Skip to content
Jacky Bosega monogram logoJACKY BOSEGA
The Lab

Security / Research

Authorised Pen-Test Range

A closed, self-owned range for vulnerability research and defensive learning — fully isolated, fully authorised, never pointed outward.

Started 2024-09-15 / Updated 2025-07-05

Security understanding does not come from reading advisories. It comes from watching an attack path work and then closing it.

Everything here runs on hardware I own, against targets I built, on a network segment with no route to anything else. That constraint is the point.

Rules of engagement

The rules are simple and non-negotiable, and they are what make the research legitimate.

  • Only self-owned, intentionally vulnerable targets.
  • No route from the range to the internet or to any other zone.
  • Findings stay in the lab; nothing is tested against third-party systems.
  • Every session starts from a snapshot and ends with a rollback.

What the range is for

Understanding detection, not exploitation. The interesting half of every exercise is what the logs, the firewall and the host telemetry did — or failed to — record while the attack ran.

Carry-over into real work

It changed how I read marketing and data infrastructure. Tag containers, tracking endpoints and third-party scripts are attack surface, and now I look at them that way.

Setup

Domain
Security
Isolation
Air-gapped segment, no egress
Authorisation
Self-owned targets only
Focus
Detection and defence

Tags

Stack

  • Isolated VLAN
  • Hypervisor snapshots
  • Vulnerable target images
  • Host and network logging

Domain

All Security experiments

Authorised, ethical and controlled

All cybersecurity and penetration-testing activity is performed in authorised, ethical and controlled lab environments, on systems I own or have explicit written permission to test.

Want the detail behind this experiment?

If this overlaps with something you're building, I'm happy to share what worked and what didn't.