Offensive security development through enterprise replication.
Lab environment
RedForge Lab Environment
The RedForge Lab Environment replicates enterprise identity, infrastructure, endpoint, and security-monitoring workflows while integrating an isolated offensive-security range for controlled adversary simulation and security validation.
Each implemented system is validated, documented, and connected to engineering records.
Future capabilities remain visible but are clearly distinguished from verified infrastructure.
Build • Validate • Document
Assess • Improve
Identity • Infrastructure • Telemetry
Offensive Security • Detection
2026-08-10
Verified topology
Interactive view of the verified environment. Select any system to explore details and related records.
▣ Virtualization boundary
Offensive Security Attack Range
Verified operational security testing environmentSelected system
RF-DC01
Windows Server 2025Operational- Purpose
- Provides verified enterprise identity, authentication, authorization, and integrated name-resolution services.
- Roles
- Domain controller
- Identity service
- DNS service
- Services
- Active Directory Domain Services
- Integrated DNS
- Enterprise authentication
- Telemetry
- Windows security and authentication telemetry is received and searchable in Splunk Enterprise.
Reviewed implementation evidence
Authentic Active Directory, DNS, Group Policy, indexing, and telemetry evidence from the verified environment.
Screenshot Gallery







Enterprise capability groups
Organized view of environment capabilities and their operational purpose.
Enterprise Foundation
Virtualization, endpoints, and core infrastructure that host and support the environment.
Capability groupIdentity Services
Identity, authentication, and name services that control access and policy.
Capability groupSecurity Operations
Telemetry collection, logging, and detection to observe and analyze activity.
Capability groupNetwork Architecture
Network security, segmentation, and traffic control across trust boundaries.
Capability groupOffensive Platform
Assessment, tooling, and attack-simulation capabilities for offensive operations.
Capability groupRecovery & Resilience
Backup, recovery, and resilience systems to restore and validate operational continuity.
Capability groupEnterprise capability roadmap
Planned capabilities and future phases of environment evolution.
- Phase 5
Endpoint & Policy Engineering
planned- Endpoint expansion
- Group Policy engineering
- Security baselines
- Policy validation
- Phase 6
Detection & Threat Hunting
planned- Detection engineering
- Correlation searches
- Threat-hunting workflows
- Coverage validation
- Phase 7
Attack Simulation & Purple Team
future- Authorized attack simulation
- Detection validation
- Purple-team workflows
- Operational reporting
- Phase 8
Automation & Cloud Expansion
future- Engineering automation
- Security orchestration
- Controlled cloud integration
- Hybrid visibility
All systems and capabilities are documented, validated, and linked to engineering records.
This environment is continuously improved through testing, assessment, and operational feedback.