The commands for every lab in the book, ready to copy and run rather than retype. The book prints these same commands; what lives only there is the reasoning behind them and the judgment each one is teaching.
Nothing here touches live infrastructure. You build the networks, you build the services, and you break them yourself, inside a synthetic range that ships with the labs.
How this site works
This is the command half of the book. Each page carries the exact things you type, under the same lab number the book uses, so Lab 3.1 here is Lab 3.1 there. What each step does and why it is built that way is written up in the book.
Five items are not here: Labs 11.8, 12.8, 12.9 and 14.8, and Chapter 15. Those run against real archived data or chain every engine into a final report, and they are covered in the book with their commands.
Stand up the container lab and prove what it can and can't reach.
All labs by chapter, with tier, platform, and memory requirements.
All 109 labs with hours to budget, at entry and intermediate level.
Chapters
Workstation tier · can you touch hidden services without exposing yourself?
WS · 4G
.onion query is worse than a DNS leak.WS · 4G
Workstation tier · understand hidden services by building, breaking, and hardening them
WS · 4G
WS · 4G
WS · 8G
WS · 8G
WS · 8G
Infrastructure tier · onion services are ephemeral; if you aren't watching, you miss it
INF · 8G
INF · 8G
INF · 8G
INF · 8G
Infrastructure tier · turn collection into an intelligence product
INF · 16G
INF · 8G
INF · 8G
INF · 16G
Optional setup, kept out of the labs
reference
./lab command with a one-line description and a copy-ready example, plus a spreadsheet download.Where to run it
Docker Desktop on Windows or macOS, Docker Engine on Linux. Comfortable through Parts I and II.
Always-on Linux. Recommended from Part III, where collection runs continuously and outages are the thing you're measuring.
lab doctorReports your platform, memory, and architecture, then tells you which labs run natively and which want the VPS.
Lab times
Every lab in the book with a time to budget for it, so you can plan a session, a week, or a term. Two columns, because the same lab is not the same work for everyone: read the one that describes you and ignore the other.
./lab and the containers.| Lab | Title | Intermediate | Entry | Where |
|---|---|---|---|---|
| Chapter 1 · The Container Lab · 6 labs · 4–6 h | ||||
| 1.0 | Clone the lab repository | 0.5 h | 0.5 h | Host (Docker) |
| 1.1 | First light | 1 h | 1.5 h | Workstation + host |
| 1.2 | Anatomy of the stack | 0.5 h | 1 h | Host (Docker) |
| 1.3 | The gateway route | 1 h | 1 h | Workstation + host |
| 1.4 | Reset discipline | 0.5 h | 1 h | Host (Docker) |
| 1.5 | Image provenance | 0.5 h | 1 h | Host (Docker) |
| Chapter 2 · Verified Access · 7 labs · 5.5–6.5 h | ||||
| 2.1 | The four leak surfaces | 0.5 h | 0.5 h | Workstation + host |
| 2.2 | Watch what actually leaves | 1 h | 1 h | Host (Docker) |
| 2.3 | The browser is a fingerprint | 0.5 h | 1 h | Host (Docker) |
| 2.4 | Behavioural vs structural: proxychains vs the gateway | 1 h | 1 h | Workstation + host |
| 2.5 | Reaching and hosting onion services | 1 h | 1 h | Host (Docker) |
| 2.6 | Keyed onions and their friction | 1 h | 1 h | Host (Docker) |
| 2.7 | When the gateway says no | 0.5 h | 1 h | Workstation + host |
| Chapter 3 · Tor From the Inside · 7 labs · 6–7.5 h | ||||
| 3.1 | The control port as an instrument | 0.5 h | 1 h | Workstation + host |
| 3.2 | The consensus: Tor's shared map | 1 h | 1 h | Workstation + host |
| 3.3 | Guards: your fixed door into the network | 1 h | 1 h | Workstation + host |
| 3.4 | Building a circuit: three hops, layered encryption | 1 h | 1.5 h | Workstation + host |
| 3.5 | Streams: how a connection rides a circuit | 1 h | 1 h | Workstation + host |
| 3.6 | Rendezvous, from the outside in | 1 h | 1 h | Workstation + host |
| 3.7 | New identity and circuit hygiene | 0.5 h | 1 h | Workstation + host |
| Chapter 4 · Onion Services v3 · 7 labs · 6.5–8 h | ||||
