logo

Automating GOAD and Live Malware Labs

ID: 9868b250-8968-541f-8994-7406a5a46b71

STIX ID: report--9868b250-8968-541f-8994-7406a5a46b71

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-08-27

Author: Nic Palmer,Adrian Chen

...
...

This blog provides a step-by-step blueprint for building an automated, high-fidelity cyber range by combining Ludus (infrastructure automation) with Elastic Security (SIEM/XDR). It merges an Active Directory lab (GOAD) and a malware/supply-chain lab (XZbot) — the latter containing a functional CVE-2024-3094 backdoor — and covers deployment, Elastic Agent/Defend instrumentation, safe isolation via Ludus testing mode, example attack executions (Kerberoasting, PrintNightmare, MSSQL abuse, SSH backdoor trigger), and investigation/automation using Elastic’s Event Analyzer, Session Viewer, Attack Discovery, AI Assistant, and Workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.