Skip to main content
Labshock
LoginStart Free

Labshock — How It Works

It Runs On
Your Hardware.

Labshock is not a hosted service and not a website you log into to watch something. It is software you install on a machine you own, which brings up real industrial systems on an isolated network — and then stays there. No cloud, no shared infrastructure, and no connection required to operate.

100%
on-premise
isolated installation on hardware you own
0
data leaves
nothing is shipped anywhere for processing or analytics
0
internet required
labs operate with no outbound connection once installed
1
machine to start
a laptop running Docker is enough for the free tier

From install to running lab

Six steps, all of them local

01

Install on your own machine

Labshock installs on hardware you own — a laptop, a workstation or your own servers. That is the same on every plan: an Organization license runs on a laptop exactly as Free does, and what a license changes is who may use it and what for, not where it can run. There is no Labshock-hosted component your labs depend on, and no account on somebody else's infrastructure holding your environments.

A laptop is enough to startLinux, macOS or Windows via DockerSame install on every plan
02

Start an environment

A lab is not a video or a sandboxed web app. It is a set of containers that come up together on an isolated virtual network — a PLC runtime executing real logic, a SCADA server serving a real mimic, a router enforcing segmentation, an IDS watching the wire, a collector shipping events. Portal brings the whole topology up and is where you operate it.

One command, or one click in PortalEach service is its own containerIT, DMZ and OT segments with real routing
03

Operate the process

You interact with the systems the way an engineer would. Write a coil and a pump starts. Send a breaker command and the state changes. Move a setpoint and the process follows. The traffic this produces is a genuine protocol implementation from logic that is actually executing, not a replayed capture.

Real Modbus, S7comm, DNP3 and IEC 104 on the wireLogic executing, not replayedProcess state responds to what you send
04

Watch your detection

Point your own IDS at the traffic and your own SIEM at the events. Because you caused the activity, you know exactly what should have been seen — which makes this the one place a detection rule can be proven rather than assumed. Surge Router mirrors the raw traffic out; Tidal Collector streams the events.

Mirror traffic to your own toolingZeek, Suricata and Wazuh run insideStream OT events to any external SIEM
05

Break it without consequence

The environment is yours and isolated, so there is nothing you are not allowed to do to it. Push the process past its limits, cut the segment, change the logic under a running plant — and watch what the operator sees and what the monitoring reports. No production system is anywhere near it.

No production system anywhere near itFailure modes you cannot rehearse elsewhereWatch process impact and alerting together
06

Reset, or hand it over

When you have finished, reset the lab and it returns to a known state — the same conditions for the next run, or the next student. Export it in the Portable Lab Format and a colleague can bring up the identical environment on their own machine, or you can archive it for a repeatable exercise.

Deterministic rebuild every timeExport and share the whole environmentSame conditions for every cohort

What a lab actually is

Containers on an isolated network

When a lab starts, Portal brings up each service as its own container and wires them into segments that behave like a real industrial network — an OT segment with the controllers, a DMZ where it exists, and routing between them that you can actually test.

That is why the traffic is worth analysing. A SCADA write leaves one container, crosses a segment, and arrives at a controller that acts on it. Nothing about that path is mocked, so an IDS watching it sees what it would see in a plant.

Your machine

PLC / RTU
SCADA
Eng. workstation
Router
IDS
Collector
Isolated virtual network
no outbound route required

An Organization license deploys the same thing onto your own servers.

The questions security teams ask first

Where it runs, and what leaves

Does it need an internet connection to run?

No. Once installed, a lab operates with no outbound connection. That matters because the networks worth practising on are frequently the ones with no route out, and a training environment that cannot run in those conditions cannot be used where it is most needed. License tokens are cryptographically signed and validate offline.

Where does my data go?

Nowhere. Process data, packet captures, telemetry, logs and user activity stay on your infrastructure. Nothing is shipped elsewhere for processing, analytics or telemetry. There is no Labshock-side copy of what your team did in a lab.

Is my environment shared with anyone else?

No. Every installation is single-tenant by construction — the containers run on your hardware, on your network. An Organization license is a dedicated deployment under your control, which is what makes it usable inside an OT estate at all.

What about the industrial systems — are they simulated?

The control systems are real software. PLC runtimes execute programs you write, SCADA reads and writes real tags, and the protocol traffic on the wire is a genuine protocol implementation rather than a replayed capture. What is simulated is the physical process the controllers are driving — the pump, the breaker, the boiler.

Can I connect my own security tools?

Yes, and that is a large part of the point. Surge Router mirrors raw industrial traffic to any external IDS or hardware appliance, and Tidal Collector streams OT events into any external SIEM. Your production tooling can sit beside the lab and be tested against it.

Install it and break something.

The free tier runs locally under Docker. No card, and nothing to send us.