Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Red-Team-GOAD-Lab-Proxmox — Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors. | Kitploit
Tools/GitHubGitHub/pho5nix/red-team-goad-lab-proxmox
Defensive ToolsPost-ExploitationSecurity VirtualizationNetwork SecurityPenetration TestingCommand and ControlLearning & EducationRed TeamingAdversarial Attack

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Labs & Practice
GitHubpho5nix/red-team-goad-lab-proxmox

Red-Team-GOAD-Lab-Proxmox

Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors.

View Repository
28381 day agoNot yet reviewed
Share

Red-Team-GOAD-Lab-Proxmox

Infrastructure diagram

image

Build in order:

  • pfSense VLANs and firewall policy.
  • Operator and Redirector VMs.
  • GOAD lab setup in Proxmox.
  • Verification, snapshots and troubleshooting.

Command syntax for Packer, Terraform and GOAD should be checked against your freshly cloned GOAD repo at build time. GOAD is actively maintained and variable file formats may change between releases.


Build summary and resources

Segments

VLANSubnetGateway (pfSense)PurposeIP source
150172.23.150.0/24172.23.150.1Kali Operator and Ubuntu C2/SliverpfSense DHCP (reservations after creation)
16010.60.160.0/2410.60.160.1HTTP/S Redirector and DNS/SSH Redirector (Ubuntu VMs)pfSense DHCP (reservations after creation)
56192.168.56.0/24192.168.56.1Ubuntu GOAD provisioning VM, GOAD AD lab (5 Windows VMs) plus ELK SIEMStatic (Terraform/Cloudbase-Init)
10010.10.100.0/2410.10.100.1Your Desktop/LaptoppfSense DHCP (reservations after creation)

GOAD hosts (static, internal to VLAN 56)

CodenameRoleOSDomainIP
kingslandingDC01WS 2019sevenkingdoms.local192.168.56.10
winterfellDC02WS 2019north.sevenkingdoms.local192.168.56.11
meereenDC03WS 2016essos.local192.168.56.12
castelblackSRV02 (MSSQL/IIS)WS 2019north.sevenkingdoms.local192.168.56.22
braavosSRV03 (MSSQL/ADCS)WS 2016essos.local192.168.56.23
GOAD-ELKSIEM (Elasticsearch/Kibana/Logstash)Ubuntu 26.04Lab Monitoring192.168.56.50

GOAD hosts use the domain controllers as their DNS (kingslanding, .10), required for AD. pfSense is their gateway only.


Resource budget (my current host is a Beelink Mini PC GTi13: i9 CPU, 80 GB RAM. 1TB SSD)

ComponentVLANvCPURAMDisk
Kali operator15048 GB60 GB
Ubuntu + Sliver C215024 GB40 GB
HTTP/S redirector16022 GB20 GB
DNS/SSH redirector16022 GB20 GB
Provisioning host5644 GB40 GB
kingslanding DC015624 GB60 GB
winterfell DC025624 GB60 GB
meereen DC035624 GB60 GB
castelblack SRV025624 GB60 GB
braavos SRV035624 GB60 GB
GOAD-ELK SIEM5648 GB80 GB

Total is roughly 28 vCPU, 48 GB RAM, 620 GB thin provisioned disk for the full GOAD lab.
Against 80 GB RAM that leaves about 30 GB headroom for Proxmox itself and snapshots.
You can setup the GOAD-Light or the MINILAB instead, if limited resources.


Disclaimer

This lab is built strictly for education and authorized security training in an isolated, self contained environment. The techniques it teaches are the same ones defenders need to understand to protect real systems. Keep it isolated, keep it local and use what you learn to make things more secure.

Download Tool