
Set up a basic computer network lab with open source tools and virtualization to test Windows and Linux systems, and implement intrusion detection and central log management.
Design a flexible lab across Windows, Linux, and operating systems to simulate malware, conduct network captures and vulnerability scans, perform forensics and build Splunk-based detections, and explore active directory hardening.
Configure a vSphere network with two subnets on SANDBOXLAN and ISOLAN, linked to Switch1 with VLAN IDs; the topology shows connected servers and a cableless physical adapter.
Configure a VirtualBox virtual network, compare memory usage with vSphere and VMware Workstation, and set up host network subnets 192.168.1.1 ISOLAN and 192.168.2.1 SANDBOXLAN with DHCP.
Demonstrates a Kali Linux and Security Onion lab using EternalBlue to exploit a Windows 7 host, perform a port scan, and review ids alerts in Squert.
Learn to set up Kali Linux by downloading the installer, configuring a virtual machine, and installing Kali Linux in the virtual machine.
Download the Kali Linux ISO installer and save it to your training folder. Choose the 64-bit installer via HTTP, with VM image options available.
Create a Kali VM in vSphere named lab-kali, allocate 4 GB RAM and 40 GB disk, mount Kali ISO, update over the internet, and enable VMware tools with time sync.
Install Kali Linux with the graphical installer, configure locale, keyboard, hostname, and user, accept default partitioning and grub, then update with apt and install chromium, mc, nano, and 7zip.
Configure a virtualized OPNsense firewall by downloading the installer, setting up the VM, assigning interfaces, and installing OPNsense, then configure DHCP, the firewall, and users.
Download the OPNsense installer for a firewall lab, choose the amd64 architecture and an ISO image from the closest mirror (for example Germany), and save the file from opnsense.org/download.
Create an OPNsense firewall VM in VMware named LAB_FW_OPNsense, assign IDSLAN and ISOLAN networks, disable WAN, install from OPNsense.iso, enable VMware tools time sync, and access the GUI at 192.168.1.*.
Configure the OPNsense firewall by setting up the LAN, WAN, and sandbox networks, assign interfaces, configure DHCP, implement static mappings, and create firewall rules to manage inter-network traffic.
Install Windows Server 2019, configure the VM, promote to domain controller with Active Directory and DNS, then create group policies and Active Directory users and computers.
Locate the Windows Server 2019 installer ISO and request a trial version. Download the ISO from a GitHub page and save it for deployment as a domain controller.
Create a Windows Server 2019 64-bit virtual machine named LAB-DC-W19 with 1 CPU, 4 GB RAM, and 90 GB disk in an isolated LAN, install GUI and VMware tools.
Manage Windows Server 2019 evaluation licenses: activate to extend to over 180 days. Configure updates with gpedit.msc to notify for download and install and set updates to manual.
Configure the domain controller in sandbox local network by booting VMs (domain controller, OPNsense, Kali Linux), assign a static 192.168.2.100 to lab-dc-w19, and refresh DHCP via ipconfig /release and /renew.
Configure the domain controller and verify the Windows Server 2019 network setup, renaming the IDSLAN to SANDBOXLAN on the 192.168.2.x LAN and adjusting the vSphere network naming.
Take a base snapshot and prepare a core Windows Server 2019 for promoting to a domain controller, configuring static IP, and adding AD DS and DNS roles.
Promote the server to a domain controller by installing the Active Directory services role, creating a new forest TESTLAB.local with 2016 level, and completing post deployment task and password setup.
Activate Windows evaluation licenses with slmgr, extend to 180 days via rearm, and verify expiration with /dli and /xpr, using server manager and OPNsense firewall rules.
Download the Windows Server 2016 installer ISO, install the OS in a VM, join the domain, and enforce policy on the host.
Download the Windows Server 2016 ISO to install a domain member server, using the Microsoft evaluation center or alternative sources like serverhelfer.de and GitHub or Vagrant links.
Install a Windows Server 2016 domain member VM LAB-SRV-W16 with 1 CPU, 4 GB RAM, 40 GB disk in an isolated network; capture a base snapshot after VMware Tools installation.
Configure the Windows Server network card to the sandbox LAN, then set 192.168.2.101 via OPNsense and release and renew the IP with ipconfig.
activate windows on the isolated lab host by enabling internet access, configuring firewall rules for 192.168.2.101, and using slmgr /ato with dns and connectivity checks.
Install Windows 10 20H2 in a VM and configure the operating system. Install VMware tools and join the PC to a domain using the provided tools and links.
Download a Windows 10 installer ISO from the Microsoft official website, select English language and 64-bit, choose the latest edition, and save it to your download folder.
