NO-ESC AirGap Lab
NO-ESC AirGap Lab is a specialised interactive cybersecurity training and validation dashboard designed for security researchers and network analys...
NO-ESC AirGap Lab
Category: Web Application / Cybersecurity Training / Interactive Dashboard
Platform: Browser-based (HTML, CSS, JavaScript) — Tauri Desktop App
Framework: Vite + TypeScript frontend; Tauri (Rust) desktop shell
Status: Active — Production Ready
Project Overview
NO-ESC AirGap Lab is a specialised interactive cybersecurity training and validation dashboard designed for security researchers and network analysts who operate wireless auditing equipment — particularly devices such as the WiFi Pineapple that transmit radio signals and interact with WiFi clients.
The core problem it solves: when operating these devices, a single misconfiguration can cause test signals to bleed into public airspace or allow test traffic to accidentally bridge onto production networks — creating legal exposure and operational security failures.
NO-ESC AirGap Lab acts as an interactive digital safety officer — a comprehensive training and validation system that ensures a wireless testing setup remains strictly confined inside a physical and logical "sandbox." It walks the analyst through both the physical containment steps (shielded cables, Faraday cages, ferrite chokes) and the software configuration steps (firewall rules, IP subnet isolation, access control lists) to guarantee that nothing leaks out.
The platform is delivered as both a standalone web application and a cross-platform desktop application via Tauri.
Module 1: Physical Leakage and Cable Attenuation
"Cable-as-Antenna" Education
Explains the phenomenon where unshielded USB cables behave as radiating antennas — allowing RF signals to pass through Faraday cage walls via the cable entry points, defeating the entire purpose of the enclosure.
Interactive Hardware Mitigation Checklist
Step-by-step verification of four physical containment layers:
| Mitigation | Description |
|---|---|
| Ferrite Chokes | Eliminates common-mode high-frequency noise at cable terminations |
| Double-Shielded Cables | Enforces grounded double-braided shielding over standard foil-only lines |
| RF Data Filters | Routes data lines through a low-pass capacitive filter bulkhead connector |
| Earth Grounding | Bonds the host laptop chassis to the laboratory earth ground line |
Each item is interactively checked off, and the routing schematic (Module 2) updates dynamically in response.
Module 2: Interactive Lab Routing Schematic
Real-Time SVG Signal Chain Diagram
A live, animated SVG diagram renders the entire signal flow from the analyst's workstation through:
- Host workstation
- USB cable egress point
- Faraday cage wall
- Bulkhead RF filter
- Internal sandbox (test device)
Dynamic Leak/Secure Indicators
- When mitigation checklist items are incomplete: the diagram animates red RF leakage waves radiating from the cable entry point, labelled "RF LEAKAGE"
- When all mitigations are verified: the diagram switches to green containment lines with a "FILTERED SECURE" status badge
LED Pattern Simulator
Emulates the hardware status LED blink patterns of the auditing device:
- Boot sequence indicator
- Running / active state
- Recovery mode
- Charging state
- Alert/error state
Teaches analysts how to diagnose hardware state from LED blink codes without external tools.
Module 3: Interactive Lab SOP Checklist (4 Phases)
A comprehensive Standard Operating Procedure walked through in four structured phases:
Phase 1 — Safely Isolated Boot
- Cold-charging procedure (battery-only, no live USB connection)
- Tethering configuration via Linux Mint NetworkManager / nmcli commands
- Admin password and initial device hardening
Phase 2 — Locking Down the PineAP Engine
- Disabling client association (prevent devices from connecting to test AP)
- MAC address allow-listing (whitelist-only mode)
- Reducing radio transmit power to minimum safe operational level
Phase 3 — Payload Safety and Auditing
- DuckyScript payload review and safety auditing procedures
- Creating physical hardware Emergency Abort Kill Switches
- Pre-test checklist verification
Phase 4 — Test Router Isolation (Gold Standard)
- Setting up an optional air-gapped router gateway
- Configuring distinct DHCP subnets for the test environment
- Implementing outbound Access Control Lists (ACLs) to block all production traffic
Module 4: Inter-Subnet Leak and Overlap Calculator
Real-Time IP Auditor
An interactive calculator that takes the analyst's specific IP subnet parameters and performs:
- Overlap detection: Checks whether the Pineapple test IP range overlaps with the home/production network range — routing overlap creates the primary bridge risk
- RFC 1918 compliance check: Verifies that all subnets fall within legal private network address space (10.x.x.x, 172.16.x.x, 192.168.x.x)
- Leakage risk prediction: Alerts if subnet configuration could allow routing to bleed between test and production networks
All calculations are performed dynamically in the browser with no server interaction.
Module 5: Tailored Security Script Generator
Generates deployment-ready scripts customised to the analyst's specific network parameters:
Windows PowerShell
- Configures Windows Defender Firewall rules
- Disables LLMNR (Link-Local Multicast Name Resolution) — a common vector for name poisoning attacks
- Disables NetBIOS over TCP/IP — eliminates legacy discovery protocol leakage
Linux (Bash / iptables)
- Complete iptables script with strict forwarding blocks
- INPUT chain filtering for the test interface
- Localhost loopback mapping
- sysctl configurations disabling IP forwarding
- All commands pre-populated with the analyst's dynamic IP inputs from the subnet calculator
Module 6: Lab SOP Compliance Signboard
A printable compliance document featuring:
- Fillable fields: analyst name, station ID, shielding type used, date/time
- Live timestamp (auto-updates)
- Verification checklist summary
- Active security status badges (colour-coded)
- Designed for physical printing and posting on the laboratory door or Faraday enclosure
Module 7: Local Session Audit Log
Persistent Browser Storage
- All analyst actions (checklist completions, script generations, isolation state changes) are automatically saved to browser localStorage
- History persists across browser tab refreshes and session restarts
Interactive Log Controls
- Filter by category: All / Isolation States / Checklist Steps / Physical Mitigation
- Purge log with a single action
Visual Timeline
- Chronological event log with precise timestamps
- Colour-coded badges for each event type
- Clean, scannable timeline layout
Technical Architecture
| Component | Detail |
|---|---|
| Frontend | HTML5 + TypeScript (Vite bundler) |
| Desktop Shell | Tauri (Rust-based cross-platform desktop wrapper) |
| Styling | Vanilla CSS |
| State | localStorage for persistence |
| Diagrams | Dynamic SVG (inline, JavaScript-animated) |
| Calculations | Pure JavaScript (no external math libraries) |
| Script Generation | Template-based string interpolation |
| Build | Vite dev server / Tauri build for distributable |
Deployment
The application can be run in two modes:
Browser Mode (Development)
npm install
npm run dev
Opens at localhost:5173 — full functionality in any modern browser.
Desktop Application (Tauri)
npm install
npm run tauri build
Produces a native .exe (Windows), .dmg (macOS), or .AppImage/.deb (Linux) distributable.
Legal and Compliance Context
NO-ESC AirGap Lab is a defensive, compliance, and training tool designed exclusively to help analysts:
- Stay within legal boundaries when operating wireless security equipment
- Prevent accidental signal leakage into public airspace
- Maintain documented evidence of safety compliance
All Rights Reserved. The software and its methodologies are proprietary.