logo

Automating GOAD and Live Malware Labs

ID: f7be1b4f-3fcc-5589-bd8c-96909f9485ec

STIX ID: report--f7be1b4f-3fcc-5589-bd8c-96909f9485ec

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2026-02-05

Date Updated: 2026-04-27

...
...

This blog presents a blueprint for an automated, scalable cyber-range combining Ludus (for multi-VM lab deployment) and Elastic Security (EDR/SIEM/XDR) to simulate and validate detection of real-world attacks. The guide includes deployment steps that intentionally install a functional backdoor (CVE-2024-3094), demonstrates exploitation techniques (PrintNightmare, Kerberoasting, MSSQL xp_cmdshell, scheduled tasks), and shows how Elastic’s detection rules, Event Analyzer, Session Viewer, Attack Discovery, AI Assistant, and Workflows can be used to detect, investigate, and automate responses to those attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.