Network Discovery Lab
Deploy the Breakwater IoT simulation environment and run ARP cache harvesting, fping sweeps, mDNS/SSDP discovery, and TCP connect probing against 22 simulated IoT devices.
Twelve hands-on labs, one per pipeline phase. Individual student ZIP packages are available below. Labs use the Breakwater IoT simulation environment — 22 simulated devices, Docker Compose, no physical hardware required.
Deploy the Breakwater IoT simulation environment and run ARP cache harvesting, fping sweeps, mDNS/SSDP discovery, and TCP connect probing against 22 simulated IoT devices.
Run concurrent multi-protocol enrichment against the IoT simulation: nmap service detection, HTTP banner scraping, TLS certificate inspection, ONVIF device info, and JARM fingerprinting.
Use the CPE records from Phase 2 to query the NVD API and OpenVAS, score CVEs, and produce an annotated vulnerability report with evidence chains.
Build a NetworkX attack graph from the scan and vulnerability data, compute Breakwater Risk Scores, map to MITRE ATT&CK, and export a STIX bundle.
Operate the autonomous testing workflow with bounded policies, evidence capture, and explicit safety gates for simulated IoT services.
Use the simulated environment as a digital twin for safe remediation planning, rollback reasoning, and what-if analysis.
Inventory cryptographic exposure and reason about post-quantum migration readiness across the lab fleet.
Work with federated intelligence concepts, shared indicators, local evidence, and privacy-preserving aggregation boundaries.
Analyze software and device supply-chain evidence, SBOM records, provenance claims, and counterfeit-detection signals.
Study deception placement, telemetry capture, engagement evidence, and active-defense trade-offs in the lab network.
Connect observed protocol behavior to formal verification claims, counterexamples, and proof-backed security properties.
Evaluate autonomous remediation decisions against safety gates, approval boundaries, rollback paths, and audit evidence.