This repository documents the architecture, deployment, and configuration of a professional-grade, hybrid cybersecurity homelab designed for Red Team operations and adversary simulation.
Unlike typical VirtualBox setups, this infrastructure focuses on technological sovereignty and performance, leveraging a Type-1 hypervisor (KVM/QEMU) on an Arch Linux host. It integrates physical hardware (Raspberry Pi 4) into the virtual environment to simulate realistic Command & Control (C2) infrastructure and network obfuscation.
The core philosophy of this lab is strict network segmentation to emulate a corporate environment, separating attacking assets from isolated victim networks.
The lab is built around a dual-homed attack architecture, ensuring that victim machines are completely isolated from the internet while remaining accessible to the attacker machine.
(Diagram showing Arch Host, NAT Network, Isolated Network, the 3 VMs, and the physical Raspberry Pi redirector connection)
| Network Name | Type | Subnet / CIDR | Description |
|---|---|---|---|
| default | NAT | 192.168.122.0/24 |
Provides outbound internet access via the Arch host. |
| Isolated-LAN | Isolated | 10.0.0.0/24 |
Strictly internal network. No internet access. Simulates a secure corporate LAN (The Bunker). |
- OS: Arch Linux (Rolling Release)
- Technology: KVM / QEMU / libvirt (managed via
virshand Virt-Manager). - Role: Provides raw performance to VMs and acts as the primary firewall/router between virtual networks.
- OS: Kali Linux
- Networking: Dual-Homed (NIC 1: NAT, NIC 2: Isolated-LAN).
- Role: The primary attack platform. It acts as a bridge/pivot, being the only machine capable of communicating with both the internet and the isolated victims.
- OS: Windows Server 2022 Standard
- Networking: Isolated-LAN only (
10.0.0.x). - Role: Active Directory Domain Controller for the
LAB.LOCALforest. - Vulnerabilities Configured: Weak user credentials for practicing brute-force, Kerberoasting, and AS-REP Roasting attacks.
- OS: Debian 13 (Trixie)
- Networking: Isolated-LAN only (
10.0.0.x). - Role: Linux server running Docker.
- Vulnerabilities Configured: Hosts intentionally vulnerable web applications (e.g., OWASP Juice Shop) exposed on port 80 for web exploitation practice (SQLi, XSS).
- Architecture: ARM64 (aarch64)
- Networking: Physical LAN connected to the home router.
- Role: Command & Control (C2) Redirector / Reverse Proxy.
- Configuration: Running Nginx configured to forward incoming traffic on port 80 directly to the Attacker VM's NAT IP. This obfuscates the attacker's true location during Red Team simulations.
Kali Linux (the pivot) successfully reaching victim machines on the isolated 10.0.0.x subnet via Nmap scan.
Accessing the vulnerale Juice Shop application running on the isolated Debian server from the Kali attacker machine.
Windows Server 2022 configured as a Domain Controller for LAB.LOCAL.
- Infrastructure as Code: Virtual networks are defined via libvirt XML configurations.
- Snapshots: Base
qcow2snapshots are taken of all VMs in a powered-off state ("golden images") to ensure rapid recovery after destructive attack simulations. - Automation: Custom Bash scripts on the Arch host handle the synchronized startup of virtual networks and VM instances.
- Executing multi-stage pivoting attacks (Kali -> Debian -> Windows DC).
- Deploying payloads via the Raspberry Pi redirector to bypass detection.
- Performing advanced Active Directory enumeration and exploitation (BloodHound, Mimikatz).



