Changelog

This will be the changelog for any additions or edits to the course, it will be displayed newest update first.


December 30th 2024

  • Splunk support added

    • Added instructions on manual lab creation with Splunk

    • Added Splunk version of Ludus deploy

    • All lessons now available with Splunk queries

  • Added note to "DPAPI at the Host and Network Layer" section, recent Chrome/Edge browser changes have rendered some of the executions in this section non functional.


December 25th 2024

  • Updated Azure Session Hijack via HAR file section with instructions on enabling HAR file generation with sensitive data


December 8th 2024

  • New BadZure module with Python installation


December 2nd 2024

  • Updated Ludus range configuration to account for Ludus API Changes

  • Made the Sumo Logic token a variable within range.yml for the Ludus range

  • Special thank you to dotKnewt for the above changes!


July 10th 2024

  • Ludus build of the lab available


July 6th 2024

  • Added an updated Kubernetes Monitoring section with new instructions

    • Legacy Kubernetes Monitoring instructions left up for reference

  • Added troubleshooting steps to Malcolm appliance provisioning

  • Updated Linux queries to be collector name agonistic

    • There is currently a bug in Podia that is preventing me from updating the queries in the Credential Access on Linux Hosts - Through a C2 Framework section

    • If your queries are not working for this section, ensure they start with sourceCategory="linuxlaurel"

  • Added some verbiage to sections for Ludus-specific lab deploys in preparation for the Ludus deployment of the Constructing Defense lab


May 24th 2024

[New Lesson]: Purple Teaming Memory Forensics With MemProcFS


April 14th 2024

[New Lesson]: DPAPI at the Host and Network Layer

[New Lesson]: Azure/Entra Session Hijack via HAR file


March 15th 2024

[New Lesson]: Web Sockets & .NET Assemblies


March 14th 2024

  • Added section for the new Malcom version (v24.03.0)

    • If you are starting the course fresh, make sure to use this section and not the old Malcolm version.


February 25th 2024

  • [New Lesson]: Kubernetes Threat Detection - Poisoned Pod

  • [New Lesson]: Kerberos Attacks & Defenses - Pass the Ticket

  • [New Lesson]: Kerberos Attacks & Defenses - Golden Ticket


February 4th 2024

  • [New Lesson]: Azure/Entra Session Hijacking via Browser Cookie Theft


January 20th 2024

  • [New Lesson]: Endpoint Analysis with Hayabusa and LangChain


January 13th 2024

  • Course is now life time access instead of 365 days

  • Added option to deploy the lab via Terraform to AWS instead of hosting it on a local hypervisor

    • Please note this option currently limits packet capture capabilities, I'm currently working on a solution for this.

Constructing Defense

Buy nowLearn more
  • 🚨Important Changes Coming to Constructing Defense - Please Read ⚠️3

Welcome to Constructing Defense!

  • Welcome & Introduction
  • Changelog

Lab Overview

  • Lab Overview4
  • General Lab Build Approach2

Lab Construction

  • ISO Downloads - Windows Server 20192
  • ISO Downloads - Windows 11
  • ISO Downloads - Ubuntu2
  • ISO Downloads - PCAP3

Lab Construction - AWS Version

  • Terraform Setup9
  • Domain Controller
  • Windows 11 A & V
  • Certer
  • Linux A & Linux V2

[Splunk] - Lab Construction & Provisioning - Ludus Version

  • [Splunk] - Ludus Overview5
  • [Splunk] - Ludus Deploy4
  • [Splunk] - Ludus Post Deploy Setup

Lab Construction & Provisioning - Ludus Version

  • Ludus Overview
  • Ludus Setup10
  • Ludus Post Deploy Setup4

Lab Provisioning

  • Domain Controller6
  • Windows 11 A & V7
  • Certer
  • Linux A & Linux V4
  • PCAP15
  • PCAP - New Malcolm Version10
  • Cloud Accounts - Azure1
  • Cloud Accounts - Amazon Web Services (AWS)1
  • Kubernetes Setup
  • Sysmon Setup7

Telemetry Setup & Miscellaneous Lab Configuration

  • Section Intro
  • Windows Auditing and GPO Setup
  • Disabling Defender
  • Certificate Enrollment
  • Linux Auditd + Laurel19
  • Sumo Logic SIEM Account
  • [Sumo Logic] - Windows Event Collection3
  • [Sumo Logic] - Linux Event Collection3
  • [Legacy] - Kubernetes Monitoring
  • [Sumo Logic] - Kubernetes Monitoring5
  • [Sumo Logic] - Cloud Collection - AWS5
  • [Sumo Logic] - Cloud Collection - Azure5
  • [Splunk] - Splunk Setup
  • [Splunk] - Forwarder Setup (Windows)5
  • [Splunk] - Forwarder Setup (Linux)3
  • [Splunk] - Kubernetes Monitoring9
  • [Splunk] - Cloud Collection - AWS5
  • [Splunk] - Cloud Collection - Azure/Entra

