Articles/Security
Security27 May 2026

Building a cyber range your students cannot accidentally escape

A good security lab lets students attack real machines and make a mess, while being certain that mess never reaches the real world.


The fastest way to teach offensive and defensive security is to let students do it for real: scan a host, find the open port, exploit the weak service, then come back as the defender and shut it down. The catch is obvious. You cannot point a class full of Kali machines at the open internet and hope for the best.

A whole network inside one machine

Instead of handing out a rack of VMs you have to wire together, StudentLabs gives each student a single machine that can run an entire network inside itself. An attacker box, a target or two, a little switch between them, all nested on the one lab machine and isolated from everything else.

That gives every student their own private range where they can:

  • Run a full attack chain from recon to exploitation to cleanup.
  • Break a target spectacularly and simply rebuild it from the template.
  • Practise defence on the same network they just attacked.

Isolated by default

Each student's range is its own sandbox. One student cannot wander into another's machines, and nothing inside the range can reach your production network or the wider internet unless you deliberately allow it. When a student does something they should not, the blast radius is their own lab and nothing more.

It also runs in your own Azure, in the region you choose, so the traffic and the data stay inside boundaries your institution already controls. For a security course, that containment is not a luxury; it is the whole point.

More from the blog

All articles →

Give every student their own machine.

Set up your first class in minutes and see it running before your next lesson.

Book a demo