Skip to content

About

Hybrid offensive security homelab on Arch/KVM — Kali pivot, isolated AD domain, Raspberry Pi 4 C2 redirector.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

🛡️ Advanced Hybrid Offensive Security Lab

🚀 Project Overview

This repository documents the architecture, deployment, and configuration of a professional-grade, hybrid cybersecurity homelab designed for Red Team operations and adversary simulation.

Unlike typical VirtualBox setups, this infrastructure focuses on technological sovereignty and performance, leveraging a Type-1 hypervisor (KVM/QEMU) on an Arch Linux host. It integrates physical hardware (Raspberry Pi 4) into the virtual environment to simulate realistic Command & Control (C2) infrastructure and network obfuscation.

The core philosophy of this lab is strict network segmentation to emulate a corporate environment, separating attacking assets from isolated victim networks.


🏗️ Network Architecture & Topology

The lab is built around a dual-homed attack architecture, ensuring that victim machines are completely isolated from the internet while remaining accessible to the attacker machine.

📊 Network Diagram

Network Topology Architecture

(Diagram showing Arch Host, NAT Network, Isolated Network, the 3 VMs, and the physical Raspberry Pi redirector connection)

🌐 Virtual Networks (KVM/libvirt)

Network Name Type Subnet / CIDR Description
default NAT 192.168.122.0/24 Provides outbound internet access via the Arch host.
Isolated-LAN Isolated 10.0.0.0/24 Strictly internal network. No internet access. Simulates a secure corporate LAN (The Bunker).

🖥️ Lab Components (The Assets)

1. The Hypervisor Host (Foundation)

  • OS: Arch Linux (Rolling Release)
  • Technology: KVM / QEMU / libvirt (managed via virsh and Virt-Manager).
  • Role: Provides raw performance to VMs and acts as the primary firewall/router between virtual networks.

2. The Attacker / Pivot Box (KVM VM)

  • OS: Kali Linux
  • Networking: Dual-Homed (NIC 1: NAT, NIC 2: Isolated-LAN).
  • Role: The primary attack platform. It acts as a bridge/pivot, being the only machine capable of communicating with both the internet and the isolated victims.

3. Victim 1: The Domain Controller (KVM VM)

  • OS: Windows Server 2022 Standard
  • Networking: Isolated-LAN only (10.0.0.x).
  • Role: Active Directory Domain Controller for the LAB.LOCAL forest.
  • Vulnerabilities Configured: Weak user credentials for practicing brute-force, Kerberoasting, and AS-REP Roasting attacks.

4. Victim 2: The Web Vector (KVM VM)

  • OS: Debian 13 (Trixie)
  • Networking: Isolated-LAN only (10.0.0.x).
  • Role: Linux server running Docker.
  • Vulnerabilities Configured: Hosts intentionally vulnerable web applications (e.g., OWASP Juice Shop) exposed on port 80 for web exploitation practice (SQLi, XSS).

5. The Physical Redirector (Raspberry Pi 4)

  • Architecture: ARM64 (aarch64)
  • Networking: Physical LAN connected to the home router.
  • Role: Command & Control (C2) Redirector / Reverse Proxy.
  • Configuration: Running Nginx configured to forward incoming traffic on port 80 directly to the Attacker VM's NAT IP. This obfuscates the attacker's true location during Red Team simulations.

📸 Proof of Concept (Deployment Validation)

1. Network Isolation & Pivoting Verified

Kali Linux (the pivot) successfully reaching victim machines on the isolated 10.0.0.x subnet via Nmap scan.

KALI TERMINAL RUNNING: nmap -sn 10.0.0.0/24

2. Web Vector Active

Accessing the vulnerale Juice Shop application running on the isolated Debian server from the Kali attacker machine.

KALI BROWSER SHOWING JUICE SHOP AT 10.0.0.149

3. Active Directory Operational

Windows Server 2022 configured as a Domain Controller for LAB.LOCAL.

SERVER MANAGER SHOWING AD DS AND DNS ROLE


🛠️ Deployment & Maintenance Notes

  • Infrastructure as Code: Virtual networks are defined via libvirt XML configurations.
  • Snapshots: Base qcow2 snapshots are taken of all VMs in a powered-off state ("golden images") to ensure rapid recovery after destructive attack simulations.
  • Automation: Custom Bash scripts on the Arch host handle the synchronized startup of virtual networks and VM instances.

🎯 Future Learning Goals utilizing this Lab

  • Executing multi-stage pivoting attacks (Kali -> Debian -> Windows DC).
  • Deploying payloads via the Raspberry Pi redirector to bypass detection.
  • Performing advanced Active Directory enumeration and exploitation (BloodHound, Mimikatz).

About

Hybrid offensive security homelab on Arch/KVM — Kali pivot, isolated AD domain, Raspberry Pi 4 C2 redirector.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages