Skip to content
BaddKharma edited this page Sep 28, 2026 · 8 revisions

Labs

The library ships several ranges as blueprints. Load one, clone it, edit it, compile, and deploy. Each lab ships with its solution, because the solutions are operator validation references, not answer keys to hide.

The GOAD family

Recreated natively as redStackPRO topologies, so they compile through redStackPRO's own Terraform and Ansible. Every one of these ships with a walkthrough; see Solutions below for what "walkthrough" means and how current each one is.

Lab What it is Walkthrough
goad-light A two-domain Active Directory range, sevenkingdoms and its child north in one forest, two domain controllers and a member server, plus a jumpbox. The smallest full GOAD experience. docs/solutions/goad-light
goad The full lab, three domains across two forests with their trusts and hosts. docs/solutions/goad (14 parts, run live)
goad-mini A smaller GOAD for a quick stand-up. docs/solutions/goad-mini
dracarys The GOAD escalation chain built out end to end. docs/solutions/goad-dracarys
goad-wazuh GOAD with a Wazuh sensor for detection work. docs/solutions/goad-wazuh (attack plus detection)
nha (Ninja Hack Academy) A GOAD community lab centered on an ESC4 certificate-template takeover in ninja.hack, reached across a forest trust. docs/solutions/goad-nha
sccm A Configuration Manager (SCCM/MECM) lab. docs/solutions/goad-sccm
minilab A single-domain AD lab, the quickest GOAD-style range to stand up. docs/solutions/goad-minilab

The GOAD blueprints are derived from GOAD and carry GPLv3. They are data the canvas loads; the rest of the project is MIT.

Harbor

A corporate forest of our own, with no theme, covering the path a real engagement tends to take. Walkthrough: docs/solutions/harbor (verified live).

Attack infrastructure

These are attack-side blueprints, not target ranges, so none of them has a walkthrough: there is no AD forest to attack, just infrastructure to stand up and use against one of the ranges above. See Redirectors and Cover Stories for the redirector and cover-story mechanics these blueprints put in front of a teamserver.

  • redStack: the attack-infrastructure blueprint. Redirector, teamservers (Mythic, Sliver, Adaptix), a jumpbox with Guacamole, Kali and Windows operators, and a collector. Blueprint only, no walkthrough.
  • split-horizon: two front doors that do not share a fate, Apache fronting Sliver and Nginx fronting Mythic, each redirector on its own peered network. Blueprint only, no walkthrough.
  • redirector-rollover: a topology for rotating a burned redirector without losing the teamservers behind it. Blueprint only, no walkthrough.
  • MinimalC2-CLI: the smallest attack topology to start from, a redirector, a headless Sliver teamserver driven from a Kali operator over SSH, and a jumpbox with Guacamole. Ships a WireGuard multi-user access mode with an operator roster. Blueprint only, no walkthrough.
  • MinimalC2-GUI: the same shape with a Mythic teamserver and a GUI Kali operator (an xrdp desktop reached over a Guacamole RDP tile) to drive Mythic's web UI. Blueprint only, no walkthrough.

Solutions

The walkthrough solutions ship alongside the ranges, under docs/solutions/ in the repo (linked per lab above). The written solution for a lab is generated from, or hand-authored against, the same topology, so it matches what was deployed. For detection work, each escalation edge is a known test case; see Validation.

Not every walkthrough has been run against a live deploy yet: read the status line at the top of each page before treating a step as proven. goad (and goad-light and goad-mini, generated from it) is validated live, part by part; harbor is verified live end to end; goad-wazuh's attack steps follow the validated GOAD series, with its detection axis partially verified live. dracarys, nha, sccm, and minilab are each marked, on their own page, as authored from the blueprint and not yet run against a live range.

Next: stand one up in Deploying a Range.

Clone this wiki locally