Practical cyber security training One-to-one and small cohort learning
Live range methodology Australian cyber security training
Build the lab. Break assumptions. Defend what matters.
Hacktivity1 trains you inside an enterprise-style cyber range you build and understand. From the bare-metal hypervisor to identity, endpoints and the SIEM, every lesson ends in work you can repeat.
A certificate can confirm what you know. It cannot configure the firewall for you.
Cyber security theory matters. It gives language to the work and explains why controls exist. But theory without repeated practice leaves a dangerous gap between recognising the right answer and producing it under pressure.
Hacktivity1 closes that gap by moving from explanation to configuration, observation, attack simulation, investigation and evidence-led response.
Two very different outcomes
Watching the work is not the same as doing it.
We keep the theory you need, then make the environment answer back. If a control fails, you troubleshoot it. If an alert fires, you follow the evidence. If the evidence is weak, you improve the visibility.
Traditional training
The learner remembers the slide, then meets a system they have never touched.
Terminology without operational context
Prebuilt labs that hide the infrastructure
Tool demonstrations without integration
Confidence that disappears when the scenario changes
The Hacktivity1 approach
The learner builds the context, operates the tools and explains the decision.
An enterprise-style range built from the hardware up
Identity, endpoints, applications and logs connected
Attack and defence practised in the same environment
Work that can be demonstrated, explained and repeated
Our practical path
From key theory to career-ready evidence
01LearnUnderstand the key theory
02BuildAssemble the lab environment
03BreakRun controlled attack scenarios
04DetectCollect and analyse the evidence
05RespondContain, remediate and improve
06SucceedExplain and repeat the work
DefendTestLead and govern
Four role-aligned pathways
Train for the work you want to be trusted with.
Cyber security is not one job. Each pathway develops a different kind of judgement while using the same connected environment to show how technical and business decisions affect one another.
01Blue Team
Defensive Security
Learn how defenders collect telemetry, investigate alerts, validate incidents and improve controls across endpoints, identity, network and cloud-connected services.
Work through authorised reconnaissance, vulnerability discovery, exploitation and lateral movement inside a contained range, then trace the evidence each action leaves behind.
Learn how governance, risk and compliance work becomes stronger when policies, access reviews, audit logs, incidents and technical evidence are understood together.
A firewall on its own is a configuration exercise. Connect it to segmented networks, Active Directory, identity provisioning, endpoints, applications and centralised logging, and it becomes part of an enterprise story.
That story is where meaningful learning begins. You see which system produced the event, how the control changed the outcome, what the analyst can prove and what the business needs to know.
Field plate 01The connected range
Infrastructure, identity, security operations, attack simulation and response shown as one working system.
Identity becomes evidence
Follow a person from HR record to security signal.
The new architecture view makes the identity and telemetry chain explicit. HR data initiates provisioning. IAM and RBAC shape access. Active Directory connects users to endpoints and services. Defender, privileged access and packet activity then produce evidence for Splunk to correlate.
Identity lifecycle and telemetryProvision. Enforce. Observe. Correlate.
01SourceHR records establish the person and employment context.
02ProvisionIAM and RBAC translate role into approved access.
03EnforceActive Directory, endpoints and services apply the controls.
04ObserveSecurity tools and Splunk turn activity into evidence.
The practical range fieldbook
Three chapters. Shown at the scale they deserve.
These are the actual architecture views behind the practical training model. They are presented directly on the page, uncropped and without hiding detail behind a lightbox.
PLATE 01
Build the enterprise
Core lab infrastructure
Start with controlled access, a real firewall and a type-1 hypervisor. Add segmented networks, Windows domain services, endpoints and the applications that give the environment believable activity.
PLATE 02
Make it observable
Identity, monitoring and security analytics
Connect the people systems to access controls, privileged administration, endpoint telemetry, vulnerability discovery, packet analysis, audit logs and a central security operations view.
PLATE 03
Put it under pressure
Attack simulation, detection and response
Run authorised adversary activity, examine what the tools can see, validate the alert and continue through containment, eradication, recovery and lessons learned.
The engineering appendix
When the simplified view is no longer enough.
The reference plates expose the denser relationships behind provisioning, authentication, role-based access, SSH keys, applications, virtual machines and centralised audit data.
Reference 01Complete system topologyCloud identity, virtual machines, directory services, business applications and audit flows.Reference 02Provisioning and access sequenceInfrastructure initialisation, LDAPS, SSO, MFA, SSH key management, access review and logging.
Workshop record 00 / Preparing the physical host
Before the first virtual machine
The practical work begins with the machine beneath the lab.
Where the learning path calls for it, we begin with compatible hardware, memory, storage and networking. From there, VMware ESXi is installed directly on the host and the virtual environment is built with an understanding of the physical constraints underneath it.
You learn how the environment fits together because you participate in building it. Each layer becomes the foundation for the next, and every later alert can be traced back through that architecture.
01
Hardware and ESXi
Prepare suitable hardware, expand memory where required and install VMware ESXi as a type-1 hypervisor.
02
Firewall and segmentation
Configure pfSense or OPNsense, VLANs, routing, DNS, DHCP, VPN access and traffic controls.
03
Domain and identity
Build Windows Server Active Directory, join endpoints and connect HR-driven provisioning, IAM, RBAC, SSO and MFA.
04
Telemetry and security analytics
Forward Windows, Defender, firewall, Linux and application events into Splunk, Wazuh or Security Onion for analysis.
05
Attack and response
Use Kali Linux, Nmap and Wireshark in controlled scenarios, investigate the resulting evidence and complete the response cycle.
Guided, not spoon-fed
Small enough to catch the moment your reasoning goes off course.
One-to-one and small group sessions give you room to ask why, test an assumption and troubleshoot properly. The instructor can see how you approach the problem, not only whether you reached the expected screen.
Build itUnderstand every dependency because you configured it.
Explain itTurn commands and alerts into a clear technical narrative.
Repeat itPractise until the process survives a different scenario.
Do not start with a course title. Start with the work you want to do.
Tell us the role you are moving toward, the experience you already have and the practical areas where you need confidence. We will help you identify a sensible path.