IR Lab Pack
Recon → Web Shell → Persistence
Attack Chain Visualization
Lab Deliverables
Timeline
Chronological attack sequence
Chronological attack sequence
IOCs
Indicators of Compromise
Indicators of Compromise
Root Cause
How the breach occurred
How the breach occurred
Fix Plan
1-page remediation strategy
1-page remediation strategy
Lab Topology
🎯 Victim Server
Ubuntu 22.04 LTS
Apache2 Web Server
Status: Compromised
Evidence: Logs, web shell artifacts
Apache2 Web Server
Status: Compromised
Evidence: Logs, web shell artifacts
🔬 Investigator Workstation
Ubuntu 24.04 LTS
Full forensics toolkit
Status: Clean
Tools: Volatility, lnav, yara, etc.
Full forensics toolkit
Status: Clean
Tools: Volatility, lnav, yara, etc.
⚠️ Safety Notice
Keep the victim VM isolated from the internet to avoid real callbacks.
All "malicious" files are intentionally planted for educational purposes and are documented for instructor reference.