🎯 Goal

The goal for today was to start transforming the lab from a collection of tools into a structured, reproducible cybersecurity environment.

The focus was on:

  • Building a Windows SOC investigation VM
  • Installing core blue-team analysis tools
  • Creating a bootstrap script for automated setup
  • Designing a Git-tracked lab infrastructure
  • Documenting the architecture so the environment can be rebuilt from scratch

This moves the lab from an ad-hoc setup to a version-controlled security research environment.


πŸ›  What I Did

1️⃣ Built a Windows SOC Investigation VM

A Windows 11 VM was prepared to act as the endpoint under investigation in the lab.

The idea is that Windows generates telemetry while other machines analyze it.

Core system preparation included:

  • enabling PowerShell 7
  • enabling OpenSSH server
  • preparing a structured workspace:

C:\Repos\cyberlab-blueprint

This repository structure will store:

  • automation scripts
  • configurations
  • architecture documentation
  • rebuild guides

This ensures the entire lab can be recreated if the VM is lost or corrupted.


2️⃣ Created a Windows Bootstrap Script

Instead of installing tools manually, I built a PowerShell bootstrap script to automate setup.

The script installs the core investigation stack using winget.

Tools included:

  • 7-Zip β€” archive handling
  • Nmap β€” network scanning
  • Sysinternals Suite β€” Microsoft investigation toolkit
  • System Informer β€” advanced process inspection
  • Velociraptor β€” DFIR (Digital Forensics & Incident Response) platform

The script also configured PowerShell 7 as the SSH shell for remote access.

This means a fresh Windows VM can be rebuilt with a single command.


3️⃣ Organized the Lab Repository Structure

A structured repository was created for the lab:

cyberlab-blueprint
β”‚
β”œβ”€β”€ windows
β”‚ β”œβ”€β”€ scripts
β”‚ β”œβ”€β”€ config
β”‚ └── manual-tools
β”‚
└── docs

Purpose of directories:

scripts

Automation scripts used to configure systems.

config

Configuration files such as telemetry configurations.

manual-tools

Reserved for forensic tools that should not be automatically installed.

docs

Lab architecture and rebuild documentation.

This structure allows the entire environment to be tracked with Git.


4️⃣ Initialized the Lab Git Repository

The repository was initialized locally:

git init

Then configured with identity information and committed.

Key files tracked include:

  • Windows bootstrap automation
  • rebuild documentation
  • architecture notes
  • configuration files

This creates a version-controlled infrastructure blueprint.


5️⃣ Connected the Repository to GitHub

The GitHub CLI (gh) was installed and used to authenticate with GitHub.

A remote repository was then created and pushed:

JuriBuora/cyberlab-blueprint

The repository now acts as the source of truth for the entire lab.

If the environment is destroyed, it can be rebuilt from the repository.


πŸ”— Key Cybersecurity Connections

Today’s work connects strongly with real SOC engineering practices.

Modern security teams rely heavily on:

Infrastructure as Code

Systems are rebuilt automatically using scripts rather than manual setup.

Version-controlled environments

Security tools, configurations, and detection rules are stored in Git repositories.

Reproducible investigation environments

Analysts must be able to rebuild their systems reliably.

The lab now mirrors this model.


⚠ Challenges

Execution Policy Blocking PowerShell Scripts

Windows initially blocked the bootstrap script due to the default PowerShell execution policy.

The solution was to enable script execution:

Set-ExecutionPolicy RemoteSigned

This allows locally created scripts to run safely.


Git Identity Configuration

Git refused to commit changes until a user identity was configured.

This required setting global configuration:

git config –global user.name
git config –global user.email

Once configured, commits worked normally.


πŸ“š What I Learned

Several key lessons emerged today.

Security environments should be reproducible

Manually installing tools creates fragile systems.

Automating setup ensures environments can be rebuilt reliably.


Version control is critical for infrastructure

Git repositories are not only for code.

They can track:

  • investigation tooling
  • configuration files
  • environment documentation

This makes complex environments easier to manage.


A structured lab is more valuable than many tools

Simply installing tools is not enough.

A useful security lab requires:

  • documentation
  • structure
  • reproducibility
  • clear architecture

➑ Next Steps

Next improvements planned for the lab:

  • install Sysmon telemetry
  • generate realistic Windows security logs
  • simulate suspicious activity
  • analyze telemetry from other machines in the lab

This will move the lab toward a true SOC investigation environment.


🧠 Reflection

Today marked a shift from simply learning tools to building infrastructure.

The lab is starting to resemble the environments used by real blue-team engineers.

By structuring the environment around:

  • automation
  • version control
  • documentation

the lab becomes a long-term platform for experimentation and investigation rather than a disposable VM.


🧩 Lessons Learned

What worked

Automating system setup with PowerShell and winget.

What broke

PowerShell execution policies initially prevented scripts from running.

Why it broke

Windows blocks scripts by default for security reasons.

Fix / takeaway

Security environments must account for platform restrictions and configure them appropriately.


πŸ“ˆ Skill Progression Context

This work strengthens several important cybersecurity skills:

  • infrastructure management
  • Windows system familiarity
  • blue-team tooling
  • version-controlled environments
  • reproducible lab design

These skills are essential for roles such as:

  • SOC analyst
  • detection engineer
  • DFIR analyst
  • security engineer

Building and maintaining a structured lab environment is a critical step toward developing practical security investigation capabilities.