<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://book.ghanim.no/index.php?action=history&amp;feed=atom&amp;title=HomeLab%2FDetection_Lab</id>
	<title>HomeLab/Detection Lab - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://book.ghanim.no/index.php?action=history&amp;feed=atom&amp;title=HomeLab%2FDetection_Lab"/>
	<link rel="alternate" type="text/html" href="https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;action=history"/>
	<updated>2026-04-05T22:47:18Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;diff=2255&amp;oldid=prev</id>
		<title>Administrator at 21:20, 17 February 2026</title>
		<link rel="alternate" type="text/html" href="https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;diff=2255&amp;oldid=prev"/>
		<updated>2026-02-17T21:20:45Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 21:20, 17 February 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[File:2024-04-DALL·E-2024-04-05-11.53.35-Create-an-image-depicting-a-cybersecurity-detection-lab.-The-scene-should-include-multiple-computer-monitors-displaying-various-types-of-cybersecurity.webp|thumb]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Update ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Update ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key my_wiki:diff:1.41:old-2254:rev-2255:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Administrator</name></author>
	</entry>
	<entry>
		<id>https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;diff=2254&amp;oldid=prev</id>
		<title>Administrator at 21:19, 17 February 2026</title>
		<link rel="alternate" type="text/html" href="https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;diff=2254&amp;oldid=prev"/>
		<updated>2026-02-17T21:19:57Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 21:19, 17 February 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l12&quot;&gt;Line 12:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 12:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This time though, it all works well.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This time though, it all works well.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[File:2024-04-image-12.png|thumb]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[File:2024-04-image-12.png|thumb]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;We can also verify that all the GOAD VM&amp;#039;s have Elastic agents running healthy.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;We can also verify that all the GOAD VM&amp;#039;s have Elastic agents running healthy.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[File:2024-04-image-13.png|thumb]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[File:2024-04-image-13.png|thumb]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The next goal is to complete GOAD while trying to monitor Elastic in order to understand which attack vector gets caught and which do not. Also will work on my malware development and evading detection in preperation for CRTO 2.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The next goal is to complete GOAD while trying to monitor Elastic in order to understand which attack vector gets caught and which do not. Also will work on my malware development and evading detection in preperation for CRTO 2.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Administrator</name></author>
	</entry>
	<entry>
		<id>https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;diff=2253&amp;oldid=prev</id>
		<title>Administrator at 21:19, 17 February 2026</title>
		<link rel="alternate" type="text/html" href="https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;diff=2253&amp;oldid=prev"/>
		<updated>2026-02-17T21:19:47Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 21:19, 17 February 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l8&quot;&gt;Line 8:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 8:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[File:2024-04-image-11.png|thumb]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[File:2024-04-image-11.png|thumb]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;After upgrading my hardware I destroyed all my ranges and used the config below for Elastic EDR, GOAD and Kali and deployed it again. This time, it all worked without any problems as opposed to earlier. Because of my weak CPU the VM&amp;#039;s was not able to catch up with Ansible and was timing out with different errors.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;After upgrading my hardware I destroyed all my ranges and used the config below for Elastic EDR, GOAD and Kali and deployed it again. This time, it all worked without any problems as opposed to earlier. Because of my weak CPU the VM&amp;#039;s was not able to catch up with Ansible and was timing out with different errors.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This time though, it all works well.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This time though, it all works well.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Administrator</name></author>
	</entry>
	<entry>
		<id>https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;diff=2252&amp;oldid=prev</id>
		<title>Administrator at 21:19, 17 February 2026</title>
		<link rel="alternate" type="text/html" href="https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;diff=2252&amp;oldid=prev"/>
