Skip to content

Image: blackhillsinfosec.com · rights & removal

Executive Summary

The setup details a methodology for building a threat hunting home lab to simulate adversary operations. The topology involves three hosts: a Control HQ, a Victim endpoint, and a C2 Server/RITA instance running on an external network. The setup requires disabling Windows Defender on the victim, installing Sysmon with a baseline configuration, and setting up network traffic capture via tools like TShark or tcpdump. The C2 infrastructure is recommended to be hosted on Ubuntu, with Sliver suggested as a starting point for command and control capabilities, while RITA runs alongside the C2 server. This architecture allows for capturing both endpoint telemetry (Sysmon) and network artifacts necessary for analyzing Command and Control beaconing patterns across external boundaries.

Facts Only

* Host 1 is the Control HQ for orchestration via browser, terminal, or RDP/VNC.
* Host 2 is the Victim, running Windows 10/11, intended to record network traffic (for Zeek logs) and endpoint activity (Sysmon).
* Host 3 is the C2 Server and RITA instance, running Ubuntu, located on an external network separate from the victim.
* The C2 server must be on an external network for RITA to analyze north-south traffic patterns effectively.
* Victim setup requires disabling Windows Defender using a specific script.
* Sysmon is installed on the victim, utilizing a baseline configuration derived from SwiftOnSecurity.
* Network traffic capture is facilitated by tools like TShark or tcpdump.
* Sliver is recommended as a starting C2 framework, while RITA is co-located with the C2 server on Ubuntu.

Full Take

The narrative advocates for an active, hands-on environment where intentional vulnerability and system manipulation are central to learning threat hunting techniques. The design intentionally forces the user to engage directly with the artifacts of an attack—network traffic and endpoint telemetry—which is a powerful pedagogical tool. The pattern observed is one of creating controlled complexity to force deep contextual understanding, moving beyond theoretical knowledge to practical observation. The reliance on open-source tools like Sliver and RITA suggests a community-driven approach to security education, offering flexibility that bypasses proprietary vendor constraints. However, the emphasis on disabling baseline security controls before installing telemetry introduces an inherent tension: maximizing data collection versus maintaining operational security in a real environment. The core implication is that true threat hunting requires operating within an adversarial mindset, where the act of breaking systems becomes the necessary precondition for insight. What assumptions about the user's current knowledge level are being addressed by this structured approach? Is the focus on the technical setup overshadowing the cognitive shift required to view system interaction as a deliberate adversary simulation? What methods exist for safely transitioning from a fully controlled lab environment to applying these principles in a more dynamic security context?

From the original · Black Hills Information Security

This article was originally published in the InfoSec Survival Guide: Teal Book — Threat Hunting. Read it free online HERE, or grab it on the Spearphish General Store (free digital download or a $1.25 physical copy, your call). | Want to understand how attackers actually operate?
Read the full story at blackhillsinfosec.com

Sentinel — Human

Confidence

The text functions as a high-quality, practical guide for setting up a specific cybersecurity research lab. It exhibits the voice and detail characteristic of an experienced technical writer sharing operational knowledge.

Signals Detected
low severity: Sentence length variance exhibits natural variation; the tone shifts between instructional command and casual encouragement.
low severity: The text flows logically from setup to specific commands, reflecting a coherent, albeit dense, instructional narrative typical of technical guides.
low severity: Specific tool names (Sliver, RITA, Sysmon, Zeek) and direct command-line instructions are used precisely, suggesting an author with deep practical knowledge.
low severity: The inclusion of specific, actionable, and verifiable GitHub links for tools and configuration files suggests direct sourcing rather than pure generation.
Human Indicators
Use of highly technical, niche community terminology (C2, RITA, Zeek logs, Sysmon) suggests an author operating within a specific technical community.
The explicit recommendation of specific frameworks (Sliver, Merlin) and the framing encouraging experimentation ('breaking things is encouraged') points toward experiential knowledge rather than generic LLM advice.
Inclusion of direct, executable shell commands implies an intent to provide hands-on steps, which often requires human verification.
Threat Hunting Home Lab: Your Personal Playground for Learning Adversary Behavior | Huntaegis