Sheet 3 — Projects · Rev 2026.08

Cybersecurity Homelab

Proxmox VE · OPNsense · Wazuh SIEM · Docker — 2026 to present

A self-hosted lab built to practice the job, not just study for it: a bare-metal hypervisor behind a segmented firewall, a SIEM whose detections I verify by attacking my own network, and automation agents that work while I don't. Everything below runs in my home right now.

01

Lab Topology

INTERNET OPNSENSE FIREWALL WAN / LAN · DHCP · DEFAULT-DENY PROXMOX VE — BARE-METAL · 6 VMs / CONTAINERS WAZUH SIEM AGENTS · ALERTS · FIM KALI LINUX ATTACK SIMULATION METASPLOITABLE2 VULNERABLE TARGET DVWA WEB-APP TARGET DOCKER · N8N AI AGENTS · AUTOMATION PI-HOLE DNS FILTERING TWINGATE ZERO-TRUST ACCESS OUTBOUND-ONLY TUNNEL — NO INBOUND PORTS EXPOSED
Fig 3.1 Lab topology — as running Scale: NTS
02

By the Numbers

6
VMs & containers
635
Findings triaged by severity
0
Inbound ports exposed
3
Attack classes verified in SIEM
03

Subsystems

SYS-01 — Virtualization

Proxmox VE Hypervisor

Bare-metal Proxmox VE host I built and administer myself — the foundation the whole lab runs on, carrying six virtual machines and containers.

  • Bare-metal install, self-administered
  • 6 VMs / containers across the stack
  • Docker workloads for services & automation
NET-02 — Perimeter & Segmentation

OPNsense Firewall

Dedicated firewall with segmented WAN/LAN interfaces sitting in front of everything. Nothing moves between segments unless a rule explicitly says it can.

  • Segmented WAN / LAN interfaces
  • DHCP services for the lab network
  • Default-deny rule sets
SEC-03 — Detection & Monitoring

Wazuh SIEM

SIEM with endpoint agents deployed across the lab. I don't assume the detections work — I prove it by running controlled attacks from Kali Linux and confirming each alert fires.

  • Verified: SSH brute-force detection
  • Verified: privilege escalation alerts
  • Verified: file integrity monitoring
VUL-04 — Vulnerability Management

OpenVAS Scanning

Scheduled scans against intentionally vulnerable targets — Metasploitable2 and DVWA — producing real findings to practice the triage workflow analysts do daily.

  • 635 findings triaged by severity
  • Targets: Metasploitable2 · DVWA
  • Severity-first prioritization
ACC-05 — Remote Access & DNS

Twingate + Pi-hole

Zero-trust remote access into the lab over an outbound-only tunnel, plus network-wide DNS filtering. The attack surface from the internet's point of view: zero open ports.

  • Twingate zero-trust access
  • Pi-hole DNS filtering, network-wide
  • No inbound ports exposed
AUT-06 — AI & Automation

n8n AI Agents

Self-hosted n8n running in Docker, orchestrating AI agent workflows — including one that hunts job postings on my behalf while the rest of the lab hums along.

  • Self-hosted n8n on Docker
  • AI agent workflows in production
  • Job-hunting agent · runs unattended
04

Also on the Bench

Node — Business

Leon's Laptop Service

The hardware side of the skill set: a repair-and-resell business — sourcing damaged laptops, diagnosing before purchase, and restoring them to full working condition.

Status: operating since 04·2026

About the business → Business site — coming soon
Node — Coursework

AAS Cybersecurity — NOVA

Windows Server & Active Directory, Linux, Network Security, Firewalls & VPNs, Ethical Hacking, and Digital Forensics — Dean's List every semester, graduating December 2026.

Status: completing 12·2026

Full resume →