All labs for this course will be completed in the Windows Lab Environment.
Ensure connectivity to the Lab Environment.
Review the provided Lab Network Topology map and System and Credential reference table.
The lab facilitator will provide instructions on connecting to the lab environment. For on site classes this may require a physical cable connection. For remote classes, this may require connecting directly to the lab Domain Controller via Remote Desktop Protocol (RDP) or using a VPN.
The APT Lab network environment topology and reference information is below. Review this information and continue to the next section of this lab.
System | Context | IP | Connection | Username | Password | ||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
AD Domain | DNS | labs.local | 10.10.98.10 | ||||||||||
NBNS | LABS | ||||||||||||
Domain Admin | labs\itadmin | Domain User | labs\heather.butler | ||||||||||
Domain Controller | Server 2016 | DC01 | 10.10.98.10 | RDP via WS01 | |||||||||
Member Server | Server 2016 | WS01 | DHCP (.14) | RDP via Internet | |||||||||
(H)ELK | SIEM Docker | ELK | 10.10.98.20 | SSH | itadmin | APTClass2021! | |||||||
Kibana | ELK | 10.10.98.20 | HTTPS | helk | hunting | ||||||||
Kafka | ELK | 10.10.98.20 | TCP : 9092 | ||||||||||
Logstash | ELK | 10.10.98.20 | TCP : 5044 | ||||||||||
Attack System | Linux | 10.10.98.20 | SSH | itadmin | APTClass2021! | ||||||||
When you have reviewed the APT Lab Topology, System, and Credential Information, continue to the next section of this lab to test initial connection into the lab.
NOTE: The Lab Facilitator will provide you with initial connection information. This initial connection may be an alternate RDP session directly to the Domain Controller system over the Internet. Follow any alternate instructions provided by the facilitator. This lab is complete when you have confirmed RDP access to the lab Domain Controller.
Context | Information |
---|---|
MSRDP | IP Address provided by instructor |
Username | labs\itadmin |
Password | APTClass2021! |
When you have confirmed you have access to the Member Server via RDP, you have completed this connectivity check step.
Once logged on to the Member Server, open a new RDP session from that RDP session. Log in to the Windows DC at dc01.labs.local via MSRDP.
Context | Information |
---|---|
MSRDP | IP Address Provided by instructor |
Username | labs\itadmin |
Password | APTClass2021! |
When you have confirmed you have access to the Domain Controller via RDP, you have completed this connectivity check lab.
Lab Complete
You have completed this lab.