Lab Executions

  • Section Intro
  • Getting to Know Ourselves3
  • Our First Shell1
  • First Shell - Detection 1
  • First Shell - Detection 2
  • Our Second Shell - Exploring the Network Layer5
  • Second Shell - Bonus Round
  • Credential Access on Windows Hosts - LSASS
  • Credential Access on Windows Hosts - File Shares1
  • Credential Access on Windows Hosts - Kerberoasting
  • Credential Access on Windows Hosts - DCSync
  • Lateral Movement in Windows Environments - WMIExec5
  • Lateral Movement in Windows Environments - PSExec
  • Discovery/Recon Detection on Windows Hosts
  • Profiling Rundll32 Executions on Windows Hosts
  • LOLBAS / LOLBINs
  • Active Directory Certificate Services3
  • Authentication Anomalies on Windows Hosts - The Classic Brute Force
  • Authentication Anomalies on Windows Hosts - The Kerberos Approach
  • Credential Access on Linux Hosts - The Shadow File
  • Credential Access on Linux Hosts - Through a C2 Framework
  • Lateral Movement on Linux Hosts - Interactive Bash Prompts
  • Web Shell Detections on Linux Hosts
  • Kubernetes Threat Detection - Dipping our Toes
  • Kubernetes Threat Detection - The Host Layer
  • Kubernetes Threat Detection - The Host Layer - Enumeration
  • Kubernetes Threat Detection - Tunneling & Exposed Services
  • Kubernetes Goat 🐐
  • Kubernetes Threat Detection - Poisoned Pod
  • Azure - Password Sprays
  • Azure - MFA Madness
  • Azure - Wrangling Applications
  • [Legacy] - Azure - Bad to the Bone3
  • [Updated] - Azure - Bad to the Bone
  • Azure - AzureHound2
  • Azure/Entra Session Hijacking via Browser Cookie Theft 🍪
  • Azure Session Hijack via HAR File
  • AWS - Account Set Up and CLI Access2
  • AWS - CloudTrail - IAM User Creation
  • AWS - CloudTrail - IAM User Enumeration
  • AWS - CloudTrail - Pacu - IAM Brute Force
  • AWS - CloudTrail - Pacu - S3 Bucket Exfil
  • Adding a bit of Purple
  • Endpoint Analysis with Hayabusa and Langchain
  • Kerberos Attacks & Defenses - Pass the Ticket
  • Kerberos Attacks & Defenses - Golden Ticket
  • Web Sockets & .NET Assemblies
  • DPAPI at the Host and Network Layer
  • Purple Teaming Memory Forensics with MemProcFS

Lab Executions - Splunk

  • [Splunk] - Getting to Know Ourselves
  • [Splunk] - Our First Shell3
  • [Splunk] First Shell - Detection 12
  • [Splunk] - First Shell - Detection 2
  • [Splunk] - Our Second Shell - Exploring the Network Layer2
  • [Splunk] - Second Shell - Bonus Round
  • [Splunk] - Credential Access on Windows Hosts - LSASS
  • [Splunk] - Credential Access on Windows Hosts - File Shares
  • [Splunk] - Credential Access on Windows Hosts - Kerberoasting
  • [Splunk] - Credential Access on Windows Hosts - DCSync
  • [Splunk] - Lateral Movement in Windows Environments - WMIExec
  • [Splunk] - Lateral Movement in Windows Environments - PSExec
  • [Splunk] - Discovery/Recon Detection on Windows Hosts
  • [Splunk] - Profiling Rundll32 Executions on Windows Hosts
  • [Splunk] - LOLBAS / LOLBINs
  • [Splunk] - Active Directory Certificate Services
  • [Splunk] - Authentication Anomalies on Windows Hosts - The Classic Brute Force
  • [Splunk] - Authentication Anomalies on Windows Hosts - The Kerberos Approach
  • [Splunk] - Credential Access on Linux Hosts - The Shadow File
  • [Splunk] - Credential Access on Linux Hosts - Through a C2 Framework
  • [Splunk] - Lateral Movement on Linux Hosts - Interactive Bash Prompts
  • [Splunk] - Web Shell Detections on Linux Hosts
  • [Splunk] - Kubernetes Threat Detection - Dipping our Toes
  • [Splunk] - Kubernetes Threat Detection - The Host Layer
  • [Splunk] - Kubernetes Threat Detection - The Host Layer - Enumeration
  • [Splunk] - Kubernetes Threat Detection - Tunneling & Exposed Services
  • [Splunk] - Kubernetes Goat 🐐
  • [Splunk] - Kubernetes Threat Detection - Poisoned Pod
  • [Splunk] - Azure - Password Sprays
  • [Splunk] - Azure - MFA Madness
  • [Splunk] - Azure - Wrangling Applications
  • [Legacy] - Azure - Bad to the Bone
  • [Updated] - Azure - Bad to the Bone
  • [Splunk] - Azure - AzureHound
  • [Splunk] - Azure/Entra Session Hijacking via Browser Cookie Theft 🍪
  • [Splunk] - Azure Session Hijack via HAR File
  • [Splunk] - AWS - Account Set Up and CLI Access
  • [Splunk] - AWS - CloudTrail - IAM User Creation
  • [Splunk] - AWS - CloudTrail - IAM User Enumeration
  • [Splunk] - AWS - CloudTrail - Pacu - IAM Brute Force
  • [Splunk] - AWS - CloudTrail - Pacu - S3 Bucket Exfil
  • [Splunk] - Adding a bit of Purple
  • [Splunk] - Endpoint Analysis with Hayabusa and Langchain
  • [Splunk] - Kerberos Attacks & Defenses - Pass the Ticket
  • [Splunk] - Kerberos Attacks & Defenses - Golden Ticket
  • [Splunk] - Web Sockets & .NET Assemblies
  • [Splunk] - Purple Teaming Memory Forensics with MemProcFS

Saying Goodbye 👋

  • Outro4