Skip to main content

Beadli Lab Academy

Build the enterprise yourself. Then defend it.

The lab you'll build

Every module adds a piece. This is where you end up: a segmented, monitored, attacked-and-defended enterprise, on one machine, which you then sync to a cloud tenant the way real hybrid environments do. The tier badges show when each piece arrives.

INTERNETNATMicrosoft Entra IDcloud directory · free tierT1Entra Connectpassword hash syncYOUR LAPTOPone machine runs everythingT116 GBT232 GBT364 GB+FW01OPNsense firewallT2WANLANWAN · the hostile sideKALI01Kali · attacker boxT1LAN · lab.internalDC01Active Directory · DNST1DC02second DC · often offT1SUBCA01issuing CA · PKIT2ADFS01single sign-onT2ROOTCA01offline root · offT2UBNT01Ubuntu · Docker host · Ansible controlT1Wazuh SIEMGrafanaGiteaKeycloakstep-canginxOPENVAS01vulnerability scannerT3SURICATA01network IDS · dual NICT3sees both segmentsVMware Workstation Pro · the hypervisor (VirtualBox works too)

One lab, built by you

Every module adds to the same environment: Active Directory, PKI, single sign-on, Docker, Ansible, monitoring. By the capstone you are running a mock enterprise on your own hardware, not a pile of disconnected exercises, and performing GRC for compliance.

You will know why it works

Every step explains the concept behind it and how the same thing is done in a real enterprise. The war stories come from a lab that exists and breaks like any other. A 16 GB laptop gets you through most of it.

Then attack it

Kali against your own lab: run the attacks, watch your detections fire, tune them, repeat. Finish with an incident investigation in infrastructure you built from nothing.

AI as a working tool

Claude is part of the toolkit from Module 1, used the way working engineers use it: troubleshooting errors, turning shell history into documentation, reviewing configs before they ship. With two rules that matter more than any prompt: understand a command before you run it, and keep secrets out of the chat window.