Skip to main content

Security Scanning & Validation Labs

This track develops disciplined use of security assessment tools across network, web application, content-management, wireless and Linux environments. The emphasis is not merely running a scanner: learners define scope, select bounded techniques, preserve evidence, validate findings, minimise false positives and produce remediation-ready reports.

Authorised lab targets only

Use only the supplied Northstar Training Services lab range, synthetic evidence and instructor-approved vulnerable targets. Never scan public IP space, third-party websites, production applications, customer wireless networks or systems outside a written rules-of-engagement document.

Track outcomes

By completing the track, you will be able to:

  1. translate a rules-of-engagement document into tool-safe target and timing controls;
  2. distinguish discovery, vulnerability identification, verification and exploitation;
  3. configure scanners to reduce unnecessary traffic and operational risk;
  4. correlate findings across tools rather than treating scanner output as proof;
  5. preserve timestamps, commands, configurations and raw evidence for reproducibility;
  6. assign remediation priorities using exploitability, exposure, business impact and compensating controls;
  7. close an assessment with cleanup, retesting and residual-risk documentation.

Lab sequence

PurposeCodeLabDuration
Network vulnerability scanningLAB-SEC-201OpenVAS / Greenbone Vulnerability Management75 min
Network vulnerability scanningLAB-SEC-202Nmap NSE Service & Vulnerability Discovery75 min
Web application scanningLAB-WEB-201Burp Suite Proxy & Manual Validation90 min
Web application scanningLAB-WEB-202OWASP ZAP Baseline & Governed Active Scan75 min
Web application scanningLAB-WEB-203Nikto Web Server Misconfiguration Review60 min
Web application scanningLAB-WEB-204Wapiti Black-Box Web Application Scan75 min
CMS scanningLAB-CMS-201WPScan WordPress Assessment60 min
CMS scanningLAB-CMS-202Droopescan Drupal/Joomla Discovery60 min
CMS scanningLAB-CMS-203CMSmap Cross-CMS Fingerprinting60 min
WirelessLAB-WIFI-201Aircrack-ng Offline Capture Analysis75 min
WirelessLAB-WIFI-202Kismet Passive Wireless Reconnaissance75 min
System auditingLAB-SYS-201Lynis Linux Security Audit75 min
Exploitation + scanningLAB-EXP-301Metasploit Vulnerability Validation90 min
Integrated assessmentLAB-SEC-390Security Assessment Capstone150 min

Authorised environment

The fictional Northstar range uses reserved lab names and a private subnet:

AssetAddressPurpose
scanner.lab10.77.0.5Learner assessment workstation
web.lab10.77.0.20Resettable vulnerable web application
wordpress.lab10.77.0.30Resettable WordPress target
drupal.lab10.77.0.31Resettable Drupal target
linux-audit.lab10.77.0.40Linux auditing target
metasploitable.lab10.77.0.50Isolated exploitation target
NORTHSTAR-LABoffline fixtureSynthetic wireless capture and Kismet database

Download the scope fixture before beginning. The synthetic evidence pack supports browser-only delivery when live lab infrastructure is unavailable.

Standard workflow

Every lab follows the same control cycle:

  1. Authorise — confirm target, identity, time window, traffic limits and prohibited techniques.
  2. Baseline — record tool version, system time, DNS resolution and target reachability.
  3. Configure — save the exact profile, command or project settings.
  4. Execute — run the least intrusive technique capable of answering the question.
  5. Correlate — compare at least two evidence sources before declaring a finding.
  6. Report — document impact, confidence, evidence, remediation and retest criteria.
  7. Clean up — stop scans, close sessions, remove test data and reset vulnerable targets.

Prohibited actions

  • internet-wide, customer or production scanning;
  • credential stuffing, password spraying or uncontrolled brute force;
  • wireless deauthentication against real networks;
  • persistence, payload obfuscation, lateral movement or data exfiltration;
  • denial-of-service, destructive modules or unrestricted scanner concurrency;
  • publishing target details, credentials, captures or exploit evidence outside the lab record.