Automating GOAD and Live Malware Labs
ID: 9868b250-8968-541f-8994-7406a5a46b71
STIX ID: report--9868b250-8968-541f-8994-7406a5a46b71
Feed Name: Elastic Security Labs
This blog provides a step-by-step blueprint for building an automated, high-fidelity cyber range by combining Ludus (infrastructure automation) with Elastic Security (SIEM/XDR). It merges an Active Directory lab (GOAD) and a malware/supply-chain lab (XZbot) — the latter containing a functional CVE-2024-3094 backdoor — and covers deployment, Elastic Agent/Defend instrumentation, safe isolation via Ludus testing mode, example attack executions (Kerberoasting, PrintNightmare, MSSQL abuse, SSH backdoor trigger), and investigation/automation using Elastic’s Event Analyzer, Session Viewer, Attack Discovery, AI Assistant, and Workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
