F
FLARETECH / LABS
PROXMOX HA CLUSTER // ONLINE
// LEVEL 10 ETHICAL HACKING ENVIRONMENT

Virtual Cyber Range &
Security Research Lab

Enterprise training environment for Active Directory exploitation, CCNA routing & switching security, CompTIA Security+ core domains, and CISSP governance alignment.

AD CS / Kerberos

01. Active Directory Range

Windows Server 2022 multi-forest range testing AD CS, Kerberoasting, and ACL privilege escalation.

EXPLORE RANGE
CCNA Aligned

02. CCNA Network Security

Cisco IOS/NX-OS routing & switching range, VLAN trunking, BGP/OSPF, and IPsec VPN tunnels.

EXPLORE RANGE
CompTIA SY0-701

03. Security+ Core Range

Threat vectors, PKI cryptography, IAM access controls, and Incident Response frameworks.

EXPLORE RANGE
ISC2 CISSP

04. CISSP Security Governance

Enterprise risk management, security architecture & engineering, and SOC operational controls.

EXPLORE RANGE
OWASP Top 10

05. Web API Security

Microservices vulnerability testing, JWT algorithm confusion, SSRF metadata access, and GraphQL.

EXPLORE RANGE
AWS & Azure

06. Cloud Security Range

Emulated LocalStack AWS environment, IAM role escalation, S3 policy bypass, and K8s RBAC.

EXPLORE RANGE
30+ Live VMs

07. Live Target Matrix

Real-time searchable table of all target virtual machines provisioned on the local lab subnet.

LAUNCH MATRIX
Proxmox HA

08. Hardware Infrastructure

Proxmox VE HA cluster specifications, OPNsense router rules, and 10GbE SFP+ mesh telemetry.

VIEW SPECS
WireGuard Mesh

09. Access Vault & Keys

WireGuard mesh VPN CLI configs, SSH public key verification, and operator PGP fingerprint.

VIEW VAULT
SYS_DIAGNOSTICS // v3.4
  • 01. Active Directory
  • 02. CCNA Security Range
  • 03. Security+ Core
  • 04. CISSP Governance
  • 05. Web API Range
  • 06. Cloud Security
  • 07. Target Matrix
  • 08. Infrastructure Specs
  • 09. Access Vault
PROXMOX CLUSTER TELEMETRY
CPU: 128 Cores [38% Load]
RAM: 512GB [62% Alloc]
NET: 10GbE SFP+ Active
// ATTACK SCENARIO 01
Active Directory Forest Architecture

AD CS (Certificate Services) Abuse Paths

Vulnerable ESC1, ESC3, and ESC8 certificate templates allowing non-privileged domain users to request client authentication certificates for Domain Administrator accounts.

MITRE: T1649 (Steal or Forge Authentication Certificates)

Kerberos Ticket Attacks & ACL Exploitation

Targeted Kerberoasting, AS-REP Roasting, and BloodHound mapped Access Control List (ACL) abuse leading to GenericAll and WriteDacl domain escalation.

MITRE: T1558.003 / T1003.001
// NETWORKING SPECS 02
CCNA Enterprise Routing & Switching Security

Cisco IOS/NX-OS Hardening & 802.1Q VLANs

802.1Q VLAN Trunking, Dynamic Trunking Protocol (DTP) exploitation, Native VLAN hopping defense, Port Security MAC restrictions, and DHCP Snooping with DAI (Dynamic ARP Inspection).

Cisco IOS / Catalyst 3850 Virtualized Range

Site-to-Site IPsec VPN & BGP/OSPF Security

Configuring IKEv2 / IPsec tunnel encryption across multi-homed BGP & OSPF routing domains. Implementing Access Control Lists (ACLs) and Control Plane Policing (CoPP).

Cisco ASAv & Firepower Threat Defense (FTD)
// COMPTIA ALIGNMENT 03
CompTIA Security+ SY0-701 Core Domains

Threat Vectors, Attacks & Cryptography

Hands-on analysis of social engineering vectors, malware payloads, PKI certificate hierarchies, asymmetric key exchange (RSA/ECC), and TLS 1.3 cipher suite configuration.

Sec+ Domain 1.0 & 2.0 Real-World Environment

Identity Access Management & IR Operations

IAM governance using SAML 2.0, OAuth, MFA enforcement, Least Privilege Access Models, and execution of automated Incident Response playbooks via Wazuh SIEM.

Sec+ Domain 3.0 & 4.0 Real-World Environment
// ISC2 ALIGNMENT 04
CISSP 8 Security Domains Governance Range

Security & Risk Management (Domain 1 & 3)

Enterprise risk assessment models (SLE, ALE, ARO), threat modeling (STRIDE/PASTA), security architecture engineering using Bell-LaPadula and Biba integrity models.

CISSP Domain 1: Security & Risk Management

Security Operations & Asset Security (Domain 2 & 7)

SOC incident response lifecycle (NIST SP 800-61), digital forensics evidence collection, disaster recovery planning (DRP), and data classification frameworks.

CISSP Domain 7: Security Operations
// ATTACK SCENARIO 05
Web Application & API Security Range

OAuth2 Token Forgery & SSRF Chains

Node.js microservices vulnerable to algorithm confusion JWT attacks, SSRF metadata extraction, and internal API pivot points.

MITRE: T1190 / T1552.005

GraphQL Introspection & Insecure Deserialization

GraphQL schema dumping, broken object-level authorization (BOLA/IDOR), and Java/Python pickle object deserialization RCE.

OWASP API Top 10 Aligned
// CLOUD SCENARIO 06
AWS & Azure Cloud Security Range

AWS IAM Privilege Escalation & LocalStack

LocalStack emulated cloud testing misconfigured IAM role pass-throughs, S3 bucket policy bypasses, and Lambda persistence mechanisms.

MITRE: T1078.004 / T1098

Kubernetes Cluster RBAC & Pod Security

Container escape vectors, privileged pod escalation, service account token theft, and Kube-bench security auditing.

K8s Hardened Cluster Architecture
// SUBNET TELEMETRY 07
Live Target Matrix
Hostname IP Address Target OS Exploitation Focus Domain Tag Status
DC01.CORP.LOCAL 10.10.10.5 Windows Server 2022 Active Directory Domain Controller AD CS / Kerberos ● ONLINE
CCNA-RTR-CORE 10.10.0.1 Cisco IOS 15.7 802.1Q Trunking / OSPF Routing CCNA NetSec ● ONLINE
SECPLUS-SIEM-01 10.10.90.10 Ubuntu 22.04 LTS Wazuh SIEM / Incident Response Security+ ● ONLINE
CISSP-GOV-AUDIT 10.10.80.2 Debian 12 Compliance Audit & Log Archiving CISSP Governance ● ONLINE
WEB-VAULT-API 10.10.20.14 Alpine Linux OWASP Top 10 / GraphQL API Web Sec ● ONLINE
// CLUSTER SPECS 08
Proxmox HA Cluster & OPNsense Specs

Compute & Ceph Storage HA Node

128 CPU Cores, 512GB ECC RAM, enterprise NVMe Ceph pool supporting automated VM instant rollback snapshots via API triggers.

Proxmox VE v8.2 HA Cluster

OPNsense Routing & Suricata IDS

OPNsense core virtual router with Suricata Intrusion Detection (IDS), WireGuard mesh endpoints, and strict 802.1Q VLAN isolation.

10GbE SFP+ Hardware Router Interface
// AUTHENTICATION 09
Access Vault & WireGuard Keys

WireGuard Mesh CLI Config

Connect directly to the internal subnet `10.10.0.0/16` for range testing.

sudo wg-quick up ./flaretech_lab.conf

Operator PGP Fingerprint

Verify signed security advisories and research writeups.

4F8A 9B2C 1D3E 5F7A 8B9C 0D1E 2F3A 4B5C