Authorized Lab Acceptance Checklist
Complete this before any offensive, malware-adjacent, cloud, mobile, or OT exercise.
- I own the environment or have written, current authorization.
- In-scope and out-of-scope assets are recorded.
- The network path cannot reach unintended systems.
- Test credentials and synthetic data are in use.
- Snapshots, reset, teardown, and cloud-budget controls work.
- Logs and evidence storage are enabled.
- Time synchronization and timezone are recorded.
- Stop conditions and emergency contacts are known.
- The exercise avoids persistence, stealth, credential theft, destructive behavior, and third-party impact.
- Malware-like samples are inert, benign, or handled in a purpose-built isolated sandbox.
- Publication and disclosure rules are understood.
If any item is false, do not start the exercise.