This series documents my cybersecurity homelab on a single Proxmox node. I use it to learn networking, Windows identity, SIEM telemetry, detection work, attack simulation, honeypots, malware-analysis isolation, and automation.

The goal is not to build many random virtual machines. The goal is to build a small but realistic lab where each network has a clear job, and each path between networks can be explained.

Logical topology — Tailscale remote access in front of Proxmox + pfSense, each function in its own VLAN (SIEM, DEFENCE, CONTAINER, PENTEST, HONEYPOT, CLIENT, ISOLATED). Click to enlarge.

Series Map

PartFocus
1Proxmox, pfSense, and the first internal bridge
2Alpine jumpbox and safe access to pfSense
3VLANs, gateways, and early DHCP
4Docker, Portainer, n8n, and macvlan
5Kali and Metasploitable in the pentest segment
6Wazuh SIEM foundation and first log sources
7Snort IDS, T-Pot, and honeypot telemetry
8Tailscale remote access behind CGNAT
9Isolated malware-analysis segment
10Active Directory, DNS, DHCP, and domain join
11Final pfSense firewall rules and segmentation hardening

VLANs

VLANSubnetPurpose
LAN10.10.1.0/24first access, jumpbox, and emergency management
1010.10.10.0/24SIEM and monitoring systems
2010.10.20.0/24defence services: Active Directory, DNS, and DHCP
3010.10.30.0/24Docker host, Portainer, automation, and containers
4010.10.40.0/24Kali and intentionally vulnerable targets
5010.10.50.0/24honeypots and attack telemetry
6010.10.60.0/24Windows clients and endpoint telemetry
9910.10.99.0/24isolated malware-analysis machines