Create a Windows 10 20H2 virtual machine for the lab domain member, allocate 1 cpu, 4 gb ram. Mount installer ISO, install Windows 10 Pro, install VMware tools, snapshot.
Configure the Windows lab PC to use the SANDBOXLAN network, set a static IP of 192.168.2.200, and renew network settings after applying changes in OPNsense.
Configure the domain controller by applying group policies to computer groups. Join and rejoin computers to the domain and enable remote GPO enforcement, while disabling automatic updates for the lab.
Create a tetlab.local active directory domain, build Resources with sub‑OUs, then add domainjoin, user1, and user2 with passwords never expiring and domain join delegated.
Discover how to delete an unintended organizational unit by enabling advanced features, adjusting the parent permissions, and removing a deny on child objects to permit deletion.
Join Windows 10 20H2 to the TESTLAB domain by configuring dns to the domain controller, validating connectivity with ipconfig, ping, and nslookup, then log in as a domain user.
Configure the server’s IPv4 DNS to the domain controller, then join the computer to the TESTLAB.local domain using the domainjoin account. Reboot and log in as a domain user.
Configure and link a group policy object to the workstations OU, set Windows update to notify for download, enable remote GPO updates firewall, and verify with gpupdate and gpresult.
Configure a global security group for servers, link a set of GPOs to enforce remote GPO updates, disable automatic updates, and allow shutdown through policy, with gpupdate and gpresults verification.
Reestablish the trust relationship by logging in with a local admin, leaving and rejoining the domain, then verify group policies with gpresult.
Download the Windows 10 1803 image, configure a virtual machine, install the operating system, and install the virtual machine guest tools using the installer link at the bottom.
Learn to download Windows installer images, specifically the 1803 Windows 10 ISO, using a downloadable tool, and transfer the ISO to a VM or USB.
Create a Windows 10 1803 machine LAB-PCx_W101803 in sandbox LAN, allocate 1 CPU, 4 GB RAM, 48 GB disk, mount 1803 ISO, and install Windows 10 Pro via custom install.
Install Windows 10 1803 in a sandbox, install VMware Tools, rename the host to LAB-PCx-W101803, and note DHCP assignment with upcoming configuration in OPNsense.
Set up Windows 7 by downloading the installer ISO, configuring the virtual machine, installing the operating system, and adding the VM guest tools; find tool links at the bottom.
Search for 'windows 7 iso escrow' to locate editions, then download the 64-bit professional Windows 7 installer ISO from Microsoft.
Install and configure a Windows 7 64-bit virtual machine named lab-pc7-w7x64, allocate 4 GB RAM and 32 GB disk, and set a static IP 192.168.2.202 via DHCP leases.
Download and set up the REMnux forensics tool in a Linux-based forensics environment, address an OVA format issue when importing the VM into vSphere, and learn the solution.
Download the remnux forensics linux machine from remnux.org, choose an ova option via google drive, and use the credentials remnux and malware to install via virtualization or ubuntu 18.04 manual.
Convert a REMnux OVA for vSphere using the OVF tool to create a new REMnux OVA, then compress and transfer it back to the vSphere host.
Create the REMnux linux virtual machine from an OVA, name it LAB-FOR1-REMNUX, and configure storage, network mapping to VM network with internet, assign 1 cpu and 4gb ram.
Boot up the REMnux and open a console, preparing the tool for use. Type remnux update and hit enter to apply all updates, leaving the system ready to use.
This course will help you building your own computer network testing environment, let it be a simple Active Directory, Splunk for log collection, Intrusion detection, Windows or Linux operating systems.
You can implement all or only a few of the systems we are going to discuss during the course depending on your needs and your resources available. I recommend using a local virtualization technology with 16GB RAM minimum, like vSphere, VMware Workstation, Virtualbox or similar.
The network set up will consist of two subnets, one being a "sandbox" where most systems will be installed. The second subnet will be the one for collecting logs and for forensics computers.
The training will cover:
installing different operating systems, like : Windows 7, Windows 10, Windows Server 2016, Windows Server 2019, Ubuntu Linux, CentOS Linux.
installing security appliances: Security Onion, AlienVault OSSIM.
installing and configuring OPNsense firewall by separating
installing and configuring services: Active Directory, Splunk SIEM, OPNsense firewall, time sync using NTP.
This will allow you to test out solutions without the risk of damaging a production environment.
The course is giving you directions how to set up these systems, and will show you one use-case at this time. I will continue adding more contents as I develop more, and update the contents based on feedback.
The training is not focusing on lexical knowledge and is not explaining what the different tools are doing in general. I assume that you either Google those or already have an idea about each solution. For example, I am not going to explain in detail what a SIEM is used for. We are going to set it up and use it.
This training is focusing on giving you the technical knowledge to be able to get systems up and running as quick as possible and work with each other in a network.