StatusISOLATED LAB
EgressBLOCKED?
Resume Session
OPERATOR CONSOLE

Isolated AD Red-Team Lab Dashboard

Build, attack, detect, and remediate inside the isolated 10.10.10.0/24 segment.

Network Topology

SUB 10.10.10.0/24

Kill Chain Progress

PHASE 03: INITIAL ACCESS30% CHAIN
T1566.001T1204.002T1059.001
OPEN PHASE →

Event Log

[RECON] Lab isolated. arp-scan across 10.10.10.0/24 returned four hosts as expected.

--:--:--

[ACCESS] Payload dropped via \\FS01\Finance\ops-lab. Beacon check-in at 60s.

--:--:--

Phase 03: Initial Access

0% COMPLETE

Obtain the first foothold. In-lab this simulates a phishing payload landing on WIN01 as a domain user.

operator@linux01 ~ /ops/access
[*] Session 1 opened: WIN01\jsmith (Medium)
sliver (WIN01) > shell whoami /all
USER INFORMATION: lab\jsmith
PRIVILEGES: SeShutdownPrivilege, SeChangeNotifyPrivilege ...
$

Quick Snapshots

apprenticeship-final
pre-exploit-clean

Apprenticeship — W4 FS01 Hardening

OPEN →

Provision shares, model NTFS + share ACLs, enable access-based enumeration.

FS01.LAB

Command Reference — Initial Access