Image: blackhillsinfosec.com · rights & removal
Threat Hunting Home Lab: Your Personal Playground for Learning Adversary Behavior
Reporting by Black Hills Information SecurityRead the original at blackhillsinfosec.com
Executive Summary
Facts Only
* Host 1 is the Control HQ for orchestration via browser, terminal, or RDP/VNC.
* Host 2 is the Victim, running Windows 10/11, intended to record network traffic (for Zeek logs) and endpoint activity (Sysmon).
* Host 3 is the C2 Server and RITA instance, running Ubuntu, located on an external network separate from the victim.
* The C2 server must be on an external network for RITA to analyze north-south traffic patterns effectively.
* Victim setup requires disabling Windows Defender using a specific script.
* Sysmon is installed on the victim, utilizing a baseline configuration derived from SwiftOnSecurity.
* Network traffic capture is facilitated by tools like TShark or tcpdump.
* Sliver is recommended as a starting C2 framework, while RITA is co-located with the C2 server on Ubuntu.
Full Take
From the original · Black Hills Information Security
This article was originally published in the InfoSec Survival Guide: Teal Book — Threat Hunting. Read it free online HERE, or grab it on the Spearphish General Store (free digital download or a $1.25 physical copy, your call). | Want to understand how attackers actually operate?Read the full story at blackhillsinfosec.com
Sentinel — Human
The text functions as a high-quality, practical guide for setting up a specific cybersecurity research lab. It exhibits the voice and detail characteristic of an experienced technical writer sharing operational knowledge.
