Mayuri is a sanitized, evidence-backed Windows investigation and DFIR lab. Its primary mission is to develop repeatable skills in Windows endpoint investigation, Active Directory analysis, Velociraptor collection, Splunk investigation, evidence handling, and defensible incident reporting while preserving the existing segmented purple-team architecture.
Wazuh, OpenCTI, Shodan, SOAR-style orchestration, Suricata, and detection engineering remain supporting capabilities in maintenance mode. Routine work is limited to health, security, compatibility, and investigation-driven fixes; independent platform expansion is not a priority. They provide leads and context, not substitutes for evidence-led investigation.
This repository documents the lab without publishing exact addresses, MACs, internal DNS names, credentials, tokens, firewall rules, or raw evidence.
- Architecture
- Asset inventory
- Network segmentation
- Telemetry pipeline
- Purple-team workflow
- Validation matrix
- Recovery model
- Storage budget
- Cloud DFIR range
Only these implementation/validation states are used:
- Planned — documented intent without installation or execution proof.
- Installed — software or configuration is present, but current operation has not been verified.
- Verified — current state was observed through a read-only or benign check.
- Live validated — a controlled event exercised the stated path end to end. Historical Live validated evidence does not prove current service health; every new investigation starts with preflight checks.
| Capability | Priority | Status | Public-safe boundary |
|---|---|---|---|
| Segmented virtualization and recovery checkpoints | Foundation | Verified | Separate management, enterprise, attack, and DFIR zones with milestone snapshots |
| Windows identity and domain-member trust | Highest | Verified | AD DS, DNS, Netlogon, and secure-channel checks were observed |
| Windows endpoint telemetry | Highest | Verified | Native logs, Sysmon, PowerShell logging, Wazuh, Splunk forwarder, and Velociraptor agent presence were observed |
| Splunk investigation and case routing | Highest | Live validated | Existing PowerShell evidence records a controlled detection-to-case path; current health still requires preflight |
| Velociraptor remote collection | Highest | Live validated | Existing evidence records a benign endpoint collection; current server, listener, and client health are not implied |
| DFIR workstation and full investigation toolchain | Highest | Installed | Core workspace and tools are staged; complete tool-by-tool and end-to-end verification remains required |
| Wazuh and OpenCTI platform health | Supporting / maintenance mode | Verified | Historical service and response checks exist; each exercise requires current preflight |
| Shodan and bounded alert-enrichment workflows | Supporting / maintenance mode | Live validated | Existing evidence covers specific enrichment and routing paths only; current health and broader coverage are not implied |
| Suricata network context | Supporting | Verified | Runtime checks exist; no broad detection-coverage claim is made |
| Detection engineering | Supporting | Live validated | Existing PowerShell evidence covers one bounded detection path; broader content and current health are not implied |
Investigation roadmap MAY-IR-001 through MAY-IR-005 |
Highest | Planned | Scenario plans do not claim completed full-lifecycle investigations |
| AWS-adjacent DFIR range | Future adjacent | Planned | Design boundary only; this repository does not provision cloud resources |
flowchart LR
Admin[Authorized operator] --> PVE[Proxmox hypervisor]
PVE --> FW[Virtual firewall / router]
FW --> ENT[Enterprise segment]
FW --> ATK[Attack segment]
FW --> DFR[DFIR segment]
ENT --> DC[Windows identity server]
ENT --> WIN[Windows validation target]
ENT --> SOC[SOC platform]
ENT --> CTI[Threat-intelligence platform]
ATK --> KALI[Authorized attacker workstation]
DFR --> DFIR[DFIR workstation]
WIN -->|Windows and Sysmon telemetry| SOC
DC -->|Identity and security telemetry| SOC
SOC -->|Lead and alert context| DFIR
DFIR -->|Approved collection| WIN
DFIR -->|Case findings| CASES[Private case storage]
CASES -->|Sanitized summary only| PUBLIC[Public repository]
SOC -->|Bounded enrichment request| CTI
CTI -->|Advisory context| SOC
Mayuri treats alerts as leads, not conclusions. Each exercise follows the 21-step investigation lifecycle: prepare and generate a controlled behavior, triage and scope it across endpoint/identity/network evidence, determine cause and impact, contain and remediate when authorized, identify telemetry and detection gaps, publish a sanitized report, and restore the lab.
| Path | Purpose |
|---|---|
docs/ |
Investigation model, architecture, operating boundaries, validation, recovery, and limitations |
evidence/ |
Text-only sanitized historical validation summaries; never raw evidence |
config/ |
Abstract example inventory with no live values |
automation/ |
Credential-free supporting enrichment and case-routing references |
tests/ |
Unit coverage for supporting integration behavior |
scripts/ |
Public-safety and Markdown-link checks |
.github/workflows/ |
CI enforcement for documentation safety |
- Testing is limited to explicitly authorized lab assets.
- The attack segment is not a general-purpose offensive platform.
- No production, home, or internet target is in scope.
- Containment, account changes, isolation, deletion, and destructive actions require explicit approval.
- Credentials and live infrastructure configuration remain outside this repository.
- Raw EVTX, PCAP, memory images, disk images, malware, sensitive logs, and private case directories are never committed.
- Public artifacts contain sanitized findings and integrity metadata only.
These records demonstrate bounded historical outcomes, not present lab health or completion of the new investigation roadmap:
- PowerShell detection-to-case validation
- Velociraptor collection validation
- OpenCTI and Shodan enrichment validation
- Wazuh and Splunk alert-enrichment validation
- Windows endpoint and Active Directory investigation planning;
- evidence acquisition, hashing, timelines, and private case handling;
- Velociraptor collection and Splunk-led investigation workflows;
- segmented lab architecture, snapshots, cleanup, and change control;
- bounded use of Wazuh, Suricata, CTI, orchestration, and detection engineering as supporting capabilities;
- honest separation of Planned, Installed, Verified, and Live validated claims;
- public-safe reporting without raw evidence or private infrastructure details.
This is a lab reference, not a production architecture or deployment repository. Exact network policy, credentials, live configuration, raw evidence, and private case content are intentionally excluded. See Known limitations.
Documentation and example configuration are released under the MIT License.