| 4.1 | Anatomy of a v3 address | 0.5 h | 1 h | Workstation + host |
| 4.2 | Publish a service the real way | 1 h | 1 h | Workstation + host |
| 4.3 | The descriptor and the hash ring | 1 h | 1 h | Workstation + host |
| 4.4 | Client authorization, properly | 1 h | 1.5 h | Workstation + host |
| 4.5 | Vanity addresses and what they cost | 1 h | 1 h | Workstation + host |
| 4.6 | How onion services get found | 1 h | 1.5 h | Workstation + host |
| 4.7 | Hardening a service you run | 1 h | 1 h | Workstation + host |
| Chapter 5 · Breaking & Hardening · 7 labs · 6.5–8 h | ||||
| 5.1 | The adversary model | 0.5 h | 1 h | Host (Docker) |
| 5.2 | Correlation, at toy scale | 1 h | 1.5 h | Host (Docker) |
| 5.3 | Malicious and colluding relays | 1 h | 1 h | Workstation + host |
| 5.4 | Guard discovery and traffic-shaping | 1 h | 1 h | Workstation + host |
| 5.5 | Application-layer deanonymization | 1 h | 1.5 h | Workstation + host |
| 5.6 | Hardening pass: hunt your own leaks | 1 h | 1 h | Workstation + host |
| 5.7 | A threat model that has weights | 1 h | 1 h | Host (Docker) |
| Chapter 6 · Beyond Tor: I2P · 7 labs · 6.5–7.5 h | ||||
| 6.1 | An I2P router in the lab | 1 h | 1 h | Host (Docker) |
| 6.2 | The NetDB and floodfill | 1 h | 1.5 h | Host (Docker) |
| 6.3 | Tunnels, unidirectional | 1 h | 1 h | Host (Docker) |
| 6.4 | Eepsites: access and host | 1 h | 1 h | Host (Docker) |
| 6.5 | I2P's threat model vs Tor's | 1 h | 1 h | Host (Docker) |
| 6.6 | Both networks, side by side | 0.5 h | 1 h | Host (Docker) |
| 6.7 | A comparison you can defend | 1 h | 1 h | Host (Docker) |
| Chapter 7 · Hyphanet · 7 labs · 7–8 h | ||||
| 7.1 | A node in a friend mesh | 1 h | 1.5 h | Host (Docker) |
| 7.2 | Insert, retrieve, and outlive the publisher | 1 h | 1.5 h | Host (Docker) |
| 7.3 | Mutable content: SSK, USK, freesites | 1 h | 1 h | Host (Docker) |
| 7.4 | Opennet vs darknet | 1 h | 1 h | Host (Docker) |
| 7.5 | Deniability and the datastore | 1 h | 1 h | Host (Docker) |
| 7.6 | Threat model vs Tor and I2P | 1 h | 1 h | Host (Docker) |
| 7.7 | The complete overlay decision | 1 h | 1 h | Host (Docker) |
| Chapter 8 · The Simulated Darknet · 7 labs · 6.5–7 h | ||||
| 8.1 | Why simulate, and the tier shift | 1 h | 1 h | Host (Docker) |
| 8.2 | A directory and the seed problem | 0.5 h | 1 h | Host (Docker) |
| 8.3 | A market and a forum: services have state | 1 h | 1 h | Host (Docker) |
| 8.4 | A leak site: persistence and flicker | 1 h | 1 h | Host (Docker) |
| 8.5 | Mirrors, clones, and phishing | 1 h | 1 h | Host (Docker) |
| 8.6 | Cross-network links | 1 h | 1 h | Host (Docker) |
| 8.7 | Ground truth and the scoring harness | 1 h | 1 h | Host (Docker) |
| Chapter 9 · Crawling Hidden Services · 7 labs · 4.5–7 h | ||||
| 9.1 | The frontier: crawling without an index | 1 h | 1 h | Host (Docker) |
| 9.2 | Fetching through Tor: slow, unreliable, and you must be polite | 0.5 h | 1 h | Host (Docker) |
| 9.3 | Parsing and link extraction across networks | 0.5 h | 1 h | Host (Docker) |
| 9.4 | Sessions and state: getting past the wall | 0.5 h | 1 h | Host (Docker) |
| 9.5 | Continuous collection: revisiting a moving target | 0.5 h | 1 h | Host (Docker) |
| 9.6 | Storage, provenance, and dedup | 0.5 h | 1 h | Host (Docker) |
| 9.7 | Scoring the crawler and closing the loop | 1 h | 1 h | Host (Docker) |
| Chapter 10 · Mirrors & Clones · 7 labs · 5–7 h | ||||
| 10.1 | Where exact hashing fails | 0.5 h | 1 h | Host (Docker) |
| 10.2 | Shingling and MinHash: near-duplicates | 0.5 h | 1 h | Host (Docker) |
| 10.3 | Structural fingerprinting | 0.5 h | 1 h | Host (Docker) |
| 10.4 | Identity without keys: secondary signals | 1 h | 1 h | Host (Docker) |
| 10.5 | Clustering: one operator, many addresses | 1 h | 1 h | Host (Docker) |
| 10.6 | Mirror vs clone: redundancy vs impersonation | 0.5 h | 1 h | Host (Docker) |
| 10.7 | Scoring the detector and closing the loop | 1 h | 1 h | Host (Docker) |
| Chapter 11 · Markets & Forums · 8 labs · 4–8 h | ||||
| 11.1 | The market as a database, and a page store | 0.5 h | 1 h | Host (Docker) |
