BSidesVienna 0x7e8

Cyber Range Fails: Lessons learned from building Defensive Labs
11-23, 13:35–14:05 (Europe/Vienna), Track 2 (3.1 (Kreativ))

I will share my experience in building defensive interactive labs. During the talk, I will cover typical cyber range architecture, its pros and cons. Listeners will gain insights into how to build their own cyber range.
I will share the problems that listeners will most likely encounter if they decide to build a home lab. By the end of the talk, listeners will be informed on how to build their own cyber range and how to avoid common mistakes.


I've been creating cyber ranges for a year. It turned out to be a non-trivial task.
The talk will be divided into four sections:
1. What is a Cyber Range?: I will explain the concept of a cyber range and review popular solutions like GOAD and CI-CD Goat, focusing on their key functions.
2. Cyber Range Architecture: I will cover the basic architecture of a typical cyber range, including components, network configurations, and integration approaches.
3. Cyber Range Fails: I will share specific problems we encountered while building a hosted cyber range, focusing on technical issues and operational mistakes.
4. Q&A. section.

I have been working in cybersecurity for over 10 years. Currently, I am part of the IT security team in the game development industry. In my free time, I design cyber ranges for my side project, Defbox.