Skip to content

About

Forked repo from PostWarTacos

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Deploy-LabArtifacts

A PowerShell toolkit for automated deployment and management of cybersecurity training lab environments. This repository provides scripts to set up realistic insider threat scenarios for forensic investigation exercises.

πŸ“‹ Overview

This toolkit automates the complete lifecycle of cybersecurity lab environments:

  1. Enable PowerShell Remoting on target computers
  2. Deploy realistic attack artifacts simulating insider threat scenarios
  3. Clean up artifacts after training exercises

Perfect for instructors setting up training labs with multiple student workstations.

πŸš€ Scripts Included

1. Deploy-Lab-Combined.ps1

Complete automated lab deployment workflow

Combines remoting setup and artifact deployment into a single streamlined process. Handles multiple targets simultaneously with comprehensive error handling.

Key Features:

  • Automated PowerShell Remoting setup using PsExec
  • Deploys realistic insider threat scenarios
  • Flexible target input (parameter, pipeline, or file dialog)
  • Customizable attack scenarios and timestamps
  • Progress tracking and detailed reporting

πŸ“– Full Documentation

2. Enable-Remoting-v2.ps1

Standalone PowerShell Remoting enablement

Enables WinRM/PowerShell Remoting on remote Windows hosts using PsExec with interactive file selection.

Key Features:

  • Interactive file selection for target lists
  • Automated TrustedHosts configuration
  • Automatic PsExec detection
  • Default training environment credentials

πŸ“– Full Documentation

3. Undo-Events.ps1

Comprehensive artifact cleanup

Safely removes all artifacts created by deployment scripts, supporting both local and remote cleanup operations.

Key Features:

  • Removes user accounts, profiles, and group memberships
  • Deletes firewall rules and suspicious files
  • Cleans up event log sources
  • Optional audit policy reset
  • Safe operation with -WhatIf support

πŸ“– Full Documentation

πŸ“¦ Quick Start

Prerequisites

Basic Usage

# 1. Deploy to multiple computers (interactive file selection)
.\Deploy-Lab-Combined.ps1

# 2. Deploy to specific targets
.\Deploy-Lab-Combined.ps1 -Targets "PC01", "PC02", "PC03"

# 3. Clean up after exercises
.\Undo-Events.ps1 -ComputerName "PC01"

Typical Workflow

# Step 1: Create targets file (targets.txt) in the same directory as script (.\Deploy-Lab-Combined.ps1)
# PC-LAB-01 or full IP address
# PC-LAB-02 or full IP address
# PC-LAB-03 or full IP address

# Step 2: Oper PowerShell and navigate to that directory in PowerShell
cd [FULL PATH TO FOLDER WHERE SCRIPT IS]
# Example: cd C:\users\student\documents\Deploy-Lab-Combined.ps1 

# Step 2: Deploy to all targets
.\Deploy-Lab-Combined.ps1 -TargetsFile "targets.txt" 
# or if same artifacts will be used for every student
.\Deploy-Lab-Combined.ps1 -TargetsFile "targets.txt" -ArtifactReuse

# Step 3: Conduct training exercises
# Students investigate the deployed artifacts

πŸ“š Detailed Documentation

Deploy-Lab-Combined.ps1 Documentation

Parameters

Target Selection:

  • -Targets (string[]): Array of computer names or IP addresses
  • -TargetsFile (string): Path to text file with targets (one per line)

Authentication:

  • -User (string): Username (default: student)
  • -Password (string): Password (default: Training1)

Artifact Configuration:

  • -TimeBase (datetime): Starting timestamp for attack timeline (default: 24 hours ago)
  • -ImpersonateUser (string): Attacker username (default: Marcus.Thompson)
  • -TargetUser (string): Backdoor account name (default: JMartinez.Backup)
  • -RuleName (string): Firewall rule name (default: Windows-System-Update-Service)
  • -ExeName (string): Malicious executable name (default: WindowsUpdateManager.exe)
  • -FirewallPort (int): TCP port for backdoor (default: 0 = auto-generate)

Options:

  • -ArtifactReuse (switch): Consistent artifacts across executions
  • -SkipRemoting (switch): Skip remoting configuration

