> For the complete documentation index, see [llms.txt](https://ajmal-anwar.gitbook.io/zyberspace-by-ajmal/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajmal-anwar.gitbook.io/zyberspace-by-ajmal/zyberlab/00-start-here/how-to-use-zyberlab.md).

# How to Use ZyberLab

ZyberLab is designed to be followed gradually. There is no need to build every system or install every security tool at the beginning.

## Recommended Approach

For each topic:

1. Read the objective.
2. Check the required virtual machines or tools.
3. Take a VM snapshot when appropriate.
4. Follow the lab steps carefully.
5. Verify the expected result.
6. Review the logs, events, or system behavior produced by the activity.
7. Record troubleshooting notes and lessons learned.
8. Restore or clean up changes when required.

## One Concept at a Time

A lab should focus on one main learning objective wherever possible.

For example, a failed-login lab should first concentrate on generating and identifying failed authentication events. Additional detection platforms or automation can be introduced later after the basic Windows behavior is understood.

This keeps the learning path clear and prevents unnecessary complexity.

## Lab Page Format

Most hands-on labs will follow a consistent structure:

### Objective

What the lab is intended to demonstrate.

### What You Will Learn

The concepts or skills covered.

### Lab Environment

The systems and virtual machines used.

### Requirements

Anything that should already be installed or configured.

### Steps

The practical procedure.

### Verify

How to confirm that the activity worked as expected.

### What Happened?

A simple explanation of what the operating system, application, or security control actually did.

### Security Relevance

Why the activity matters from a cybersecurity perspective.

### Clean Up

Any changes that should be reversed after testing.

### Key Takeaways

A short summary of the important points.

## Build Only What You Need

The environment will grow only when a new lab requires additional components.

The initial focus is Windows, Active Directory, networking, logs, and basic security monitoring. More advanced platforms can be added later when there is a clear learning purpose.

## Documentation Standard

Screenshots, commands, IP addresses, usernames, and examples should be safe for public documentation. Real organizational information, credentials, sensitive logs, production addresses, customer information, or confidential architecture should never be published.
