Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Lab4PurpleSec — Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense + Suricata, and a Wazuh SIEM. It provides a realistic, open-source training environment for web exploitation, pivoting, Active Directory attacks, and Blue Team detection. | Kitploit
Tools/GitHubGitHub/0xmr007/lab4purplesec
Privilege EscalationIDS/IPS EvasionWeb Application ExploitationPenetration TestingIntrusion DetectionLearning & EducationRed TeamingLabs & Practice
GitHub0xmr007/lab4purplesec

Lab4PurpleSec

View Repository
30635119 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense + Suricata, and a Wazuh SIEM. It provides a realistic, open-source training environment for web exploitation, pivoting, Active Directory attacks, and Blue Team detection.

Share

Lab4PurpleSec

Lab4PurpleSec

Version License Status Platform Maintenance

Note: This project was previously named "Lab4OffSec" and has been renamed to "Lab4PurpleSec" to better reflect its Purple Team focus.

Note: This is a V1. Feedback and contributions are welcome.

📜 License Notice: The use of this project (including for CTFs, commercial projects, training, or any other purpose) is subject to the terms and conditions of the MIT License. See LICENSE for full details. By using this project, you agree to comply with the license terms, including maintaining copyright notices and license information.

🇫🇷 Version française disponible ici

Table of Contents

  • Lab4PurpleSec
    • Overview
    • Prerequisites
      • Hardware Requirements
        • Minimum Configuration (Limited Scenarios)
        • Recommended Configuration (Full Lab Experience)
        • Optimal Configuration (Maximum Performance)
      • Software Requirements
      • Project Goals
    • TL;DR
    • Network Architecture
      • Lab4PurpleSec
      • GOAD-MINILAB
    • Repository Structure
    • Quick Start
      • Option 1: Automated Deployment (Recommended)
      • Option 2: Manual Deployment
    • Possible Scenarios
      • 1. Pivoting — WAN → DMZ → LAN
      • 2. OWASP Web Exploit → Persistence (webshell)
      • 3. Kerberoasting (AD) — reconnaissance & ticket recovery
    • Component Installation
      • Automated Components
      • Manual Components
    • Contributions
    • License
    • Legal Notice
    • Credits

Overview

Lab4PurpleSec is an evolving cybersecurity homelab designed for Red Team and Blue Team training in a near-enterprise environment, integrating network/web pentesting, Active Directory, detection, SIEM, and IDS/IPS.

Project intended for students and cybersecurity enthusiasts!

Prerequisites

Hardware Requirements

Lab4PurpleSec is designed to be flexible and can be deployed according to your needs and available resources. You don't need to run all VMs simultaneously - scenarios are designed to be executed step-by-step.

Minimum Configuration (Limited Scenarios)

  • RAM: 16 GB minimum
  • CPU: 4-core processor (i5/i7 or equivalent)
  • Storage: 150 GB free disk space
  • Use Case: Run 2-3 VMs at a time for specific scenarios (e.g., web server + attack machine, or SIEM + one target)

Recommended Configuration (Full Lab Experience)

  • RAM: 32 GB recommended
  • CPU: 6+ core processor (i5/i7/i9 or equivalent)
  • Storage: 200+ GB free disk space (SSD recommended)
  • Use Case: Run multiple VMs simultaneously for complex scenarios (e.g., full AD environment + SIEM + web services)

Optimal Configuration (Maximum Performance)

  • RAM: 64 GB
  • CPU: 8+ core processor (i9/Ryzen 9 or equivalent)
  • Storage: 500+ GB free disk space (NVMe SSD recommended)
  • Use Case: Run entire lab simultaneously with all services active

Note: These prerequisites are for a reference configuration. You can customize them to fit your needs. Of course, the RAM is the most important resource to consider (for virtualisation, CPU/GPU power is not as important as RAM).

Important Notes:

  • You can customize VM resources in the Vagrantfile to match your hardware (reduce RAM/CPU per VM if needed)
  • Not all VMs need to run at once - start only the VMs needed for your current scenario
  • Wazuh Manager (LAN-SIEM-LIN) requires 8GB RAM - this is the most resource-intensive VM
  • GOAD VMs (Windows) require significant resources - consider running them separately if RAM is limited
  • Disk space usage: With default settings, the lab uses approximately 130-150 GB

For detailed hardware and software requirements, see docs/SETUP/prereqs.md.

Software Requirements

  • Hypervisor: VirtualBox or VMware Workstation/Player
  • Vagrant: Version 2.2+ (for automated VMs)
  • Ansible: Optional, for manual playbook execution
  • ISO Images: See docs/SETUP/prereqs.md for complete list

Project Goals

Lab4PurpleSec does not provide pre-built virtual machines (OVA/OVF). Installation is done entirely "from scratch" by following the detailed guides provided. This approach:

  • Encourages learning: Understanding each installation and configuration step
  • Ensures reproducibility: Each user builds their environment identically (yet still customizable)
  • Strengthens understanding: Mastery of systems, networks, and configurations
  • Facilitates customization: Easy adaptation according to specific needs

TL;DR

Lab4PurpleSec includes the following features:

  • Segmented architecture (WAN, DMZ, LAN, AD)
  • pfSense firewall, Suricata IDS/IPS, Wazuh SIEM
  • Vulnerable machines (OWASP, Metasploitable, Windows DC)
  • Detailed installation and configuration guides

Network Architecture

Lab4PurpleSec

Lab4PurpleSec is an environment dedicated to application and system vulnerability exploitation, hosting intentionally vulnerable machines (Metasploitable2/3), OWASP web applications in an isolated DMZ zone, as well as a vulnerable Active Directory environment (GOAD MINILAB).

Homelab-light.png

GOAD-MINILAB

GOAD-MINILAB replicates a simplified Active Directory environment with a domain controller and a Windows client workstation (multiple if needed), allowing simulation of various types of Active Directory-oriented attacks.

GOAD-MINILAB.png

Repository Structure

This section presents the organization of the Lab4PurpleSec repository and describes the role of each directory and main file. This structure enables clear navigation between installation guides, configurations, tests, and project resources.

Download Tool