Web Application / Cybersecurity Training / Interactive Dashboard

NO-ESC AirGap Lab

NO-ESC AirGap Lab is a specialised interactive cybersecurity training and validation dashboard designed for security researchers and network analys...

NO-ESC AirGap Lab

Category: Web Application / Cybersecurity Training / Interactive Dashboard
Platform: Browser-based (HTML, CSS, JavaScript) — Tauri Desktop App
Framework: Vite + TypeScript frontend; Tauri (Rust) desktop shell
Status: Active — Production Ready


Project Overview

NO-ESC AirGap Lab is a specialised interactive cybersecurity training and validation dashboard designed for security researchers and network analysts who operate wireless auditing equipment — particularly devices such as the WiFi Pineapple that transmit radio signals and interact with WiFi clients.

The core problem it solves: when operating these devices, a single misconfiguration can cause test signals to bleed into public airspace or allow test traffic to accidentally bridge onto production networks — creating legal exposure and operational security failures.

NO-ESC AirGap Lab acts as an interactive digital safety officer — a comprehensive training and validation system that ensures a wireless testing setup remains strictly confined inside a physical and logical "sandbox." It walks the analyst through both the physical containment steps (shielded cables, Faraday cages, ferrite chokes) and the software configuration steps (firewall rules, IP subnet isolation, access control lists) to guarantee that nothing leaks out.

The platform is delivered as both a standalone web application and a cross-platform desktop application via Tauri.


Module 1: Physical Leakage and Cable Attenuation

"Cable-as-Antenna" Education

Explains the phenomenon where unshielded USB cables behave as radiating antennas — allowing RF signals to pass through Faraday cage walls via the cable entry points, defeating the entire purpose of the enclosure.

Interactive Hardware Mitigation Checklist

Step-by-step verification of four physical containment layers:

Mitigation Description
Ferrite Chokes Eliminates common-mode high-frequency noise at cable terminations
Double-Shielded Cables Enforces grounded double-braided shielding over standard foil-only lines
RF Data Filters Routes data lines through a low-pass capacitive filter bulkhead connector
Earth Grounding Bonds the host laptop chassis to the laboratory earth ground line

Each item is interactively checked off, and the routing schematic (Module 2) updates dynamically in response.


Module 2: Interactive Lab Routing Schematic

Real-Time SVG Signal Chain Diagram

A live, animated SVG diagram renders the entire signal flow from the analyst's workstation through:

  1. Host workstation
  2. USB cable egress point
  3. Faraday cage wall
  4. Bulkhead RF filter
  5. Internal sandbox (test device)

Dynamic Leak/Secure Indicators

  • When mitigation checklist items are incomplete: the diagram animates red RF leakage waves radiating from the cable entry point, labelled "RF LEAKAGE"
  • When all mitigations are verified: the diagram switches to green containment lines with a "FILTERED SECURE" status badge

LED Pattern Simulator

Emulates the hardware status LED blink patterns of the auditing device:

  • Boot sequence indicator
  • Running / active state
  • Recovery mode
  • Charging state
  • Alert/error state

Teaches analysts how to diagnose hardware state from LED blink codes without external tools.


Module 3: Interactive Lab SOP Checklist (4 Phases)

A comprehensive Standard Operating Procedure walked through in four structured phases:

Phase 1 — Safely Isolated Boot

  • Cold-charging procedure (battery-only, no live USB connection)
  • Tethering configuration via Linux Mint NetworkManager / nmcli commands
  • Admin password and initial device hardening

Phase 2 — Locking Down the PineAP Engine

  • Disabling client association (prevent devices from connecting to test AP)
  • MAC address allow-listing (whitelist-only mode)
  • Reducing radio transmit power to minimum safe operational level

Phase 3 — Payload Safety and Auditing

  • DuckyScript payload review and safety auditing procedures
  • Creating physical hardware Emergency Abort Kill Switches
  • Pre-test checklist verification

Phase 4 — Test Router Isolation (Gold Standard)

  • Setting up an optional air-gapped router gateway
  • Configuring distinct DHCP subnets for the test environment
  • Implementing outbound Access Control Lists (ACLs) to block all production traffic

Module 4: Inter-Subnet Leak and Overlap Calculator

Real-Time IP Auditor

An interactive calculator that takes the analyst's specific IP subnet parameters and performs:

  • Overlap detection: Checks whether the Pineapple test IP range overlaps with the home/production network range — routing overlap creates the primary bridge risk
  • RFC 1918 compliance check: Verifies that all subnets fall within legal private network address space (10.x.x.x, 172.16.x.x, 192.168.x.x)
  • Leakage risk prediction: Alerts if subnet configuration could allow routing to bleed between test and production networks

All calculations are performed dynamically in the browser with no server interaction.


Module 5: Tailored Security Script Generator

Generates deployment-ready scripts customised to the analyst's specific network parameters:

Windows PowerShell

  • Configures Windows Defender Firewall rules
  • Disables LLMNR (Link-Local Multicast Name Resolution) — a common vector for name poisoning attacks
  • Disables NetBIOS over TCP/IP — eliminates legacy discovery protocol leakage

Linux (Bash / iptables)

  • Complete iptables script with strict forwarding blocks
  • INPUT chain filtering for the test interface
  • Localhost loopback mapping
  • sysctl configurations disabling IP forwarding
  • All commands pre-populated with the analyst's dynamic IP inputs from the subnet calculator

Module 6: Lab SOP Compliance Signboard

A printable compliance document featuring:

  • Fillable fields: analyst name, station ID, shielding type used, date/time
  • Live timestamp (auto-updates)
  • Verification checklist summary
  • Active security status badges (colour-coded)
  • Designed for physical printing and posting on the laboratory door or Faraday enclosure

Module 7: Local Session Audit Log

Persistent Browser Storage

  • All analyst actions (checklist completions, script generations, isolation state changes) are automatically saved to browser localStorage
  • History persists across browser tab refreshes and session restarts

Interactive Log Controls

  • Filter by category: All / Isolation States / Checklist Steps / Physical Mitigation
  • Purge log with a single action

Visual Timeline

  • Chronological event log with precise timestamps
  • Colour-coded badges for each event type
  • Clean, scannable timeline layout

Technical Architecture

Component Detail
Frontend HTML5 + TypeScript (Vite bundler)
Desktop Shell Tauri (Rust-based cross-platform desktop wrapper)
Styling Vanilla CSS
State localStorage for persistence
Diagrams Dynamic SVG (inline, JavaScript-animated)
Calculations Pure JavaScript (no external math libraries)
Script Generation Template-based string interpolation
Build Vite dev server / Tauri build for distributable

Deployment

The application can be run in two modes:

Browser Mode (Development)

npm install
npm run dev

Opens at localhost:5173 — full functionality in any modern browser.

Desktop Application (Tauri)

npm install
npm run tauri build

Produces a native .exe (Windows), .dmg (macOS), or .AppImage/.deb (Linux) distributable.


Legal and Compliance Context

NO-ESC AirGap Lab is a defensive, compliance, and training tool designed exclusively to help analysts:

  • Stay within legal boundaries when operating wireless security equipment
  • Prevent accidental signal leakage into public airspace
  • Maintain documented evidence of safety compliance

All Rights Reserved. The software and its methodologies are proprietary.

Return to Projects