A hands-on pivoting lab
An isolated eight-machine network in Docker. Start on the attacker box, enumerate, get a foothold, then tunnel through it to reach internal services and web apps you can't touch directly. You just log in and start.
First time? About 10 minutes — most of it Docker installing. Done once.
Free, one-time, and the only software you need. Download for your system ↗, install it, and start it — wait until it shows “running”.
⭳ Download the ZIP, then unzip it. You'll get a folder named cybersecurity-lab-lateral-movement-main — put it somewhere easy, like your Desktop.
On Windows, “Extract All” nests it one level deeper — cybersecurity-lab-lateral-movement-main\cybersecurity-lab-lateral-movement-main. That's normal: the inner folder (the one containing start.bat) is the one you want. Move it somewhere easy and delete the empty outer one.
Prefer the terminal? Open Terminal, type cd (with a trailing space), drag the folder onto the window, press Enter, then run ./start.sh
If a window flashes open and vanishes: right-click an empty spot inside the folder → Open in Terminal, type .\start.bat and press Enter — the message stays on screen. It usually says Docker Desktop isn't running yet.
Or from any terminal: cd path/to/cybersecurity-lab-lateral-movement-main && ./start.sh
Two network segments. Break in, then pivot to reach what you shouldn't.
You start on the attacker box (secutils). The goal is to move laterally — enumerate the network, get a foothold on a host, then tunnel through it (SSH / SOCKS proxy) to reach internal services (LDAP, MySQL, telnet) and the vulnerable web apps you can't hit directly.
Eight machines across two segments — corp and internal. The attacker box is highlighted.
Hands-on security labs across the lifecycle — plus two companion books and a game that tie it together. Found one? Here's the rest — or browse the whole series on the series home.