Skip to content

Commit 6207180

Browse files
authored
Merge pull request #5 from KAISERaustin/timscreenshotupdates
Timscreenshotupdates
2 parents 41fe2e6 + 35798c5 commit 6207180

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

76 files changed

+225
-82
lines changed

IntroClassFiles/Tools/IntroClass/LCmeetsAtomicRed/LCAR.md

Lines changed: 21 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -12,38 +12,49 @@ We need to install the plugin for Atomic Red that Lima Charlie offers.
1212

1313
Start by navigating to the "Add-ons" tab in the top right of the web page.
1414

15-
<img src="attachments/ADDONS.PNG" alt="register an account" width="300" />
15+
![](attachments/ADDONS.PNG)
1616

1717
Scroll down until you see the Atomic Red plugin. Click the Atomic Red plugin.
1818

19-
<img src="attachments/AR.PNG" alt="register an account" width="300" />
20-
19+
![](attachments/AR.PNG)
2120
Take a minute to look at the different plugins and see the full capabillities and features Lima Charlie has to offer.
2221

2322
Then locate the subscribe button on the right side of the page, and click "Subscribe"
2423

25-
<img src="attachments/SUBSCRIBE.PNG" alt="register an account" width="300" />
24+
![](attachments/SUBSCRIBE.PNG)
2625

2726
After Atomic Red finishes installing return back to your organization and click on your machine.
2827

29-
<img src="attachments/HOST.PNG" alt="register an account" width="300" />
28+
![](attachments/navtoorganizations.png)
29+
30+
![](attachments/selectorganization.png)
31+
32+
On the left side of your screen, click on "Extensions" to expand the dropdown menu. Select Atomic Red Team.
33+
34+
![](attachments/extensions.png)
3035

31-
Scroll down and you will see a few options, yara and atomic red. Click "Run atomic tests"
36+
On the next screen, we need to first click on the dropdown next to the Sid bar at the top. Then, select your device.
3237

33-
<img src="attachments/RUNAR.PNG" alt="register an account" width="300" />
38+
![](attachments/selectdevice.png)
3439

35-
Go to the command and control and click "(1)Select Category" then click "(2)Run Tests"
40+
Next, scroll down until you find the `command-and-control` category. Select the box next to the category header and make sure that it selects all of the boxes below.
3641

37-
<img src="attachments/C2ALL.PNG" alt="register an account" width="300" />
42+
Now, hit `Run Tests`
43+
44+
![](attachments/C2ALL.PNG)
3845

3946
Then move over to the "Detections" tab on the left and start going through event logs
4047

41-
<img src="attachments/DETECTED.PNG" alt="register an account" width="700" />
48+
![](attachments/detections.png)
49+
50+
![](attachments/logsscreen.png)
4251

4352
There will be a lot of events, everytime the page is refreshed more attacks will appear.
4453

4554
Looking through all of the logs and note the cmd.exe or powershell invokes are taking place. These are (usually) indications of something malicious occuring and needs to be examined further.
4655

56+
![](attachments/DETECTED.PNG)
57+
4758
Lima Charlie is an amazing tool because of its versatillity. With an easy to look at interface that if need be, allows a user to dig deeper to see whats happening before, during, and after an attack. Its abillity to be used on small and large scale is a great feature.
4859

4960
Many plugins allow for different uses large and small, and automating the difficult tasks.
130 KB
Loading
35.2 KB
Loading
52.8 KB
Loading
57.4 KB
Loading
136 KB
Loading
137 KB
Loading
303 KB
Loading
89.6 KB
Loading
37.1 KB
Loading

0 commit comments

Comments
 (0)