Defensive labs
Practise using synthetic traces, sanitised configurations and tabletop scenarios. The exercises stay offline and separate from operational devices, real credentials and physical controls.
On this page
Overview#
These labs are bounded research procedures based on synthetic fixtures, offline artefacts, calculations, or loopback simulation. They teach interpretation and evidence planning without requiring an operational system.
Lab scope is limited to synthetic or sanitised offline artefacts, calculations, table tops, simulated topologies, and local loopback simulation. External networks, operational systems, physical devices, real credentials, dispatchable alarms, and physical actuation are excluded.
Lab classes#
| Class | Meaning |
|---|---|
| Offline fixture | Embedded synthetic text/bytes; preferred |
| Calculation | Synthetic inputs evaluated with documented units, assumptions, and uncertainty |
| Tabletop | A paper scenario used to reason about roles, decisions, evidence, and recovery |
| Loopback simulation | Synthetic local components bound exclusively to operating system loopback, with no route to an external network or device |
| Simulated topology | Invented components and flows documented without a network or device |
Physical hardware, field buses, devices, real brokers, monitoring receivers, service endpoints, and external networks aren't lab classes. Use the separate commissioning and acceptance process for them.
Labs#
- Authorisation, topology, and safety
- Offline packet and trace reading
- TLS certificate chain review
- ONVIF discovery and media flow reasoning
- RTSP/RTP/SDP trace analysis
- MQTT TLS and ACL review
- WebSocket event flow review
- OSDP and Wiegand offline decoding
- SIA DC09 validation planning
- Modbus and BACnet interpretation
- Time drift and event correlation
- SNMP and syslog health correlation
- Video bandwidth and storage calculation
- Camera and controller hardening review
- Certificate rotation and restore tabletop
- Incident response tabletop
Prohibited lab actions#
- Internet or production scanning; brute force; password lists; credential harvesting.
- Card/credential cloning, live replay, bypass, evasion or jamming.
- Denial of service, exploit delivery, undocumented privileged APIs or firmware tampering.
- Unlocking/locking doors, moving gates/elevators, disarming/silencing alarms, energizing relays or generating monitoring centre dispatch.
- Capturing or using traffic, media, credentials or personal data belonging to others.
- Connecting to physical devices, field wiring, real brokers, monitoring receivers, service endpoints, or any non loopback network.
Owner authorised physical acceptance is a separate activity governed by the environment validation checklist, manufacturer instructions, site change control, and the responsible safety or operations authority. It isn't a defensive lab.