Authorized Lab Acceptance Checklist

Complete this before any offensive, malware-adjacent, cloud, mobile, or OT exercise.

  • I own the environment or have written, current authorization.
  • In-scope and out-of-scope assets are recorded.
  • The network path cannot reach unintended systems.
  • Test credentials and synthetic data are in use.
  • Snapshots, reset, teardown, and cloud-budget controls work.
  • Logs and evidence storage are enabled.
  • Time synchronization and timezone are recorded.
  • Stop conditions and emergency contacts are known.
  • The exercise avoids persistence, stealth, credential theft, destructive behavior, and third-party impact.
  • Malware-like samples are inert, benign, or handled in a purpose-built isolated sandbox.
  • Publication and disclosure rules are understood.

If any item is false, do not start the exercise.