Shell to Signal

The Range

The isolated lab where every attack on this site is run and recorded. This page is kept up to date as the lab changes.

Version 1.0 · Updated

Every article on this site is tested here. When an article says “Tested in Range v1.0”, this is the lab it means.

The lab changes over time. When it does, the version number goes up and the change is listed at the bottom of this page.

The Range, version 1.0A firewall sits in the middle. Three lab networks connect to it: Corp with a domain controller and a workstation, SOC with the SIEM, and Red with the attacker machine. A fourth network for malware has no connection at all. The lab can reach the internet but is blocked from the personal network. Logs from Corp and Red flow to the SIEM.Internetoutbound onlyPersonal networkmy own devicesblockedFirewallroutes and filters between roomsCORPthe "company" networkDC01domain controllerWS01employee PCinternet kill switchSOCwhere the logs goSIEMSplunkAnalystworkstationREDthe attackerKaliattack machineisolation switchWindows logsLinux logsMALWARE ROOMno cable to anythingRange v1.0 · everything runs as virtual machines on one laptop
The whole lab at a glance. Everything runs as virtual machines on one laptop.

The Rooms

The lab is split into separate networks, like rooms in a building with a guard at every door. The guard is the firewall.

RoomWhat it isWho can it talk to?
CorpA small pretend company: a domain controller and an employee PCThe firewall, the SIEM, and the internet (unless the kill switch is on)
SOCThe security team’s room, where all the logs end upThe rooms it watches
RedThe attacker’s machineOnly the SIEM, to send its own logs. Everything else can be switched off.
Malware roomFor studying malwareNothing. It has no network cable at all.
Personal networkMy own laptop and devicesNo lab room can reach it. Blocked at the firewall.
Note

The rooms cannot see each other’s traffic directly. Everything between rooms goes through the firewall. Traffic inside one room does not. That is a blind spot, and there is an article about it.

The Machines

MachineRoomWhat it is
DC01CorpWindows Server 2025, the domain controller (it manages logins for the whole company)
WS01CorpWindows 10, a normal employee PC
SIEMSOCUbuntu with Splunk Enterprise 10.4 (free developer licence)
Analyst workstationSOCKali Purple, for investigating
KaliRedKali Linux 2026.2, the attacker
FirewallMiddleOPNsense, which routes and filters between rooms

What Gets Recorded

SourceWhereWhat it records
SysmonWindowsPrograms starting, network connections, file changes, and more
Windows Security logWindowsLogins, new processes with their full command line (4688)
PowerShell logWindowsThe actual script text that PowerShell ran (4104)
auditdLinuxEvery command run on the attacker machine
Firewall logFirewallConnections between rooms that were allowed or blocked
DNS logFirewallEvery website name a lab machine looked up

The Safety Switches

Some tests are risky, so the lab has switches that can be flipped before running them.

  • Corp internet kill switch. Cuts the company network off from the internet, so a test cannot contact the outside world.
  • Red isolation switch. Cuts the attacker machine off from everything except sending its logs.
  • Snapshots. Every machine is saved in a clean state, and goes back to it after every test.

Changelog

VersionDateWhat changed
v1.010 Oct 2026First version: Corp, SOC, Red and malware rooms, Splunk, Sysmon, auditd, firewall and DNS logs