This repo documents my hands-on walkthrough of Josh Madakor's vulnerability management lab, part of his public cybersecurity course material. I completed it as structured learning.
The program design is his. So are the meeting videos, policy documents, scan exports, and remediation data linked below. The scripts in scripts/ are his scripts, vendored here for study with attribution in each file header. What I did myself: stood up the lab environment and worked through each phase on my own test VM, following the course.
The lab simulates building a vulnerability management program from scratch in an enterprise environment, using Azure VMs and Tenable (Nessus) as the scanner. It runs the full lifecycle: policy drafting, stakeholder negotiation, credentialed scanning, change board approval, remediation rounds, and ongoing maintenance.
- Tenable (enterprise vulnerability management platform)
- Azure Virtual Machines (for the Nessus scan engine and target systems)
- PowerShell & Bash (remediation automation)
Starting Point: No vulnerability management policy, no processes in place.
End State: An approved policy, stakeholder buy-in, and a complete remediation cycle across the environment.
- Vulnerability Management Policy Draft
- Stakeholder Policy Review Meeting
- Policy Finalization & Leadership Sign-Off
- Initial Scan Permission Meeting
- Initial Scan of Server Assets
- Vulnerability Assessment & Prioritization
- Distributing Remediations
- Post-Scan Review Meeting
- CAB Meeting for Remediation Approval
- Remediation Rounds
- First Cycle Results
- Maintenance Mode
The lab opens with drafting a practical Vulnerability Management Policy covering scope, roles and responsibilities, remediation timelines, and scanning cadence. The draft linked here is the course's document.
→ View the course's draft policy
The draft goes to the server team for review. The recorded session shows their concerns being worked through. One example: the critical remediation timeline moves from 48 hours to one week based on operational feedback.
The policy is revised with the team's feedback and sent to leadership for sign-off. The finalized document linked here is the course's version.
→ Finalized policy (course document)
Before any scanning, the lab covers getting the server team's approval for credentialed scans. The approach: start with one server, monitor the impact, and use just-in-time AD credentials.
Following the course, I provisioned a deliberately vulnerable Windows Server, introduced common issues, and ran a full authenticated scan. The scan screenshot and export below are from the source project.
→ Scan 1 results (source project)
The scan results get prioritized by risk, ease of remediation, and business impact. The course's top priorities:
- Remove outdated third-party software (Wireshark)
- Disable insecure protocols & cipher suites
- Remove Guest account from Administrators group
- Apply Windows OS updates
This phase covers sending the server team clear remediation guidance, scripts, and scan reports.
→ Example remediation email (from the source repo)
The findings are reviewed with the team, and remediation packages are prepared for Change Advisory Board (CAB) approval.
The remediation plan goes to the CAB. The changes are approved with rollback scripts and a phased rollout.
→ Watch the course CAB meeting
The scripts below are the course's scripts, vendored here for study (attribution in each file header). The scan screenshots and exports are from the source project.
Round 1: Outdated Wireshark Removal
A PowerShell script uninstalls the vulnerable version. A follow-up scan verifies the fix.
→ Scan 2 results (source project)
Round 2: Insecure Protocols & Ciphers
Weak protocols and cipher suites are disabled via PowerShell.
→ Protocols Script
→ Ciphers Script
→ Scan 3 results (source project)
Round 3: Guest Account Group Membership
The Guest account is removed from the local Administrators group.
→ Scan 4 results (source project)
Round 4: Windows OS Updates
Updates are re-enabled and applied until the system is current.
→ Scan 5 results (source project)
The source project reports an 80% reduction in total vulnerabilities (from 30 to 6) after the first cycle:
- Criticals: 100% resolved
- Highs: 90% resolved
- Mediums: 76% resolved
These are Josh Madakor's reported results for his course environment, not measurements from my own lab. The spreadsheet below is his. In a real environment, the next step is to keep driving the count down using asset criticality scoring.
→ Full remediation data (source project)
The lab closes with the program shifting into steady-state operations: regular scans, patch management, continuous monitoring, policy reviews, and stakeholder coordination, all defined in the course's finalized policy.
Key activities:
- Scheduled scans: weekly or monthly cadence to catch new vulnerabilities as systems evolve
- Patch management: continuous application of security updates
- Remediation follow-ups: prioritized by risk and business impact
- Policy reviews: kept current with evolving best practices and organizational needs
- Audit & compliance: internal audits to verify adherence to policy and external requirements
- Stakeholder communication: ongoing coordination with remediation teams
The goal is to stay ahead of new vulnerabilities instead of playing constant catch-up.
- Program design, videos, policy documents, scan exports, and remediation data: Josh Madakor, from lognpacific-public. The scripts in
scripts/are vendored from that repo'sautomation/folder. - My part: running the lab hands-on and keeping these notes.
If you want to run the same exercise, start from the source repo. The recorded meetings are worth watching in full.