		<updated>2026-02-17T21:19:41Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 21:19, 17 February 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l6&quot;&gt;Line 6:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 6:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I was able to upgrade my CPU and motherboard to i9 9900k. 9900k have a passmark above 18000.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I was able to upgrade my CPU and motherboard to i9 9900k. 9900k have a passmark above 18000.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[File:2024-04-image-11.png|thumb]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[File:2024-04-image-11.png|thumb]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key my_wiki:diff:1.41:old-1211:rev-2252:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Administrator</name></author>
	</entry>
	<entry>
		<id>https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;diff=1211&amp;oldid=prev</id>
		<title>imported&gt;Aghanim at 09:55, 5 August 2024</title>
		<link rel="alternate" type="text/html" href="https://book.ghanim.no/index.php?title=HomeLab/Detection_Lab&amp;diff=1211&amp;oldid=prev"/>
		<updated>2024-08-05T09:55:51Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[File:2024-04-DALL·E-2024-04-05-11.53.35-Create-an-image-depicting-a-cybersecurity-detection-lab.-The-scene-should-include-multiple-computer-monitors-displaying-various-types-of-cybersecurity.webp|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Update ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I was able to upgrade my CPU and motherboard to i9 9900k. 9900k have a passmark above 18000.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image-11.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After upgrading my hardware I destroyed all my ranges and used the config below for Elastic EDR, GOAD and Kali and deployed it again. This time, it all worked without any problems as opposed to earlier. Because of my weak CPU the VM&amp;#039;s was not able to catch up with Ansible and was timing out with different errors.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This time though, it all works well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image-12.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We can also verify that all the GOAD VM&amp;#039;s have Elastic agents running healthy.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image-13.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The next goal is to complete GOAD while trying to monitor Elastic in order to understand which attack vector gets caught and which do not. Also will work on my malware development and evading detection in preperation for CRTO 2.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Intro ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
When doing an engagement sometimes one would need to test a payload or an attack vector before deploying it. Watching how an operating system logs different events or how security solutions detect certain payloads can be valuable information for a red teamer/penetration tester.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
An example that happened was gained credentials to MSSQL, and the MSSQL user had rights to enable xp_cmdshell. Of course, running commands through xp_cmdshell would always be detected in a mature envrionment, but what about other indirect exectuion such as relaying? Instead of testing in a production environment and possibly blow your cover, one could test it in a detection lab.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
So the the plan is as follow:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Using Ludus to set up GOAD ([https://docs.ludus.cloud/docs/Environment%20Guides/goad Game of Active Directory (GOAD) | Ludus])&lt;br /&gt;
&lt;br /&gt;
GOAD (https://github.com/Orange-Cyberdefense/GOAD) is a great way to test different attack vectors against AD.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Using Ludus to setup ELK and Fleet. ([https://docs.ludus.cloud/docs/Environment%20Guides/elastic Elastic Security | Ludus])&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Setting up ludus ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Setting up ludus is explained in detail on their website: https://ludus.cloud. In my lab setup I&amp;#039;ve used debian 12 with 32 GB ram, 250 GB on an NVME ssd and 4 cores. My i3 9100F is not strong enough to run GOAD, Elastic and Kali. So until I&amp;#039;ve upgraded my hardware I will deploy elastic, windows vm, linux vm and a kali.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Remember to make sure your CPU is higher than 6000 passmark. Preferably 10K, maybe more.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now onto the building of templates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Keep in mind building the first templates can take hours, depending on your internet speed and hardware.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to interact with the VM&amp;#039;s either using SSH, RDP or KasmVNC you need to setup WireGuard.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
$env:LUDUS_API_KEY=&amp;#039;JD._7Gx2T5kTUSD%uTWZ*lFi=Os6MpFR^OrG+yT94Xt&amp;#039;&lt;br /&gt;
.\ludus-client.exe user wireguard --user JD --url https://127.0.0.1:8081 | Tee-Object -Variable luduswg; $luduswg  | Set-Content -Encoding ASCII ludus.conf&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
When the setup is finished you will have a ludus.conf file that you import to WireGuard and connect.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Setting up ranges ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After you&amp;#039;ve finished setting up ludus, you are now ready to deploy ranges. There are multiple environments you can set up. A complete list can be found here: [https://docs.ludus.cloud/docs/category/environment-guides 🏗️ Environment Guides | Ludus].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For this lab I&amp;#039;ve setup GOAD and Elastic Security.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Follow the guide for setting up GOAD. After that we can deploy elastic and agents on the GOAD vms. Use the config below.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Add the roles below&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