| 11.2 | Structured extraction: pages to records | 0.5 h | 1 h | Host (Docker) |
| 11.3 | Anti-crawling: detect, never defeat | 0.5 h | 1 h | Host (Docker) |
| 11.4 | Sessions at scale, and the shadow-ban | 0.5 h | 1 h | Host (Docker) |
| 11.5 | The vendor and reputation graph | 0.5 h | 1 h | Host (Docker) |
| 11.6 | The data is adversarial | 0.5 h | 1 h | Host (Docker) |
| 11.7 | Scoring extraction, and closing the loop | 0.5 h | 1 h | Host (Docker) |
| 11.8 | Extract a real market slice and graph its vendorsoptional | 0.5 h | 1 h | Host, offline |
| Chapter 12 · Leak Sites & Negotiation · 9 labs · 5.5–8 h | ||||
| 12.1 | The extortion operation as two surfaces | 0.5 h | 1 h | Host (Docker) |
| 12.2 | Leak-site victim extraction | 0.5 h | 0.5 h | Host (Docker) |
| 12.3 | The victim lifecycle over time | 0.5 h | 0.5 h | Host (Docker) |
| 12.4 | Reposted victims and affiliate movement | 0.5 h | 0.5 h | Host (Docker) |
| 12.5 | The negotiation channel | 0.5 h | 1 h | Host (Docker) |
| 12.6 | The bluff is in the gap | 0.5 h | 1 h | Host (Docker) |
| 12.7 | Scoring, operator tells, and the hand-off | 0.5 h | 1 h | Host (Docker) |
| 12.8 | Negotiate live, then analyse your own transcriptoptional | 1.5 h | 1.5 h | Host (Docker) |
| 12.9 | Analyse the real leak-site channeloptional | 0.5 h | 1 h | Host, offline |
| Chapter 13 · Persona Linkage · 7 labs · 3.5–6 h | ||||
| 13.1 | The linkage problem and the identifier ledger | 0.5 h | 1 h | Host (Docker) |
| 13.2 | Hard identifiers and the provenance trap | 0.5 h | 1 h | Host (Docker) |
| 13.3 | Stylometry, a soft signal | 0.5 h | 0.5 h | Host (Docker) |
| 13.4 | Rhythm, handles, and tactic signatures | 0.5 h | 0.5 h | Host (Docker) |
| 13.5 | Fusing the signals into an operator | 0.5 h | 1 h | Host (Docker) |
| 13.6 | The adversarial identity | 0.5 h | 1 h | Host (Docker) |
| 13.7 | Scoring, calibration, and where linkage stops | 0.5 h | 1 h | Host (Docker) |
| Chapter 14 · Detection · 8 labs · 4.5–7.5 h | ||||
| 14.1 | The monitoring shift and the watchlist | 0.5 h | 1 h | Host (Docker) |
| 14.2 | The change feed | 0.5 h | 1 h | Host (Docker) |
| 14.3 | Classifying events | 0.5 h | 1 h | Host (Docker) |
| 14.4 | Scoring and prioritization | 0.5 h | 1 h | Host (Docker) |
| 14.5 | Correlation and dedup | 0.5 h | 0.5 h | Host (Docker) |
| 14.6 | Noise, drift, and the flood | 1 h | 1 h | Host (Docker) |
| 14.7 | Scoring the detector and the watch loop | 0.5 h | 1 h | Host (Docker) |
| 14.8 | Monitor the real leak-site change-feedoptional | 0.5 h | 1 h | Host, offline |
| Chapter 15 · Capstone & Reporting · 8 labs · 4.5–6 h | ||||
| 15.1 | The intelligence product | 0.5 h | 0.5 h | Host (Docker) |
| 15.2 | The evidence chain | 0.5 h | 0.5 h | Host (Docker) |
| 15.3 | Confidence and calibration | 0.5 h | 0.5 h | Host (Docker) |
| 15.4 | Assembling the report | 0.5 h | 1 h | Host (Docker) |
| 15.5 | Analytic integrity and the overclaim trap | 1 h | 1 h | Host (Docker) |
| 15.6 | What would change this | 0.5 h | 1 h | Host (Docker) |
| 15.7 | Scoring the report and the book's close | 0.5 h | 1 h | Host (Docker) |
| 15.8 | A visual intelligence packageoptional | 0.5 h | 0.5 h | Host, offline |
| All 109 labs | 80 h | 108 h | ||
The times cover the keyboard: reading the lab, running it, and reading what came back. They do not cover installing Docker, the host preparation in the Technical Appendix, or reading the chapter away from the machine. Where a first run waits on the wall clock rather than on you, that wait is already in the number: the first image build in Lab 1.1, the I2P router integrating in 6.1, the Hyphanet mesh settling in 7.1.
At entry level the book is 108 hours of lab work, a full three-credit semester of lab time, or a fortnight of evenings for someone working through it alone. At intermediate level it is 80. If you need it shorter, the five optional labs and the deep protocol labs in Chapters 3, 6 and 7 are the ones to cut first; the through-line from Chapter 8 onward is the part that builds into the capstone, and cutting there costs you the argument the book is making.