clong/DetectionLab resource
Automate the creation of a lab environment complete with security tooling and logging best practices observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3448
- days_rel: n/a
- days_push: 788
- n_releases_24m: 0
Adoption not part of the score
5010 stars · 1010 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
DetectionLab is an automation project that builds a Windows domain lab environment pre-loaded with security tooling and logging best practices using Vagrant, Packer, Terraform, and Ansible. It is designed for defenders to quickly spin up hosts with tools like Splunk, osquery/Fleet, Sysmon, Zeek, and Suricata for detection and DFIR testing.
Use cases
- build a windows domain lab for security testing
- set up a dfir lab environment
- practice security detection engineering
- test sysmon and osquery configurations
- learn windows event forwarding and logging best practices
- simulate an enterprise network for blue team training
When to choose
- you need a reproducible windows domain lab with pre-installed security tooling
- you want to learn or test detection and logging configurations
- you are a defender or DFIR analyst practicing in a safe environment
When to avoid
- you need a hardened or production-ready environment
- you require active maintenance or up-to-date tooling
- you want a minimal lab without heavy resource requirements
Facets
infra-config · maturity abandoned
security monitoring logging infrastructure-as-code deployment security self-hosted windows dfir detection-lab vagrant packer ansible osquery sysmon splunk zeek suricata windows-domain security-tooling lab-environment devops linux terraform
1 source
- readme: https://github.com/clong/DetectionLab · fetched 2026-08-28 · c18d35747ee0
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| clong/DetectionLab | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="clong/DetectionLab")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem