Live range methodology Australian cyber security training

Build the lab.
Break assumptions.
Defend what matters.

Hacktivity1 trains you inside an enterprise-style cyber range you build and understand. From the bare-metal hypervisor to identity, endpoints and the SIEM, every lesson ends in work you can repeat.

Type-1Hypervisor foundation
4Career-aligned pathways
1:1Or small group guidance
End to endBuild, attack, detect, respond

The capability gap

A certificate can confirm what you know. It cannot configure the firewall for you.

Cyber security theory matters. It gives language to the work and explains why controls exist. But theory without repeated practice leaves a dangerous gap between recognising the right answer and producing it under pressure.

Hacktivity1 closes that gap by moving from explanation to configuration, observation, attack simulation, investigation and evidence-led response.

Two very different outcomes

Watching the work is not the same as doing it.

We keep the theory you need, then make the environment answer back. If a control fails, you troubleshoot it. If an alert fires, you follow the evidence. If the evidence is weak, you improve the visibility.

Traditional training

The learner remembers the slide, then meets a system they have never touched.

  • Terminology without operational context
  • Prebuilt labs that hide the infrastructure
  • Tool demonstrations without integration
  • Confidence that disappears when the scenario changes
The Hacktivity1 approach

The learner builds the context, operates the tools and explains the decision.

  • An enterprise-style range built from the hardware up
  • Identity, endpoints, applications and logs connected
  • Attack and defence practised in the same environment
  • Work that can be demonstrated, explained and repeated

Our practical path

From key theory to career-ready evidence

  1. 01LearnUnderstand the key theory
  2. 02BuildAssemble the lab environment
  3. 03BreakRun controlled attack scenarios
  4. 04DetectCollect and analyse the evidence
  5. 05RespondContain, remediate and improve
  6. 06SucceedExplain and repeat the work
Cyber security operations, offensive security training and governance work represented across three connected environments
Defend Test Lead and govern

Four role-aligned pathways

Train for the work you want to be trusted with.

Cyber security is not one job. Each pathway develops a different kind of judgement while using the same connected environment to show how technical and business decisions affect one another.

01 Blue Team

Defensive Security

Learn how defenders collect telemetry, investigate alerts, validate incidents and improve controls across endpoints, identity, network and cloud-connected services.

  • SOC Analyst
  • Cyber Security Analyst
  • Security Monitoring Analyst
  • Incident Responder
  • Threat Hunter
Explore this pathway
02 Red Team

Offensive Security

Work through authorised reconnaissance, vulnerability discovery, exploitation and lateral movement inside a contained range, then trace the evidence each action leaves behind.

  • Penetration Tester
  • Red Team Operator
  • Ethical Hacker
  • Adversary Emulation Specialist
  • Purple Team Analyst
Explore this pathway
03 Leadership

Security Management

Develop the operational and leadership judgement needed to manage security teams, programmes, incidents, stakeholders and risk-informed decisions.

  • Cyber Security Manager
  • Security Operations Manager
  • Information Security Manager
  • Cyber Security Program Manager
  • Security Project Manager
Explore this pathway
04 GRC

Governance, Risk & Compliance

Learn how governance, risk and compliance work becomes stronger when policies, access reviews, audit logs, incidents and technical evidence are understood together.

  • GRC Analyst
  • Cyber Risk Analyst
  • Compliance Analyst
  • Information Security Auditor
  • ISMS Coordinator
Explore this pathway

The connected cyber range

One environment. Every relationship visible.

A firewall on its own is a configuration exercise. Connect it to segmented networks, Active Directory, identity provisioning, endpoints, applications and centralised logging, and it becomes part of an enterprise story.

That story is where meaningful learning begins. You see which system produced the event, how the control changed the outcome, what the analyst can prove and what the business needs to know.

Inspect the complete range
Hacktivity1 connected cyber range showing management, user, identity and security operations networks
Field plate 01 The connected range Infrastructure, identity, security operations, attack simulation and response shown as one working system.

Identity becomes evidence

Follow a person from HR record to security signal.

The new architecture view makes the identity and telemetry chain explicit. HR data initiates provisioning. IAM and RBAC shape access. Active Directory connects users to endpoints and services. Defender, privileged access and packet activity then produce evidence for Splunk to correlate.

Identity and telemetry flow from HR management through IAM, Active Directory and endpoints into Splunk SIEM
Identity lifecycle and telemetry Provision. Enforce. Observe. Correlate.
01SourceHR records establish the person and employment context.
02ProvisionIAM and RBAC translate role into approved access.
03EnforceActive Directory, endpoints and services apply the controls.
04ObserveSecurity tools and Splunk turn activity into evidence.

The practical range fieldbook

Three chapters. Shown at the scale they deserve.

These are the actual architecture views behind the practical training model. They are presented directly on the page, uncropped and without hiding detail behind a lightbox.

PLATE 01

Build the enterprise

Core lab infrastructure

Start with controlled access, a real firewall and a type-1 hypervisor. Add segmented networks, Windows domain services, endpoints and the applications that give the environment believable activity.

Core cyber range infrastructure with firewall, VMware ESXi, Windows Server and user applications
PLATE 02

Make it observable

Identity, monitoring and security analytics

Connect the people systems to access controls, privileged administration, endpoint telemetry, vulnerability discovery, packet analysis, audit logs and a central security operations view.

Identity, monitoring and security analytics architecture with IAM, SIEM, EDR and audit logs
PLATE 03

Put it under pressure

Attack simulation, detection and response

Run authorised adversary activity, examine what the tools can see, validate the alert and continue through containment, eradication, recovery and lessons learned.

Cyber security training workflow connecting attack simulation, monitoring and incident response

The engineering appendix

When the simplified view is no longer enough.

The reference plates expose the denser relationships behind provisioning, authentication, role-based access, SSH keys, applications, virtual machines and centralised audit data.

Detailed virtual machine, identity and service topology for the Hacktivity1 cyber range
Reference 01Complete system topologyCloud identity, virtual machines, directory services, business applications and audit flows.
Detailed sequence flow showing provisioning, authentication, access and log movement
Reference 02Provisioning and access sequenceInfrastructure initialisation, LDAPS, SSO, MFA, SSH key management, access review and logging.
Installing memory into compact homelab hardware before configuring the cyber security range
Workshop record 00 / Preparing the physical host

Before the first virtual machine

The practical work begins with the machine beneath the lab.

Where the learning path calls for it, we begin with compatible hardware, memory, storage and networking. From there, VMware ESXi is installed directly on the host and the virtual environment is built with an understanding of the physical constraints underneath it.

HostPrepared and validated
HypervisorVMware ESXi, type 1
GatewaypfSense or OPNsense
OutcomeA range you can explain
See how the range is assembled

What you assemble

The range starts before the operating system.

You learn how the environment fits together because you participate in building it. Each layer becomes the foundation for the next, and every later alert can be traced back through that architecture.

  1. 01

    Hardware and ESXi

    Prepare suitable hardware, expand memory where required and install VMware ESXi as a type-1 hypervisor.

  2. 02

    Firewall and segmentation

    Configure pfSense or OPNsense, VLANs, routing, DNS, DHCP, VPN access and traffic controls.

  3. 03

    Domain and identity

    Build Windows Server Active Directory, join endpoints and connect HR-driven provisioning, IAM, RBAC, SSO and MFA.

  4. 04

    Telemetry and security analytics

    Forward Windows, Defender, firewall, Linux and application events into Splunk, Wazuh or Security Onion for analysis.

  5. 05

    Attack and response

    Use Kali Linux, Nmap and Wireshark in controlled scenarios, investigate the resulting evidence and complete the response cycle.

Hacktivity1 instructor guiding learners through a practical cyber security exercise

Guided, not spoon-fed

Small enough to catch the moment your reasoning goes off course.

One-to-one and small group sessions give you room to ask why, test an assumption and troubleshoot properly. The instructor can see how you approach the problem, not only whether you reached the expected screen.

Build itUnderstand every dependency because you configured it.
Explain itTurn commands and alerts into a clear technical narrative.
Repeat itPractise until the process survives a different scenario.
Read about our teaching approach

Your next move

Do not start with a course title. Start with the work you want to do.

Tell us the role you are moving toward, the experience you already have and the practical areas where you need confidence. We will help you identify a sensible path.

Discuss your training path