Skip to content
This repository was archived by the owner on Oct 4, 2026. It is now read-only.

Latest commit

 

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Mayuri Purple-Team Lab

Repository validation

Mayuri is a sanitized, evidence-backed Windows investigation and DFIR lab. Its primary mission is to develop repeatable skills in Windows endpoint investigation, Active Directory analysis, Velociraptor collection, Splunk investigation, evidence handling, and defensible incident reporting while preserving the existing segmented purple-team architecture.

Wazuh, OpenCTI, Shodan, SOAR-style orchestration, Suricata, and detection engineering remain supporting capabilities in maintenance mode. Routine work is limited to health, security, compatibility, and investigation-driven fixes; independent platform expansion is not a priority. They provide leads and context, not substitutes for evidence-led investigation.

This repository documents the lab without publishing exact addresses, MACs, internal DNS names, credentials, tokens, firewall rules, or raw evidence.

Start here

Investigation and career direction

Architecture and operations

Publication and supporting services

Status vocabulary

Only these implementation/validation states are used:

  • Planned — documented intent without installation or execution proof.
  • Installed — software or configuration is present, but current operation has not been verified.
  • Verified — current state was observed through a read-only or benign check.
  • Live validated — a controlled event exercised the stated path end to end. Historical Live validated evidence does not prove current service health; every new investigation starts with preflight checks.

Current status

Capability Priority Status Public-safe boundary
Segmented virtualization and recovery checkpoints Foundation Verified Separate management, enterprise, attack, and DFIR zones with milestone snapshots
Windows identity and domain-member trust Highest Verified AD DS, DNS, Netlogon, and secure-channel checks were observed
Windows endpoint telemetry Highest Verified Native logs, Sysmon, PowerShell logging, Wazuh, Splunk forwarder, and Velociraptor agent presence were observed
Splunk investigation and case routing Highest Live validated Existing PowerShell evidence records a controlled detection-to-case path; current health still requires preflight
Velociraptor remote collection Highest Live validated Existing evidence records a benign endpoint collection; current server, listener, and client health are not implied
DFIR workstation and full investigation toolchain Highest Installed Core workspace and tools are staged; complete tool-by-tool and end-to-end verification remains required
Wazuh and OpenCTI platform health Supporting / maintenance mode Verified Historical service and response checks exist; each exercise requires current preflight
Shodan and bounded alert-enrichment workflows Supporting / maintenance mode Live validated Existing evidence covers specific enrichment and routing paths only; current health and broader coverage are not implied
Suricata network context Supporting Verified Runtime checks exist; no broad detection-coverage claim is made
Detection engineering Supporting Live validated Existing PowerShell evidence covers one bounded detection path; broader content and current health are not implied
Investigation roadmap MAY-IR-001 through MAY-IR-005 Highest Planned Scenario plans do not claim completed full-lifecycle investigations
AWS-adjacent DFIR range Future adjacent Planned Design boundary only; this repository does not provision cloud resources

Architecture

flowchart LR
    Admin[Authorized operator] --> PVE[Proxmox hypervisor]
    PVE --> FW[Virtual firewall / router]

    FW --> ENT[Enterprise segment]
    FW --> ATK[Attack segment]
    FW --> DFR[DFIR segment]

    ENT --> DC[Windows identity server]
    ENT --> WIN[Windows validation target]
    ENT --> SOC[SOC platform]
    ENT --> CTI[Threat-intelligence platform]
    ATK --> KALI[Authorized attacker workstation]
    DFR --> DFIR[DFIR workstation]

    WIN -->|Windows and Sysmon telemetry| SOC
    DC -->|Identity and security telemetry| SOC
    SOC -->|Lead and alert context| DFIR
    DFIR -->|Approved collection| WIN
    DFIR -->|Case findings| CASES[Private case storage]
    CASES -->|Sanitized summary only| PUBLIC[Public repository]
    SOC -->|Bounded enrichment request| CTI
    CTI -->|Advisory context| SOC
Loading

Investigation posture

Mayuri treats alerts as leads, not conclusions. Each exercise follows the 21-step investigation lifecycle: prepare and generate a controlled behavior, triage and scope it across endpoint/identity/network evidence, determine cause and impact, contain and remediate when authorized, identify telemetry and detection gaps, publish a sanitized report, and restore the lab.

Repository map

Path Purpose
docs/ Investigation model, architecture, operating boundaries, validation, recovery, and limitations
evidence/ Text-only sanitized historical validation summaries; never raw evidence
config/ Abstract example inventory with no live values
automation/ Credential-free supporting enrichment and case-routing references
tests/ Unit coverage for supporting integration behavior
scripts/ Public-safety and Markdown-link checks
.github/workflows/ CI enforcement for documentation safety

Safety boundaries

  • Testing is limited to explicitly authorized lab assets.
  • The attack segment is not a general-purpose offensive platform.
  • No production, home, or internet target is in scope.
  • Containment, account changes, isolation, deletion, and destructive actions require explicit approval.
  • Credentials and live infrastructure configuration remain outside this repository.
  • Raw EVTX, PCAP, memory images, disk images, malware, sensitive logs, and private case directories are never committed.
  • Public artifacts contain sanitized findings and integrity metadata only.

Historical evidence highlights

These records demonstrate bounded historical outcomes, not present lab health or completion of the new investigation roadmap:

What this demonstrates

  • Windows endpoint and Active Directory investigation planning;
  • evidence acquisition, hashing, timelines, and private case handling;
  • Velociraptor collection and Splunk-led investigation workflows;
  • segmented lab architecture, snapshots, cleanup, and change control;
  • bounded use of Wazuh, Suricata, CTI, orchestration, and detection engineering as supporting capabilities;
  • honest separation of Planned, Installed, Verified, and Live validated claims;
  • public-safe reporting without raw evidence or private infrastructure details.

Limitations

This is a lab reference, not a production architecture or deployment repository. Exact network policy, credentials, live configuration, raw evidence, and private case content are intentionally excluded. See Known limitations.

License

Documentation and example configuration are released under the MIT License.

About

Sanitized architecture, runbooks, and live-validation evidence for a segmented Proxmox purple-team lab.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages