Case Study: Bare-Metal Offensive Security Lab
How the home-server lab supports repeatable AD, wireless, endpoint, and red-team practice.
Project URL: https://rian-friedt.de/projects/home-server-lab-infrastructure/
Short Summary
A strong lab is more than a place to run tools. It is the foundation for repeatable practice, clean testing, and honest methodology. My home-server setup gives me a controlled environment for Active Directory labs, wireless security practice, endpoint research, snapshots, and rebuilds.
Why I Built It
Cloud labs are useful, but I wanted a local environment where I can control network separation, rebuild states, and performance. Bare-metal hardware makes it easier to run Windows domains, Linux attack workstations, monitoring, and isolated test networks without depending on public targets.
Design Principles
- Keep offensive testing scoped to owned lab networks.
- Use snapshots so experiments are reversible.
- Separate management, testing, and target networks.
- Document what was tested, what changed, and what was learned.
Takeaway
The lab helps turn certification practice into a real workflow: prepare, test, validate, document, reset, and improve.