Purple Team Lab
A controlled security engineering environment for adversary emulation, telemetry collection, detection development, incident investigation and defensive validation.
Controlled security validation
The environment is designed to generate known adversary activity, capture the resulting telemetry and measure defensive visibility.
Execute known adversary techniques against isolated lab systems without exposing production infrastructure.
Collect endpoint, network, authentication and cloud evidence generated during each exercise.
Turn observed behavior into detections, hunting queries and investigative workflows.
Retest the same technique after remediation to verify that defensive controls actually improved.
Security validation pipeline
The lab is intentionally staged so individual components can be started, tested and shut down without requiring a large permanent range.
HP ZBook
Primary virtualization and security engineering workstation.
Kali Linux
Controlled adversary emulation, reconnaissance and attack generation.
Windows Endpoint
Victim workload used for execution, persistence, discovery and incident-response exercises.
Elastic
Central telemetry analysis, hunting and detection engineering platform.
Velociraptor
Endpoint collection, triage, artifact acquisition and investigation.
Wireshark
Packet capture and protocol-level analysis for network investigations.
Suricata
Network intrusion detection and signature validation for later campaigns.
Azure Security Lab
Future cloud extension for identity, workload, posture, activity-log and security-control validation.
What the lab observes
Each campaign should identify which evidence sources are expected before the attack is executed.
Host Telemetry
Process execution, authentication, services, persistence, PowerShell activity and operating-system events.
Network Telemetry
DNS, TCP, TLS, HTTP, SMB and suspicious connection behavior captured during controlled attacks.
Detection Telemetry
Searches, alerts, correlation logic and hunting queries derived from observed adversary behavior.
Azure Telemetry
Identity, resource activity, policy findings and workload security events when the cloud lab is introduced.
Lab design requirements
The lab should remain useful even as individual technologies change.
Isolated
Attack traffic stays separated from production and business systems.
Reproducible
Configuration, scripts and documentation make scenarios repeatable.
Observable
Exercises are designed around known telemetry expectations rather than blind attack execution.
Disposable
Lab systems can be reverted, rebuilt or destroyed after testing.
The lab exists to support the campaigns.
Each BELISARIUS13 campaign should add or improve a lab capability, telemetry source, detection or investigation workflow.