Labshock — How It Works
It Runs On
Your Hardware.
Labshock is not a hosted service and not a website you log into to watch something. It is software you install on a machine you own, which brings up real industrial systems on an isolated network — and then stays there. No cloud, no shared infrastructure, and no connection required to operate.
From install to running lab
Six steps, all of them local
Install on your own machine
Labshock installs on hardware you own — a laptop, a workstation or your own servers. That is the same on every plan: an Organization license runs on a laptop exactly as Free does, and what a license changes is who may use it and what for, not where it can run. There is no Labshock-hosted component your labs depend on, and no account on somebody else's infrastructure holding your environments.
Start an environment
A lab is not a video or a sandboxed web app. It is a set of containers that come up together on an isolated virtual network — a PLC runtime executing real logic, a SCADA server serving a real mimic, a router enforcing segmentation, an IDS watching the wire, a collector shipping events. Portal brings the whole topology up and is where you operate it.
Operate the process
You interact with the systems the way an engineer would. Write a coil and a pump starts. Send a breaker command and the state changes. Move a setpoint and the process follows. The traffic this produces is a genuine protocol implementation from logic that is actually executing, not a replayed capture.
Watch your detection
Point your own IDS at the traffic and your own SIEM at the events. Because you caused the activity, you know exactly what should have been seen — which makes this the one place a detection rule can be proven rather than assumed. Surge Router mirrors the raw traffic out; Tidal Collector streams the events.
Break it without consequence
The environment is yours and isolated, so there is nothing you are not allowed to do to it. Push the process past its limits, cut the segment, change the logic under a running plant — and watch what the operator sees and what the monitoring reports. No production system is anywhere near it.
Reset, or hand it over
When you have finished, reset the lab and it returns to a known state — the same conditions for the next run, or the next student. Export it in the Portable Lab Format and a colleague can bring up the identical environment on their own machine, or you can archive it for a repeatable exercise.
What a lab actually is
Containers on an isolated network
When a lab starts, Portal brings up each service as its own container and wires them into segments that behave like a real industrial network — an OT segment with the controllers, a DMZ where it exists, and routing between them that you can actually test.
That is why the traffic is worth analysing. A SCADA write leaves one container, crosses a segment, and arrives at a controller that acts on it. Nothing about that path is mocked, so an IDS watching it sees what it would see in a plant.
Your machine
An Organization license deploys the same thing onto your own servers.
The questions security teams ask first
Where it runs, and what leaves
Does it need an internet connection to run?
No. Once installed, a lab operates with no outbound connection. That matters because the networks worth practising on are frequently the ones with no route out, and a training environment that cannot run in those conditions cannot be used where it is most needed. License tokens are cryptographically signed and validate offline.
Where does my data go?
Nowhere. Process data, packet captures, telemetry, logs and user activity stay on your infrastructure. Nothing is shipped elsewhere for processing, analytics or telemetry. There is no Labshock-side copy of what your team did in a lab.
Is my environment shared with anyone else?
No. Every installation is single-tenant by construction — the containers run on your hardware, on your network. An Organization license is a dedicated deployment under your control, which is what makes it usable inside an OT estate at all.
What about the industrial systems — are they simulated?
The control systems are real software. PLC runtimes execute programs you write, SCADA reads and writes real tags, and the protocol traffic on the wire is a genuine protocol implementation rather than a replayed capture. What is simulated is the physical process the controllers are driving — the pump, the breaker, the boiler.
Can I connect my own security tools?
Yes, and that is a large part of the point. Surge Router mirrors raw industrial traffic to any external IDS or hardware appliance, and Tidal Collector streams OT events into any external SIEM. Your production tooling can sit beside the lab and be tested against it.
Install it and break something.
The free tier runs locally under Docker. No card, and nothing to send us.
