← Back to portfolio Project

SAM.LAB — Home Enterprise Lab

A self-built small enterprise environment on domain sam.lab, running Active Directory, centralized endpoint management, a SIEM/SOC stack, and network security tooling — built from scratch for hands-on cybersecurity and network engineering practice.

Domain: sam.lab Network: 10.0.0.0/24 Windows Server 2022 Fully Implemented & Operational
1

Network & Infrastructure Diagram

Topology overview
SAM.LAB complete home enterprise lab network diagram

Full topology from the ISP router down through the pfSense/IPsec firewall into the sam.lab internal network — covering core infrastructure VMs (DC01, DHCP, DEPLOYWIN, CM01), physical servers (FILE01, WEB01, IPSEC-GW), the Hyper-V host, and managed client devices.

2

Security & Management Policies

Group Policy & hardening
SAM.LAB security and management policies implemented via Group Policy

All policies enforced across the domain via Group Policy — spanning identity & access, endpoint security, centralized management, monitoring & auditing, network security, data protection, access control, and compliance hardening.

3

Core Applications Implemented

Enterprise IT · SOC · Network Security
SAM.LAB core applications implemented, including SCCM, Wazuh, Sysmon, and pfSense

Fifteen tools configured, integrated, and operational — including SCCM, Ivanti Neurons, Wazuh SIEM/XDR, Sysmon, Wireshark, Nmap, Kali Linux, Greenbone/OpenVAS, pfSense, TheHive, Autopsy, Zabbix, and the Elastic Stack.