Hub of my cybersecurity lab portfolio. Each project builds part of the security programme of LogiSecure SA, a fictional Belgian parcel logistics operator, on one shared lab environment. A project is listed here once its repository is published, plus the one in progress. Every figure on this page is evidenced in a repository.
| Attribute | Detail |
|---|---|
| Sector | Parcel logistics for B2B e-commerce — warehousing, automated sorting, collection and delivery |
| Size | 500 employees · HQ Brussels, Belgium |
| NIS2 status | Important entity under the Belgian NIS2 law (in force since 18 Oct 2024): courier service provider (Annex II — postal and courier services) · large enterprise · ex post supervision by the CCB |
| Reference frameworks | ISO 27001 · IEC 62443 (OT) |
| OT environment | Sorting conveyors · legacy HMI (Windows 7) · PLC · WMS · SCADA historian |
| Suppliers | TechLogix BV (WMS) · ConveyorPro GmbH (OT) · DataAPI SAS (API) |
| Key risks | Ransomware · IT→OT lateral movement · API data leak · Supply chain compromise |
This table describes the scenario. What is actually built is shown in Lab Architecture.
| Repository | Status | Evidenced results |
|---|---|---|
| logisecure-active-directory | ✅ Completed | AD domain lab.local with OU design · 4 GPOs (password, lockout, audit, hardening) · Wazuh agents on DC01 and WKS01 · 3 custom MITRE-mapped rules · PingCastle: Privileged Accounts 50 → 40, Stale Objects 41 → 36 |
| logisecure-pfsense-segmentation | ✅ Completed | WAN / LAN / DMZ behind pfSense · 12 firewall rules, default-deny on every interface · Suricata on 3 interfaces (inline IPS on WAN, IDS on LAN and DMZ) · DMZ scan alerts in Wazuh, mapped to T1046 · OpenVAS validated against an nmap baseline |
| logisecure-ebios-rm-assessment | 🔄 In progress | EBIOS RM risk assessment of LogiSecure SA |
Each completed project has a lessons_learned.md documenting what went wrong, why, and what changed — start with the detection rule that never fired for four months.
LOGISECURE SA — LAB AS BUILT
INTERNET / WAN (VirtualBox NAT)
│
[pfSense CE 2.7.2 — firewall / router] → logisecure-pfsense-segmentation
│ Suricata: WAN inline IPS · LAN IDS · DMZ IDS
│
├── [LAN IT — 10.10.10.0/24]
│ DC01 10.10.10.10 AD DS · DNS · GPO → logisecure-active-directory
│ WKS01 10.10.10.20 domain workstation → logisecure-active-directory
│ Wazuh 10.10.10.30 SIEM manager → logisecure-active-directory
│
└── [DMZ — 10.10.20.0/24]
Kali 10.10.20.10 test / attack host → logisecure-pfsense-segmentation
Detection paths: Wazuh agents on DC01 and WKS01 · DMZ Suricata alerts → syslog → Wazuh
Kali also runs OpenVAS (GVM); it was moved to the LAN (10.10.10.50) for the vulnerability scans, so that the scan measures the hosts rather than the firewall.
Known limits — documented in logisecure-pfsense-segmentation: the LAN is flat (no micro-segmentation); a gateway IDS cannot see traffic inside a segment, so lateral movement within
10.10.10.0/24is only partly covered by the Wazuh agents; only the DMZ sensor is forwarded to Wazuh, over plain UDP syslog.
| Domain | In place (evidenced) | Known gaps | Repository |
|---|---|---|---|
| Identity & Access Management | 4 GPOs · MachineAccountQuota = 0 · AD Recycle Bin · AES256 on all accounts · NTLMv2 only · LDAP signing · admin account marked sensitive · PingCastle Privileged Accounts 50 → 40, Stale Objects 41 → 36 | PingCastle domain risk level still 55/100 — residual Anomalies (pass-the-credential, network sniffing) | logisecure-active-directory |
| Network Segmentation | LAN and DMZ behind pfSense · 12 justified rules, default-deny on every interface · DMZ→LAN blocked and logged · 7 logged rules | LAN still flat · rules 2, 3 and 10 in place but untested — they govern access to a DMZ web service not deployed yet | logisecure-pfsense-segmentation |
| Threat Detection | Wazuh 4.14.5 · 2 agents · DMZ Suricata alerts parsed by a custom decoder · 3 custom AD rules mapped to T1078, T1087 and T1110 · network scans detected and mapped to T1046, validated with nmap from the DMZ | The T1110 rule (100001) fires on a single failed logon — it detects failures, not brute force yet · rule 100002 is noisy · WAN and LAN sensors not forwarded | logisecure-active-directory · logisecure-pfsense-segmentation |
| Vulnerability Management | OpenVAS unauthenticated scan of DC01 and WKS01, first scan invalidated by an nmap baseline and redone: 0 Critical · 0 High · 2 Medium · 1 Low | No authenticated (patch-level) scan yet · 2 NVTs timed out on DC01 | logisecure-pfsense-segmentation |
| Framework | Where it is applied |
|---|---|
| MITRE ATT&CK | Detections mapped to T1046 (Suricata scan alerts in Wazuh), T1078 and T1087 (custom Wazuh rules) · Mitigations for T1110 (account lockout) and T1557 (LLMNR disabled) |
| CIS Benchmarks | GPO hardening — password and lockout policies, NTLMv2 only, SMB signing |
| ISO 27001:2022 · NIS2 Art. 21 | Default-deny firewall rules justified against ISO 27001 A.8.20 and NIS2 Art. 21 |
All environments simulate the fictional enterprise LogiSecure SA, used solely for educational and portfolio purposes.
Built by Maxime Belliard — Cybersecurity · Technical & GRC