Lab environment

RedForge Lab Environment

The RedForge Lab Environment replicates enterprise identity, infrastructure, endpoint, and security-monitoring workflows while integrating an isolated offensive-security range for controlled adversary simulation and security validation.

Each implemented system is validated, documented, and connected to engineering records.

Future capabilities remain visible but are clearly distinguished from verified infrastructure.

Purpose

Offensive security development through enterprise replication.

Approach

Build Validate Document
Assess Improve

Focus areas

Identity Infrastructure Telemetry
Offensive Security Detection

Updated

2026-08-10

Verified topology

Interactive view of the verified environment. Select any system to explore details and related records.

Topology legend

▣ Virtualization boundary

Sysmon telemetry
Windows security telemetry
Active Directory DSIdentity serviceDNSName resolutionSysmonTelemetry source
RF-KALI01Controlled Adversary Simulation — PlannedRF-WIN11-01

Offensive Security Attack Range

Verified operational security testing environment
Verified
Controlled NAT: RF-KALI01 + RF-MINT01 only
OperationalVerified and active PlannedNot yet implemented Isolated targetVerified host-only target Established connectionVerified and active Planned connectionFuture implementation

Selected system

RF-DC01

Windows Server 2025Operational
Purpose
Provides verified enterprise identity, authentication, authorization, and integrated name-resolution services.
Roles
  • Domain controller
  • Identity service
  • DNS service
Services
  • Active Directory Domain Services
  • Integrated DNS
  • Enterprise authentication
Telemetry
Windows security and authentication telemetry is received and searchable in Splunk Enterprise.

Reviewed implementation evidence

Authentic Active Directory, DNS, Group Policy, indexing, and telemetry evidence from the verified environment.

Screenshot Gallery

Active Directory Domains and Trusts showing the RedForge enterprise test forest
Reviewed evidenceREVIEWED IMPLEMENTATION EVIDENCE — The enterprise forest and internal test domain are operational.
Active Directory Users and Computers showing the RedForge organizational unit hierarchy
Reviewed evidenceREVIEWED IMPLEMENTATION EVIDENCE — The directory uses a structured enterprise Organizational Unit hierarchy.
Group Policy Management showing the implemented RedForge policy objects
Reviewed evidenceREVIEWED IMPLEMENTATION EVIDENCE — Baseline domain, audit, defender, firewall, and workstation policies are defined.
DNS Manager showing directory-integrated records for the RedForge test domain
Reviewed evidenceREVIEWED IMPLEMENTATION EVIDENCE — Integrated DNS resolves the documented enterprise systems.
Splunk Enterprise index management showing RedForge indexes and indexed events
Reviewed evidenceREVIEWED IMPLEMENTATION EVIDENCE — Enterprise telemetry is separated into purpose-built indexes and contains events.
Splunk Search and Reporting showing indexed Windows and Sysmon events from RF-DC01
Reviewed evidenceREVIEWED IMPLEMENTATION EVIDENCE — SPL returns real indexed Windows and Sysmon telemetry from the domain controller.
Splunk Search and Reporting showing a validated Sysmon process-event search
Reviewed evidenceREVIEWED IMPLEMENTATION EVIDENCE — Sysmon process telemetry is searchable in the centralized monitoring platform.

Enterprise capability groups

Organized view of environment capabilities and their operational purpose.

Enterprise Foundation

Virtualization, endpoints, and core infrastructure that host and support the environment.

Capability group

Identity Services

Identity, authentication, and name services that control access and policy.

Capability group

Security Operations

Telemetry collection, logging, and detection to observe and analyze activity.

Capability group

Network Architecture

Network security, segmentation, and traffic control across trust boundaries.

Capability group

Offensive Platform

Assessment, tooling, and attack-simulation capabilities for offensive operations.

Capability group

Recovery & Resilience

Backup, recovery, and resilience systems to restore and validate operational continuity.

Capability group

Enterprise capability roadmap

Planned capabilities and future phases of environment evolution.

  1. Phase 5

    Endpoint & Policy Engineering

    planned
    • Endpoint expansion
    • Group Policy engineering
    • Security baselines
    • Policy validation
  2. Phase 6

    Detection & Threat Hunting

    planned
    • Detection engineering
    • Correlation searches
    • Threat-hunting workflows
    • Coverage validation
  3. Phase 7

    Attack Simulation & Purple Team

    future
    • Authorized attack simulation
    • Detection validation
    • Purple-team workflows
    • Operational reporting
  4. Phase 8

    Automation & Cloud Expansion

    future
    • Engineering automation
    • Security orchestration
    • Controlled cloud integration
    • Hybrid visibility
Engineering records

All systems and capabilities are documented, validated, and linked to engineering records.
This environment is continuously improved through testing, assessment, and operational feedback.

View engineering records