B13 // LAB ENVIRONMENT

Purple Team Lab

A controlled security engineering environment for adversary emulation, telemetry collection, detection development, incident investigation and defensive validation.

ISOLATED REPRODUCIBLE OBSERVABLE ATT&CK-ALIGNED AZURE-READY
LAB MISSION

Controlled security validation

The environment is designed to generate known adversary activity, capture the resulting telemetry and measure defensive visibility.

01 // ATTACK Generate controlled activity

Execute known adversary techniques against isolated lab systems without exposing production infrastructure.

02 // OBSERVE Capture security telemetry

Collect endpoint, network, authentication and cloud evidence generated during each exercise.

03 // DETECT Engineer visibility

Turn observed behavior into detections, hunting queries and investigative workflows.

04 // VALIDATE Prove defensive improvement

Retest the same technique after remediation to verify that defensive controls actually improved.

LAB ARCHITECTURE

Security validation pipeline

The lab is intentionally staged so individual components can be started, tested and shut down without requiring a large permanent range.

HOST 01

HP ZBook

Primary virtualization and security engineering workstation.

Windows VMware Hyper-V
ATTACKER RED

Kali Linux

Controlled adversary emulation, reconnaissance and attack generation.

AVAILABLE
TARGET ENDPOINT

Windows Endpoint

Victim workload used for execution, persistence, discovery and incident-response exercises.

AVAILABLE
↓ TELEMETRY
SIEM BLUE

Elastic

Central telemetry analysis, hunting and detection engineering platform.

INTEGRATION
DFIR IR

Velociraptor

Endpoint collection, triage, artifact acquisition and investigation.

INTEGRATION
NETWORK PCAP

Wireshark

Packet capture and protocol-level analysis for network investigations.

AVAILABLE
SENSOR NDR

Suricata

Network intrusion detection and signature validation for later campaigns.

PLANNED
↓ FUTURE EXPANSION
CLOUD AZURE

Azure Security Lab

Future cloud extension for identity, workload, posture, activity-log and security-control validation.

Entra ID Defender for Cloud Azure Monitor Policy
PLANNED
TELEMETRY MATRIX

What the lab observes

Each campaign should identify which evidence sources are expected before the attack is executed.

ENDPOINT

Host Telemetry

Process execution, authentication, services, persistence, PowerShell activity and operating-system events.

Sysmon Event Logs Velociraptor
NETWORK

Network Telemetry

DNS, TCP, TLS, HTTP, SMB and suspicious connection behavior captured during controlled attacks.

Wireshark PCAP Suricata
DETECTION

Detection Telemetry

Searches, alerts, correlation logic and hunting queries derived from observed adversary behavior.

Elastic Sigma KQL
CLOUD

Azure Telemetry

Identity, resource activity, policy findings and workload security events when the cloud lab is introduced.

Entra Activity Logs Defender
ENGINEERING PRINCIPLES

Lab design requirements

The lab should remain useful even as individual technologies change.

01

Isolated

Attack traffic stays separated from production and business systems.

02

Reproducible

Configuration, scripts and documentation make scenarios repeatable.

03

Observable

Exercises are designed around known telemetry expectations rather than blind attack execution.

04

Disposable

Lab systems can be reverted, rebuilt or destroyed after testing.

CAMPAIGN INTEGRATION

The lab exists to support the campaigns.

Each BELISARIUS13 campaign should add or improve a lab capability, telemetry source, detection or investigation workflow.

B13 // PURPLE TEAM LAB Controlled activity. Measurable defense.