You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: IntroClassFiles/Tools/IntroClass/LCmeetsAtomicRed/LCAR.md
+21-10Lines changed: 21 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,38 +12,49 @@ We need to install the plugin for Atomic Red that Lima Charlie offers.
12
12
13
13
Start by navigating to the "Add-ons" tab in the top right of the web page.
14
14
15
-
<imgsrc="attachments/ADDONS.PNG"alt="register an account"width="300" />
15
+

16
16
17
17
Scroll down until you see the Atomic Red plugin. Click the Atomic Red plugin.
18
18
19
-
<imgsrc="attachments/AR.PNG"alt="register an account"width="300" />
20
-
19
+

21
20
Take a minute to look at the different plugins and see the full capabillities and features Lima Charlie has to offer.
22
21
23
22
Then locate the subscribe button on the right side of the page, and click "Subscribe"
24
23
25
-
<imgsrc="attachments/SUBSCRIBE.PNG"alt="register an account"width="300" />
24
+

26
25
27
26
After Atomic Red finishes installing return back to your organization and click on your machine.
28
27
29
-
<imgsrc="attachments/HOST.PNG"alt="register an account"width="300" />
28
+

29
+
30
+

31
+
32
+
On the left side of your screen, click on "Extensions" to expand the dropdown menu. Select Atomic Red Team.
33
+
34
+

30
35
31
-
Scroll down and you will see a few options, yara and atomic red. Click "Run atomic tests"
36
+
On the next screen, we need to first click on the dropdown next to the Sid bar at the top. Then, select your device.
32
37
33
-
<imgsrc="attachments/RUNAR.PNG"alt="register an account"width="300" />
38
+

34
39
35
-
Go to the commandandcontroland click "(1)Select Category" then click "(2)Run Tests"
40
+
Next, scroll down until you find the `command-and-control` category. Select the box next to the category header and make sure that it selects all of the boxes below.
36
41
37
-
<imgsrc="attachments/C2ALL.PNG"alt="register an account"width="300" />
42
+
Now, hit `Run Tests`
43
+
44
+

38
45
39
46
Then move over to the "Detections" tab on the left and start going through event logs
40
47
41
-
<imgsrc="attachments/DETECTED.PNG"alt="register an account"width="700" />
48
+

49
+
50
+

42
51
43
52
There will be a lot of events, everytime the page is refreshed more attacks will appear.
44
53
45
54
Looking through all of the logs and note the cmd.exe or powershell invokes are taking place. These are (usually) indications of something malicious occuring and needs to be examined further.
46
55
56
+

57
+
47
58
Lima Charlie is an amazing tool because of its versatillity. With an easy to look at interface that if need be, allows a user to dig deeper to see whats happening before, during, and after an attack. Its abillity to be used on small and large scale is a great feature.
48
59
49
60
Many plugins allow for different uses large and small, and automating the difficult tasks.
0 commit comments