and security telemetry, and documented vulnerabilities, attack paths and defensive improvements.
Technical approach
- Used Windows Server and Active Directory to investigate identity and access-control scenarios, alongside Ubuntu, Kali Linux and pfSense.
- Used Nmap, Wireshark and SIEM tooling to examine network behavior and correlate observations with the tested scenarios.
Scope & considerations
The work concerns simulated lab scenarios. The engineering focus is the relationship between identity, network boundaries, privilege and the visibility needed to investigate security events.
Outcome
Demonstrates enterprise infrastructure knowledge, Active Directory security, network investigation and the ability to connect offensive testing with documented defensive improvements.