Ludus

Open-source cyber range and automated lab platform built on Proxmox. Deploy Active Directory labs, pen test environments, and purple team setups via Infrastructure-as-Code. By Bad Sector Labs.

3.3 ★ (0 reviews) freemium Free (Community) / Paid (Pro & Enterprise)

Well-regarded open-source cyber range with strong community adoption and active development. CISA has forked the project on GitHub. No formal reviews on G2/TrustRadius, but praised by practitioners on social media and security blogs. Limited analyst coverage due to niche focus and small company size.

Visit Website →
Purple TeamOpen Sourcepenetration testingcyber rangelab automationActive DirectoryProxmox

About Ludus

Ludus is an open-source cyber range platform created by Bad Sector Labs (founded by Erik Hunstad in Ann Arbor, Michigan). Built on Proxmox virtualization with automation via Packer and Ansible, Ludus lets security teams deploy reproducible, portable cyber environments using simple YAML configuration files.

Key use cases include Active Directory lab deployments, penetration testing environments, purple teaming setups, Atomic Red Team testing, and security training scenarios. The platform supports multi-user isolated ranges on a single server, includes a built-in WireGuard VPN for secure remote access, and offers snapshot capabilities for environment management. It integrates with GOAD (Game of Active Directory) for complex AD scenarios.

Ludus is available in multiple editions:

  • Community (Free) — Open-source core under AGPLv3
  • Pro — For professionals, with additional closed-source plugins
  • Enterprise Self-Hosted — Self-hosted at scale for organizations managing their own infrastructure
  • Enterprise Fully Hosted — Fully managed by Bad Sector Labs, no infrastructure overhead

The project is actively developed on GitLab with a GitHub mirror, and notably has a CISA (Cybersecurity and Infrastructure Security Agency) fork on GitHub. The platform has gained strong community adoption among red teamers, blue teamers, and security trainers, with tutorials and integrations appearing across security blogs and YouTube.

Headquarters
Ann Arbor, Michigan
Target
SMB

// Similar Tools

HackerOne
Bug bounty and vulnerability disclosure platform connecting organizations with ethical hackers worldwide.
4.3 ★
Pentera
Automated security validation platform that continuously tests your defenses with real attack techniques.
4 ★
Cymulate
Breach and attack simulation platform for continuous security validation and exposure management.
4 ★
Picus Security
Adversarial exposure validation combining attack simulation, automated pentesting, and risk prioritization.
4 ★