ludus ansible roles add badsectorlabs.ludus_elastic_container&lt;br /&gt;
ludus ansible roles add badsectorlabs.ludus_elastic_agent&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    2. Add &amp;lt;code&amp;gt;badsectorlabs.ludus_elastic_agent&amp;lt;/code&amp;gt; role to the hosts you want to deploy agent to. See the config below. Afterwards run &amp;lt;code&amp;gt;ludus range config set -f config.yml&amp;lt;/code&amp;gt; and deploy using &amp;lt;code&amp;gt;ludus range deploy&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The below config wil deploy GOAD, Elastic EDR and a Kali. All the VMs in GOAD will have an Elastic Agent. You can add roles by adding these lines&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
roles:&lt;br /&gt;
      - badsectorlabs.ludus_elastic_agent&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;yaml&amp;quot;&amp;gt;&lt;br /&gt;
ludus:&lt;br /&gt;
&lt;br /&gt;
 - vm_name: &amp;quot;{{ range_id }}-elastic&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-elastic&amp;quot;&lt;br /&gt;
    template: debian-12-x64-server-template&lt;br /&gt;
    vlan: 10&lt;br /&gt;
    ip_last_octet: 1&lt;br /&gt;
    ram_gb: 8&lt;br /&gt;
    cpus: 4&lt;br /&gt;
    linux: true&lt;br /&gt;
    testing:&lt;br /&gt;
      snapshot: false&lt;br /&gt;
      block_internet: false&lt;br /&gt;
    roles:&lt;br /&gt;
      - badsectorlabs.ludus_elastic_container&lt;br /&gt;
    role_vars:&lt;br /&gt;
      ludus_elastic_password: &amp;quot;thisisapassword&amp;quot;&lt;br /&gt;
&lt;br /&gt;
  - vm_name: &amp;quot;{{ range_id }}-GOAD-DC01&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-DC01&amp;quot;&lt;br /&gt;
    template: win2019-server-x64-template&lt;br /&gt;
    vlan: 10&lt;br /&gt;
    ip_last_octet: 10&lt;br /&gt;
    ram_gb: 4&lt;br /&gt;
    cpus: 2&lt;br /&gt;
    windows:&lt;br /&gt;
      sysprep: true&lt;br /&gt;
    roles:&lt;br /&gt;
      - badsectorlabs.ludus_elastic_agent&lt;br /&gt;
  - vm_name: &amp;quot;{{ range_id }}-GOAD-DC02&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-DC02&amp;quot;&lt;br /&gt;
    template: win2019-server-x64-template&lt;br /&gt;
    vlan: 10&lt;br /&gt;
    ip_last_octet: 11&lt;br /&gt;
    ram_gb: 4&lt;br /&gt;
    cpus: 2&lt;br /&gt;
    windows:&lt;br /&gt;
      sysprep: true&lt;br /&gt;
    roles:&lt;br /&gt;
      - badsectorlabs.ludus_elastic_agent&lt;br /&gt;
  - vm_name: &amp;quot;{{ range_id }}-GOAD-DC03&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-DC03&amp;quot;&lt;br /&gt;
    template: win2016-server-x64-template&lt;br /&gt;
    vlan: 10&lt;br /&gt;
    ip_last_octet: 12&lt;br /&gt;
    ram_gb: 4&lt;br /&gt;
    cpus: 2&lt;br /&gt;
    windows:&lt;br /&gt;
      sysprep: true&lt;br /&gt;
    roles:&lt;br /&gt;
      - badsectorlabs.ludus_elastic_agent&lt;br /&gt;
  - vm_name: &amp;quot;{{ range_id }}-GOAD-SRV02&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-SRV02&amp;quot;&lt;br /&gt;
    template: win2019-server-x64-template&lt;br /&gt;
    vlan: 10&lt;br /&gt;
    ip_last_octet: 22&lt;br /&gt;
    ram_gb: 4&lt;br /&gt;
    cpus: 2&lt;br /&gt;
    windows:&lt;br /&gt;
      sysprep: true&lt;br /&gt;
    roles:&lt;br /&gt;
      - badsectorlabs.ludus_elastic_agent&lt;br /&gt;
  - vm_name: &amp;quot;{{ range_id }}-GOAD-SRV03&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-SRV03&amp;quot;&lt;br /&gt;
    template: win2019-server-x64-template&lt;br /&gt;
    vlan: 10&lt;br /&gt;
    ip_last_octet: 23&lt;br /&gt;
    ram_gb: 4&lt;br /&gt;
    cpus: 2&lt;br /&gt;
    windows:&lt;br /&gt;
      sysprep: true&lt;br /&gt;
    roles:&lt;br /&gt;
      - badsectorlabs.ludus_elastic_agent&lt;br /&gt;
  - vm_name: &amp;quot;{{ range_id }}-kali&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-kali&amp;quot;&lt;br /&gt;
    template: kali-x64-desktop-template&lt;br /&gt;
    vlan: 10&lt;br /&gt;
    ip_last_octet: 99&lt;br /&gt;
    ram_gb: 4&lt;br /&gt;
    cpus: 2&lt;br /&gt;
    linux: true&lt;br /&gt;
    testing:&lt;br /&gt;
      snapshot: false&lt;br /&gt;
      block_internet: false&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The config below will deploy Elastic, Windows 11 host, a Debian  host and Kali.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
ludus:&lt;br /&gt;
  - vm_name: &amp;quot;{{ range_id }}-elastic&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-elastic&amp;quot;&lt;br /&gt;
    template: debian-12-x64-server-template&lt;br /&gt;
    vlan: 20&lt;br /&gt;
    ip_last_octet: 1&lt;br /&gt;
    ram_gb: 8&lt;br /&gt;
    cpus: 4&lt;br /&gt;
    linux: true&lt;br /&gt;
    testing:&lt;br /&gt;
      snapshot: false&lt;br /&gt;
      block_internet: false&lt;br /&gt;
    roles:&lt;br /&gt;
      - badsectorlabs.ludus_elastic_container&lt;br /&gt;
    role_vars:&lt;br /&gt;
      ludus_elastic_password: &amp;quot;thisisapassword&amp;quot;&lt;br /&gt;
&lt;br /&gt;
  - vm_name: &amp;quot;{{ range_id }}-debian&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-debian&amp;quot;&lt;br /&gt;
    template: debian-12-x64-server-template&lt;br /&gt;
    vlan: 20&lt;br /&gt;
    ip_last_octet: 20&lt;br /&gt;
    ram_gb: 4&lt;br /&gt;
    cpus: 2&lt;br /&gt;
    linux: true&lt;br /&gt;
    testing:&lt;br /&gt;
      snapshot: false&lt;br /&gt;
      block_internet: false&lt;br /&gt;
