The Assume-Breach Series
Self-contained security labs that run on your laptop — break in, move laterally, defend, investigate, and audit. Most drop you into a real shell with the genuine tools — no VM or setup pain. Paired with two companion books and a game that ties it all together.
Each runs on its own — start anywhere. Together they walk the arc of a breach, from the attacker's first move to the investigator's final report.
Recon, scan, and exploit your way onto a target. Twelve labs from enumeration to a full De-ICE box.
Open lab ↗ Offensive · move throughLand a foothold, then pivot through a segmented network to reach the internal services you can't touch directly.
Open lab ↗ DefensiveEleven labs in defensive security — scanning, crypto, firewalls, packet capture — assuming the attacker is already in.
Open lab ↗ Post-breachInvestigate the Cloudcore breach: recover deleted files, analyse memory, follow the exfiltration, write the report.
Open lab ↗ Govern · auditPlay the consultant: audit a fictional company against the Essential Eight — read policies, interview staff, substantiate every finding.
Open lab ↗The lifecycle labs assume a working network: routes that hold, DNS that resolves, firewalls with rules already in them. These two build that layer, so "the scan never reached the host" becomes something you can reason about instead of a mystery.
A miniature enterprise across Perth, London, LA and a Pilbara mine site on a latency-shaped satellite link. Real FRR/OSPF routing, real dnsmasq, real nftables — plus a Suricata sensor on the HQ router and traffic that follows the sun around the network.
Open lab ↗ Browser · no installDrag out a topology and watch ARP and ICMP animate across the wire. Devices take real Linux
syntax — ip addr, ip route, ping, nftables — not an
invented teaching CLI. Five labs with auto-checked objectives.
The labs carry the tool mechanics; two companion books carry the mindset and the audit discipline; the game turns the whole lifecycle into cooperative play; and the toys break one stubborn misconception each, in about ninety seconds.
The defender's-mindset thesis behind the labs — tool-agnostic, the "why" to the labs' "how".
Read ↗ Book · auditSecurity audit & controls — how to prove a control actually works with evidence, not take it on faith.
Read ↗ The gameA print-and-play cooperative game across the whole security lifecycle, grounded in MITRE ATT&CK and NIST CSF.
Play ↗ The toysSingle-page browser toys, one misconception each: how long a password really lasts, why no alert threshold catches everything. No install, no network.
Try them ↗Why these labs are built on Docker — and, just as important, where Docker isn't the right tool and what to reach for instead. Then where to go once you've outgrown them.
Why containers, where they fall short (physical forensics, kernel work, malware, Windows/AD), and which approach — VM, bare metal, VPS — to use when they do.
Read ↗ Go furtherVulnHub, Hack The Box, TryHackMe, PortSwigger, OverTheWire, DFIR datasets and more — grouped and mapped to these labs.
Read ↗Every lab shares one skeleton: a console that hides Docker and logs you into a real interactive shell, a browser landing page, phased guides, and multi-arch images published to GHCR. The scaffold stamps out a new lab in that house style so you can focus on the security scenario, not the plumbing.
create-lab.sh copies the template and wires in the shell-mode console, landing page, GHCR workflow and Series strip.Learner walkthroughs stay in the public labs. Answer keys, marking rubrics and facilitator guides deliberately do not — they live in a private companion repo, so a student who finds this page can't find the solutions.
Per-module facilitator guides, assignment briefs and marking rubrics, the full lateral-movement pivot solution, the audit lab's planted-gap map and answer key, and the IT brief on running these labs on managed machines. No runnable lab lives here — it's assessor material only.
Teaching this material? Request access by opening an issue ↗