Security365 Lab Launcher · Windows (M3) Labs ATT&CK Navigator
Windows attack lifecycle · pick a stage

The Windows kill chain, one lab at a time

Each lab is a stage of the same engagement against one target (Metasploitable 3 @ 10.10.10.12, Windows Server 2008 R2): reconnaissance feeds SMB enumeration, which confirms the EternalBlue surface. Walk them top to bottom, or jump to any stage. The Blue Team capstone reconstructs the whole chain from Windows event logs.