Security Labs

The Assume-Breach Series

Learn security by doing — across the whole attack lifecycle.

Self-contained security labs that run on your laptop — break in, move laterally, defend, investigate, and audit. Most drop you into a real shell with the genuine tools — no VM or setup pain. Paired with two companion books and a game that ties it all together.

Five labs, one lifecycle

Each runs on its own — start anywhere. Together they walk the arc of a breach, from the attacker's first move to the investigator's final report.

Break in→Move through→ Assume compromise→Investigate→Govern

Foundations — the network underneath

The lifecycle labs assume a working network: routes that hold, DNS that resolves, firewalls with rules already in them. These two build that layer, so "the scan never reached the host" becomes something you can reason about instead of a mystery.

The books, the game & the toys

The labs carry the tool mechanics; two companion books carry the mindset and the audit discipline; the game turns the whole lifecycle into cooperative play; and the toys break one stubborn misconception each, in about ninety seconds.

Learn more

Why these labs are built on Docker — and, just as important, where Docker isn't the right tool and what to reach for instead. Then where to go once you've outgrown them.

Build your own

Every lab shares one skeleton: a console that hides Docker and logs you into a real interactive shell, a browser landing page, phased guides, and multi-arch images published to GHCR. The scaffold stamps out a new lab in that house style so you can focus on the security scenario, not the plumbing.

1
Read the architectureHow we simulate a security environment with Docker + a few scripts — the shared anatomy of every lab.
2
Scaffold a labcreate-lab.sh copies the template and wires in the shell-mode console, landing page, GHCR workflow and Series strip.
3
Contribute backAdd a module to an existing lab, or open a new one — the contributing guide covers both paths.

For instructors

Learner walkthroughs stay in the public labs. Answer keys, marking rubrics and facilitator guides deliberately do not — they live in a private companion repo, so a student who finds this page can't find the solutions.

Private · invite only

security-labs-staff 🔒

Per-module facilitator guides, assignment briefs and marking rubrics, the full lateral-movement pivot solution, the audit lab's planted-gap map and answer key, and the IT brief on running these labs on managed machines. No runnable lab lives here — it's assessor material only.

Teaching this material? Request access by opening an issue ↗