🎉 Launch offer — 20% off every workbook & bundle. Applied automatically at checkout.
ciso.diy
R02 — The Adversary Environment Corpus preview
Cyber Range cyber rangeGOADActive DirectoryVulhub

R02 — The Adversary Environment Corpus

What to put in the range and how to curate what you maintain — the GOAD family for Active Directory, Vulhub for per-CVE containers, cloud and IaC targets, organised into five handling tiers by reset cost and risk, with the maintenance treadmill made explicit.

Volume 01 built the facility. This volume fills it — and the first thing it tells you is to deploy less than you want to.

A corpus is not a download list. It is a maintained collection, and every environment you add creates recurring work: templates that expire, container images that silently patch themselves, upstream projects that go quiet, cloud accounts that bill while you sleep. The operators with useful ranges are the ones who said no to most of it. Every environment costs you roughly one template rebuild cycle, one upstream-breakage debugging session, and one "why doesn't this work anymore" morning per year — multiply by your corpus size and that is your annual tax, paid in the hours you wanted to spend testing.

The four questions an environment must pass to earn a slot, and five handling tiers by reset cost and risk: A Windows/Active Directory, B per-CVE reproduction, C web and application targets, D cloud and IaC (which does not run in your range at all), E malware and untrusted binaries.

Tier A — the expensive tier that justifies the hardware. The GOAD family (GOAD, GOAD-Light, the SCCM/MECM site hierarchy, NHA and DRACARYS), ADCS as its own toggleable environment so you can test one escalation path in isolation, and the gotchas that will cost you an evening: the ".local" domain suffix that breaks SCCM, the 15-character NetBIOS hostname limit, site role completeness, and client push firewall rules. Plus the 180-day evaluation licence clock — the single largest recurring cost in the corpus and the most common reason a range quietly dies.

Tier B — the CVE reproduction bench, where most of your working hours go and where it is cheap. Vulhub as the backbone, run as Tier 0 container work on one Linux VM you should be least precious about. Two traps: image drift (an unpinned corpus is not reproducible, and reproducibility is the entire point — pin by digest and mirror what you care about) and architecture, because a meaningful fraction of the bench will not start on ARM.

Tier D breaks the containment model and the chapter says so before you deploy anything in it: these environments run in a real cloud account with real billing and real internet exposure. Five rules — a dedicated account always, hard billing guardrails set before the first apply, destroy as part of the deployment, exposure restricted to your address, and nothing standing.

Tier E is optional and the rules are stricter: its own VLAN with no route to any other zone, zero egress with no build-time window, no shared storage, Tier 2 reset minimum every time.

Closes with the maintenance calendar, the annual deprecation review (the task everyone skips), how to build your own targets and client digital twins with structure replicated and contents never, and the corpus register whose "teaches" field does the real work — if you cannot write that sentence, the environment does not belong.

What's included

  • PDF — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
One-time purchase
$99.00 $79.20 20% off
  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-08-31
Pages 6