REFERENCE ARCHITECTURE

Built to isolate behavior.
Designed to explain the evidence.

M3HT4 separates orchestration, scenario compute, telemetry, and presentation into purpose-built layers. The result is a controlled environment for authorized emulation, detection engineering, investigation, and collaborative training.

Segmented Observable Disposable Review-first
SYSTEM VIEW

The M3HT4 reference environment.

This is a deliberately public-safe view. Addressing, credentials, management endpoints, switch ports, firewall rules, and other operational security details are intentionally omitted.

Public architecture view
Open full resolution ↗
Public-safe M3HT4 technical architecture diagram
Architecture, not reconnaissance.

The diagram communicates design intent and technology roles without publishing the information needed to administer or target the underlying environment.

CORE SYSTEMS

Four roles. One operating model.

Each system has a focused responsibility. Together they form the control, compute, detection, and presentation planes of M3HT4.

Operational

Control Node

Controller & orchestration node

Provides the persistent management plane for orchestration, infrastructure visibility, controller services, monitoring, and future automation.

  • Infrastructure management
  • Automation & orchestration
  • Monitoring & telemetry
  • Controller services
  • Centralized logging (planned)
Operational

Virtualization Host

Proxmox VE / scenario compute

Runs persistent infrastructure workloads and will host disposable M3HT4 scenario environments separated from the public-facing platform.

  • Proxmox virtualization
  • Reusable VM templates
  • Disposable scenario workloads
  • Snapshot / recovery workflows
  • Isolated scenario networks (planned)
Deployment next

Detection Sensor

Monitoring & detection node

The dedicated detection plane for network telemetry, packet analysis, event collection, and future Security Onion-backed workflows.

  • Network traffic analysis
  • Zeek telemetry
  • Suricata detections
  • Elastic-backed investigation
  • Detection engineering
Operational

Status Display

Dashboard & status node

A dedicated display appliance for infrastructure health, scenario status, alerts, and real-time operational visibility.

  • Infrastructure health
  • Service availability
  • Scenario status
  • Detection visibility
  • Kiosk dashboard presentation
WORKFLOW

From controlled activity to reusable learning.

The infrastructure exists to support a repeatable evidence lifecycle, not simply to host virtual machines.

01

Define

A scenario begins with an objective, expected behavior, resource limits, telemetry goals, and explicit authorization.

02

Provision

Disposable workloads are created inside bounded scenario infrastructure rather than on persistent production systems.

03

Emulate

Authorized behavior is executed within the scenario boundary to create representative security evidence.

04

Observe

Telemetry is collected through the monitoring and detection plane for investigation and validation.

05

Improve

Red, Blue, and Purple perspectives convert evidence into detections, lessons, and repeatable training material.

06

Publish

Only sanitized, intentionally selected outputs cross the boundary into the public M3HT4 experience.

SECURITY MODEL

Safe by architecture, not by assumption.

The public platform and the private lab are intentionally treated as separate trust zones.

+

Separation of duties

Control, compute, detection, and presentation are treated as distinct roles so a single service does not become the entire platform.

+

Fail-closed scenarios

Scenario environments are designed around isolation first, with no assumption that an emulation workload requires public Internet access.

+

Telemetry by design

M3HT4 is built around the evidence produced by behavior—not around screenshots of individual security tools.

+

Public/private boundary

Raw evidence remains private. Public material is normalized, reviewed, and sanitized before publication.

BUILD STATUS

Built incrementally.

The reference architecture shows both operating infrastructure and the direction of the platform. Planned capabilities are labeled rather than presented as finished.

Network security & segmentation
Operational
Control Node
Operational
Proxmox virtualization
Operational
Status Display
Operational
Detection Sensor
Deployment next
Isolated scenario workflow
Planned
Interactive emulation replay
Roadmap
MODERN HUNTING TERRAIN

One terrain. Three teams. Four pillars.

Hunt the behavior. Detect what matters. Emulate safely. Turn the evidence into training.

Explore M3HT4 →
M3HT4 MODERN HUNTING TERRAIN
INDEPENDENT PROJECT SUPPORT

Keep the terrain
moving.

Voluntary support helps fund the infrastructure, research, tooling, and public learning experiences behind M3HT4.

Research Tools Infrastructure

Support never buys access. It does not purchase influence, services, testing authorization, priority, or private M3HT4 material.

SUPPORT M3HT4

Choose what feels right.

Ko-fi checkout
Opening secure support panel Loading Ko-fi only after you choose Support.

Checkout is provided by Ko-fi and its payment partners. M3HT4 does not collect payment-card details through this website.