Attacker
Attack workstation
Kali Linux or Parrot Security
4 vCPU · 8 GB RAM · 80 GB disk
Your operating position. Everything offensive originates here so that traffic attribution stays unambiguous.
Snapshot immediately after tooling is installed and configured. You will want to roll back to a clean state more often than you expect.
Infrastructure
Domain controller
Windows Server 2022 (evaluation)
2 vCPU · 4 GB RAM · 60 GB disk
Active Directory, DNS and DHCP for the lab domain. The centrepiece of any realistic internal scenario.
Deliberately introduce the misconfigurations you want to study: Kerberoastable service accounts, weak ACLs, unconstrained delegation.
Target
Domain workstation
Windows 11 Enterprise (evaluation)
2 vCPU · 4 GB RAM · 60 GB disk
A domain-joined endpoint representing initial foothold. Where credential access and lateral movement begin.
Install Sysmon with a well-tuned configuration so you can see exactly what your own techniques generate.
Target
Linux application server
Ubuntu Server LTS
2 vCPU · 4 GB RAM · 40 GB disk
Hosts deliberately vulnerable web applications for the web track: Juice Shop, DVWA, WebGoat.
Run each application in its own container so you can reset one without disturbing the others.
Monitoring
Monitoring & SIEM
Ubuntu Server LTS
4 vCPU · 8 GB RAM · 120 GB disk
Collects logs from every node. This is what turns an attack lab into a detection lab.
Wazuh or an Elastic stack both work well. The disk fills faster than you plan for — size generously.
Infrastructure
pfSense firewall
pfSense CE
2 vCPU · 2 GB RAM · 20 GB disk
Segments the lab and controls egress. Also gives you a realistic target for segmentation testing.
Configure it so lab traffic cannot reach your home or office network. This is the single most important step on the page.