    roles:&lt;br /&gt;
      - badsectorlabs.ludus_elastic_agent&lt;br /&gt;
&lt;br /&gt;
  - vm_name: &amp;quot;{{ range_id }}-win11-22h2-enterprise-x64-1&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-WIN11-22H2-1&amp;quot;&lt;br /&gt;
    template: win11-22h2-x64-enterprise-template&lt;br /&gt;
    vlan: 10&lt;br /&gt;
    ip_last_octet: 21&lt;br /&gt;
    ram_gb: 8&lt;br /&gt;
    cpus: 4&lt;br /&gt;
    windows:&lt;br /&gt;
      install_additional_tools: false&lt;br /&gt;
    roles:&lt;br /&gt;
      - badsectorlabs.ludus_elastic_agent&lt;br /&gt;
&lt;br /&gt;
  - vm_name: &amp;quot;{{ range_id }}-kali&amp;quot;&lt;br /&gt;
    hostname: &amp;quot;{{ range_id }}-kali&amp;quot;&lt;br /&gt;
    template: kali-x64-desktop-template&lt;br /&gt;
    vlan: 99&lt;br /&gt;
    ip_last_octet: 1&lt;br /&gt;
    ram_gb: 8&lt;br /&gt;
    cpus: 4&lt;br /&gt;
    linux: true&lt;br /&gt;
    testing:&lt;br /&gt;
      snapshot: false&lt;br /&gt;
      block_internet: false&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After deployment is finished it should look like this.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image-1.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The default credentials to access to different VM&amp;#039;s is:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Default Machine Credentials[https://docs.ludus.cloud/docs/quick-start/deploy-range#default-machine-credentials ​] ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Kali&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;kali:kali&amp;lt;/code&amp;gt; (OS)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;kali:password&amp;lt;/code&amp;gt; (KasmVNC - port 8444)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Windows&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;localuser:password&amp;lt;/code&amp;gt; (local Administrator)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;LUDUS\domainuser:password&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;LUDUS\domainadmin:password&amp;lt;/code&amp;gt; (Domain Admin)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Debian based boxes&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;debian:debian&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Others&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;localuser:password&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Testing the lab ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After everything is setup we can verify that Elastic have a healthy agent on the Windows 11 host and debian host.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image-2.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
As you can see that looks good.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Accessing Kali is done using a browser  with KasmVNC.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image-3.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
And we can RDP to the Windows machine. To get RDP config &amp;lt;code&amp;gt;ludus range rdp&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image-4.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Test Elastic Defender ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now the fun can begin. Lets test defender by dropping a payload to the Windows machine. Elastic EDR have been set to prevent mode.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To make it a bit more challenging av dropped a &amp;lt;code&amp;gt;js&amp;lt;/code&amp;gt; file on disk, that will fetch a payload called chrome.exe. Chrome.exe is an APC injection that will fetch msf.bin payload and execute the task asynchronously. In this test I&amp;#039;ve done it simple and just used metasploit as my c2 framework.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image-7.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After executing the payload we get a pop-up saying that there is a malware alert. Now we can go to Elastic to find out what happened.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image-8.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Looking in Elastic we can see that it flagged our payload &amp;quot;chrome.exe&amp;quot; as malicous.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:2024-04-image-10.png|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This above picutre tells us that a process with the name &amp;quot;chrome&amp;quot;, with parent process wscript.exe, was executed by localuser on the machine and its categorized as critical.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
It wont exactly tell which part of the payload that got caught. So that part you have to dig for yourself using for example ThreatCheck.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Unreachable ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
When deploying a range you might experience an error saying that a host is unreachable. The fix that worked for me is to log into Proxmox and manually reset the host and try deploying again&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Add trusts between domain ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This error occurd multiple times while running &amp;lt;code&amp;gt;provisionning.sh&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To fix this I logged into the faulty host(s) and manually removed the DNS server ending with .254.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then removing trust between the DC1 and DC2. In order to do that you have to have an enterprise admin account, so just create one manually.&lt;br /&gt;
&lt;br /&gt;
[[Category:HomeLab]]&lt;/div&gt;</summary>
		<author><name>imported&gt;Aghanim</name></author>
	</entry>
</feed>