awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
clong avatar

clong/DetectionLab

0
View on GitHub↗
4,904 stars·1,013 forks·HTML·mit·18 views

DetectionLab

DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms.

The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients.

The environment includes a telemetry pipeline that aggregates Sysmon and Windows Event Logs from multiple hosts into a single analysis point. It further covers endpoint monitoring, network traffic analysis, and data forwarding to security information and event management systems.

Features

  • Windows Domain Detection Labs - Deploys a pre-configured Windows Active Directory environment specifically designed for testing security detection capabilities.
  • Lab Provisioning Automation - Uses Packer and Vagrant to automate the provisioning of multi-machine security laboratory environments.
  • Ansible Playbooks - Provides declarative playbooks to automate the installation of security tools and Active Directory services.
  • Vagrant Multi-Provider Orchestrators - Provides an automation framework using Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms.
  • Windows Domain Detection Testing - Creates a realistic Windows Active Directory environment specifically to verify security alerts and detection rules.
  • Centralized Logging Systems - Aggregates system logs and security telemetry from multiple endpoints into a single central analysis point.
  • Distributed Security Event Aggregation - Centralizes security logs and telemetry from multiple distributed hosts into a single analysis point.
  • Windows Event - Implements a telemetry pipeline that aggregates native Sysmon and Windows Event Logs from multiple hosts.
  • Windows Endpoint Monitoring - Configures system auditing and telemetry tools like Sysmon and OSQuery to track detailed activity across hosts.
  • Browser-Based Remote Desktops - Provides a browser-based remote access interface via Apache Guacamole for interacting with laboratory hosts.
  • Cloud Security Lab Provisioning - Provides infrastructure-as-code provisioning for cloud-based Windows security environments with Active Directory setups.
  • Hypervisor-Specific Lab Provisioning - Implements infrastructure-as-code tooling for provisioning security laboratory environments specifically on ESXi hypervisors.
  • Cross-Hypervisor Orchestration - Abstracts virtualization layers to deploy a single configuration across VirtualBox, VMware, Hyper-V, and cloud platforms.
  • Internal Lab Networks - Creates isolated private networks for virtual lab environments using virtual switches to contain security traffic.
  • Endpoint Auditing Configurations - Implements advanced auditing and transcript logging to capture detailed system and process activity on endpoints.
  • Browser-Based Remote Desktop Clients - Implements a web-based interface via Apache Guacamole for managing laboratory hosts without native RDP clients.
  • Centralized Environment Visibility - Provides a centralized connection system that links all hosts to a single server for unified environment visibility.
  • Browser-Accessible Labs - Offers a centralized web gateway for remote desktop access to all hosts within the security laboratory.
  • System Activity Monitoring - Tracks system processes and events using monitoring tools and custom auditing configurations.
  • Detection Labs - Automated lab setup for security tooling and logging practice.
  • DevSecOps and Automation - Automated lab environment for security tooling.
  • Detection and Hunting Tools - Automated lab environment setup for security tooling and logging.
  • Lab Environments - Automated lab environment with security tooling.
  • Security Tools - Listed in the “Security Tools” section of the Awesome Hacking awesome list.

Star history

Star history chart for clong/detectionlabStar history chart for clong/detectionlab

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with DetectionLab

These projects share indexed features with DetectionLab. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • stamparm/maltrailstamparm avatar

    stamparm/maltrail

    8,498View on GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    View on GitHub↗8,498
  • elastic/beatselastic avatar

    elastic/beats

    12,630View on GitHub↗

    Beats is a collection of lightweight, modular agents designed to gather, process, and forward operational telemetry from distributed infrastructure to centralized storage and analysis platforms. These agents function as a distributed data transport layer, decoupling the collection of logs, metrics, and network events from their final delivery destination. By maintaining local state and managing data flow, the system ensures reliable transmission of information across heterogeneous environments. The project distinguishes itself through a modular pipeline architecture that allows for the assemb

    Gofilebeatheartbeatmetricbeat
    View on GitHub↗12,630
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • linuxserver/docker-webtoplinuxserver avatar

    linuxserver/docker-webtop

    3,936View on GitHub↗

    This project is a containerized Linux desktop streamer that renders a full operating system interface in a web browser using encoded video streams. It allows for remote access to various Linux distributions and serves as a platform for browser-based application hosting. The system supports GPU acceleration via KVM and direct hardware passthrough to enable low-latency graphics rendering and video encoding. It also features volume mapping for home directory persistence, ensuring that user data and portable applications survive environment updates. Additional capabilities include the creation o

    Shellalpinearchdocker
    View on GitHub↗3,936
Compare all 30 related projects→

Frequently asked questions

What does clong/detectionlab do?

DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms.

What are the main features of clong/detectionlab?

The main features of clong/detectionlab are: Windows Domain Detection Labs, Lab Provisioning Automation, Ansible Playbooks, Vagrant Multi-Provider Orchestrators, Windows Domain Detection Testing, Centralized Logging Systems, Distributed Security Event Aggregation, Windows Event.

Which projects share features with clong/detectionlab?

Projects with overlapping indexed features include: stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network… elastic/beats — Beats is a collection of lightweight, modular agents designed to gather, process, and forward operational telemetry… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… linuxserver/docker-webtop — This project is a containerized Linux desktop streamer that renders a full operating system interface in a web browser… kunkundi/crossdesk — Crossdesk is a cross-platform remote desktop software used for streaming and controlling remote computers. It consists… lwch/natpass — Natpass is a web-based remote access gateway and orchestrator designed to manage remote server instances, desktop…