[03] THE_SANDBOX // LAB INFRASTRUCTURE
THE SANDBOX // Bare-Metal Virtualization Range
A self-hosted, quarantined lab environment used to build and break enterprise infrastructure without touching a production network — every VM below runs on dedicated bare-metal hardware behind an isolated VLAN.
[ VIEW REPO]Dell Latitude E7270 (Bare-Metal Ubuntu Linux)
Linux KVM + QEMU + virt-manager
ASUS GS-BE18000 — VLAN 53 (192.168.50.0/24) — Access Intranet: Disabled
Containment Policy
All lab VMs run behind isolated virtual switches with no bridge to the host's LAN-facing NIC. Exploit traffic, malware samples, and C2 beacons generated inside the range cannot reach the host network by design.
VIRTUAL_ENVIRONMENTS
3 environments onlineWindows Server 2022
Enterprise Domain Controller (W2K22)
Windows Server 2022 — Active Directory hardening range
- Domain
- an.local
- Password Policy
- GPO-enforced, 14-character minimum
- LLMNR
- Disabled
- NetBIOS
- Stripped
- SMB Signing
- Enforced
macOS Sonoma 14
macOS Sonoma 14 Security Sandbox
OpenCore-booted macOS for endpoint security testing
- Bootloader
- OpenCore
- CPU Emulation
- Intel Penryn
- SMC
- Apple SMC cryptographic OSK injection
- Memory
- 7.1 GB RAM
- Storage
- 64 GB APFS
Kali Linux
Kali Linux Offensive Platform
Attacker-side platform for scanning and exploitation practice
- Recon
- Network scanning across the isolated range
- Vulnerability Audits
- Nmap NSE scripts
- Verification
- Protocol verification against target VMs