π Day 40 β Building a Reproducible Windows SOC VM and Lab Infrastructure
π― Goal
The goal for today was to start transforming the lab from a collection of tools into a structured, reproducible cybersecurity environment.
The focus was on:
- Building a Windows SOC investigation VM
- Installing core blue-team analysis tools
- Creating a bootstrap script for automated setup
- Designing a Git-tracked lab infrastructure
- Documenting the architecture so the environment can be rebuilt from scratch
This moves the lab from an ad-hoc setup to a version-controlled security research environment.
π What I Did
1οΈβ£ Built a Windows SOC Investigation VM
A Windows 11 VM was prepared to act as the endpoint under investigation in the lab.
The idea is that Windows generates telemetry while other machines analyze it.
Core system preparation included:
- enabling PowerShell 7
- enabling OpenSSH server
- preparing a structured workspace:
C:\Repos\cyberlab-blueprint
This repository structure will store:
- automation scripts
- configurations
- architecture documentation
- rebuild guides
This ensures the entire lab can be recreated if the VM is lost or corrupted.
2οΈβ£ Created a Windows Bootstrap Script
Instead of installing tools manually, I built a PowerShell bootstrap script to automate setup.
The script installs the core investigation stack using winget.
Tools included:
- 7-Zip β archive handling
- Nmap β network scanning
- Sysinternals Suite β Microsoft investigation toolkit
- System Informer β advanced process inspection
- Velociraptor β DFIR (Digital Forensics & Incident Response) platform
The script also configured PowerShell 7 as the SSH shell for remote access.
This means a fresh Windows VM can be rebuilt with a single command.
3οΈβ£ Organized the Lab Repository Structure
A structured repository was created for the lab:
cyberlab-blueprint
β
βββ windows
β βββ scripts
β βββ config
β βββ manual-tools
β
βββ docs
Purpose of directories:
scripts
Automation scripts used to configure systems.
config
Configuration files such as telemetry configurations.
manual-tools
Reserved for forensic tools that should not be automatically installed.
docs
Lab architecture and rebuild documentation.
This structure allows the entire environment to be tracked with Git.
4οΈβ£ Initialized the Lab Git Repository
The repository was initialized locally:
git init
Then configured with identity information and committed.
Key files tracked include:
- Windows bootstrap automation
- rebuild documentation
- architecture notes
- configuration files
This creates a version-controlled infrastructure blueprint.
5οΈβ£ Connected the Repository to GitHub
The GitHub CLI (gh) was installed and used to authenticate with GitHub.
A remote repository was then created and pushed:
JuriBuora/cyberlab-blueprint
The repository now acts as the source of truth for the entire lab.
If the environment is destroyed, it can be rebuilt from the repository.
π Key Cybersecurity Connections
Todayβs work connects strongly with real SOC engineering practices.
Modern security teams rely heavily on:
Infrastructure as Code
Systems are rebuilt automatically using scripts rather than manual setup.
Version-controlled environments
Security tools, configurations, and detection rules are stored in Git repositories.
Reproducible investigation environments
Analysts must be able to rebuild their systems reliably.
The lab now mirrors this model.
β Challenges
Execution Policy Blocking PowerShell Scripts
Windows initially blocked the bootstrap script due to the default PowerShell execution policy.
The solution was to enable script execution:
Set-ExecutionPolicy RemoteSigned
This allows locally created scripts to run safely.
Git Identity Configuration
Git refused to commit changes until a user identity was configured.
This required setting global configuration:
git config βglobal user.name
git config βglobal user.email
Once configured, commits worked normally.
π What I Learned
Several key lessons emerged today.
Security environments should be reproducible
Manually installing tools creates fragile systems.
Automating setup ensures environments can be rebuilt reliably.
Version control is critical for infrastructure
Git repositories are not only for code.
They can track:
- investigation tooling
- configuration files
- environment documentation
This makes complex environments easier to manage.
A structured lab is more valuable than many tools
Simply installing tools is not enough.
A useful security lab requires:
- documentation
- structure
- reproducibility
- clear architecture
β‘ Next Steps
Next improvements planned for the lab:
- install Sysmon telemetry
- generate realistic Windows security logs
- simulate suspicious activity
- analyze telemetry from other machines in the lab
This will move the lab toward a true SOC investigation environment.
π§ Reflection
Today marked a shift from simply learning tools to building infrastructure.
The lab is starting to resemble the environments used by real blue-team engineers.
By structuring the environment around:
- automation
- version control
- documentation
the lab becomes a long-term platform for experimentation and investigation rather than a disposable VM.
π§© Lessons Learned
What worked
Automating system setup with PowerShell and winget.
What broke
PowerShell execution policies initially prevented scripts from running.
Why it broke
Windows blocks scripts by default for security reasons.
Fix / takeaway
Security environments must account for platform restrictions and configure them appropriately.
π Skill Progression Context
This work strengthens several important cybersecurity skills:
- infrastructure management
- Windows system familiarity
- blue-team tooling
- version-controlled environments
- reproducible lab design
These skills are essential for roles such as:
- SOC analyst
- detection engineer
- DFIR analyst
- security engineer
Building and maintaining a structured lab environment is a critical step toward developing practical security investigation capabilities.