Usage Examples

# Custom credentials
.\Deploy-Lab-Combined.ps1 -Targets "PC01","PC02" -User "Administrator" -Password "P@ssw0rd!"

# Custom scenario configuration
.\Deploy-Lab-Combined.ps1 -Targets "Lab01","Lab02","Lab03" `
    -ImpersonateUser "John.Smith" `
    -TargetUser "Admin.Backup" `
    -RuleName "System-Service" `
    -TimeBase (Get-Date).AddHours(-12)

# Variable reuse for consistent labs
.\Deploy-Lab-Combined.ps1 -Targets "PC01","PC02","PC03" -ArtifactReuse

# Skip remoting (already configured)
.\Deploy-Lab-Combined.ps1 -Targets "PC01","PC02" -SkipRemoting

What Gets Deployed

The script creates a realistic insider threat scenario including:

Security Event Logs:

  • Event ID 4624: Successful logon events
  • Event ID 4720: User account creation
  • Event ID 4732: Group membership changes (Administrator group)
  • Event ID 4656/4663: File access attempts
  • Event ID 4688: Process creation (malicious executable)

Application Event Logs:

  • Remote Desktop connection events
  • Simulated RDP access patterns

System Changes:

  • Backdoor user account with administrative privileges
  • Persistent firewall rules for network access
  • Suspicious executable in temp directory
  • Modified audit policies for detailed logging

Workflow

Start
  β”‚
  β”œβ”€β–Ί Parse Parameters / Pipeline Input / File Dialog
  β”‚
  β”œβ”€β–Ί Configure TrustedHosts for WinRM
  β”‚
  β”œβ”€β–Ί Locate PsExec.exe
  β”‚
  └─► For Each Target:
        β”‚
        β”œβ”€β–Ί [Optional] Enable PS Remoting via PsExec
        β”‚     β”‚
        β”‚     β”œβ”€β–Ί Success β†’ Continue to Deployment
        β”‚     └─► Failure β†’ Skip Target
        β”‚
        β”œβ”€β–Ί Test WinRM Connectivity
        β”‚
        β”œβ”€β–Ί Execute Deployment via Invoke-Command
        β”‚     (All artifact creation runs remotely)
        β”‚
        └─► Report Success/Failure

Enable-Remoting-v2.ps1 Documentation

Features

  • Interactive file selection dialog for target lists
  • Automated TrustedHosts configuration (Set-Item WSMan:\localhost\Client\TrustedHosts -Value "*")
  • Uses PsExec for reliable remote enabling of PowerShell Remoting
  • Automatic PsExec location detection

Default Credentials

  • Username: student
  • Password: Training1

⚠️ Note: Credentials are hardcoded. Modify for production use.

Usage

# Run with file dialog (will prompt to select targets file)
.\Enable-Remoting-v2.ps1

What It Does

  1. Displays file selection dialog for targets file
  2. Configures WinRM TrustedHosts to allow all connections
  3. Locates PsExec.exe in common directories
  4. For each target:
    • Uses PsExec to remotely execute Enable-PSRemoting -Force
    • Executes with elevated privileges (-h flag)
    • Uses provided credentials for authentication

Undo-Events.ps1 Documentation

Parameters

  • -TargetUser (string): User account to remove (default: JMartinez.Backup)
  • -ruleName (string): Firewall rule to remove (default: Windows-System-Update-Service)
  • -exeName (string): Executable to remove (default: WindowsUpdateManager.exe)
  • -ComputerName (string): Remote computer to clean (empty = local)
  • -Credential (PSCredential): Credentials for remote connection
  • -KeepAuditPolicies (switch): Keep audit policies enabled
  • -WhatIf (switch): Preview changes without executing

What Gets Cleaned Up

User Accounts & Profiles:

  • Removes created local user
  • Removes user from Administrators group
  • Deletes user profile directory (C:\Users\[username])

Firewall Rules:

  • Removes created firewall rules

Files & Executables:

  • Removes malicious executable from temp directory
  • Cleans up temporary batch files
  • Removes temporary XML event files
  • Stops running processes

Event Log Sources:

  • Removes custom sources: SimLabGenerator, Security-Simulation, AdminActivity

Audit Policies:

  • Optionally resets to default (disabled) state

Usage Examples

# Local cleanup
.\Undo-Events.ps1

# Preview without changes
.\Undo-Events.ps1 -WhatIf

# Keep audit policies enabled
.\Undo-Events.ps1 -KeepAuditPolicies

# Remote cleanup
$cred = Get-Credential
.\Undo-Events.ps1 -ComputerName "RemotePC01" -Credential $cred

# Custom parameters
.\Undo-Events.ps1 -TargetUser "CustomUser" -ruleName "CustomRule" -exeName "CustomApp.exe"

Important Notes

  • Administrator rights required for local cleanup
  • Log events cannot be removed programmatically (remain until log rotation)
  • Event source removal requires system restart to fully take effect
  • Safe to run multiple times (skips non-existent items)

πŸ”§ Troubleshooting

PsExec Not Found

Error: "psexec.exe not found"

Solution:

  1. Download from Microsoft Sysinternals
  2. Place in script directory or common location
  3. Verify file is not blocked: Right-click β†’ Properties β†’ Unblock

Remoting Fails on Target

Symptom: Target skipped, deployment not attempted

Solutions:

  • Verify network connectivity: Test-Connection -ComputerName <target>
  • Ensure RPC/SMB ports accessible (135, 445)
  • Check credentials have administrative rights
  • Verify Windows Firewall allows remote management
  • Confirm target computer is online

TrustedHosts Error

Error: WinRM authentication errors

Solutions:

  • Script sets TrustedHosts to * automatically
  • Manual fix: Set-Item WSMan:\localhost\Client\TrustedHosts -Value "*" -Force
  • Production restriction: Set-Item WSMan:\localhost\Client\TrustedHosts -Value "PC01,PC02" -Force

Authentication Failures

Symptom: Access denied errors

Solutions:

  • Verify username/password are correct
  • Ensure account has local administrator rights
  • Use domain credentials for domain environments
  • Check account is not locked out

Remote Cleanup Issues

Symptom: Undo-Events.ps1 fails on remote computer

Solutions:

  1. Verify PowerShell Remoting: Test-WSMan -ComputerName <target>
  2. Ensure administrative privileges on target
  3. Check network connectivity and WinRM ports (5985/5986)
  4. Verify WinRM service is running on target
  5. Use -Credential parameter with valid credentials

πŸ”’ Security Considerations

⚠️ LAB ENVIRONMENT ONLY

WARNING: These scripts are designed for isolated training environments only.

Security concerns intentionally introduced for training:

  • Sets TrustedHosts to * (all hosts)
  • Stores credentials in plain text
  • Opens firewall rules
  • Creates administrative backdoor accounts
  • Modifies audit policies

DO NOT USE IN PRODUCTION

If adapting for production environments:

  • Use secure credential management (Get-Credential, vaults)
  • Restrict TrustedHosts to specific computers
  • Implement proper logging and auditing
  • Use Kerberos/domain authentication
  • Follow least privilege principles
  • Use Group Policy for WinRM configuration

Network Isolation

  • Ensure lab network is completely isolated from production
  • Use appropriate network segmentation
  • Implement proper access controls
  • Monitor for unauthorized access

πŸ“ Targets File Format

Create a plain text file with one computer name or IP address per line:

PC-LAB-01
PC-LAB-02
PC-LAB-03
192.168.1.100
192.168.1.101
STUDENT-WS-01

Comments and blank lines are ignored.

🎯 Best Practices

  1. Test First: Verify script works on single target before batch deployment
  2. Consistent Timestamps: Use -TimeBase parameter for realistic timeline
  3. Document Scenarios: Keep track of custom parameters for each session
  4. Verify Prerequisites: Ensure all targets meet requirements
  5. Monitor Progress: Watch output for errors during deployment
  6. Always Clean Up: Run Undo-Events.ps1 after exercises complete
  7. Network Isolation: Keep training labs on isolated networks
  8. Backup Systems: Always have backups of important systems

πŸ“Š Example Output

[INIT] Loading targets from file dialog...
[INIT] Found 3 target computer(s)
[INIT] Configuring TrustedHosts for WinRM...
[INIT] TrustedHosts set to * (all hosts)
[INIT] Locating PsExec.exe...
[INIT] Found psexec.exe at: C:\Tools\psexec.exe

[REMOTING] Enabling PS Remoting on PC01...
[REMOTING] Successfully enabled PS Remoting on PC01
[DEPLOY] Deploying lab artifacts to PC01...
[DEPLOY] Successfully deployed artifacts to PC01

[REMOTING] Enabling PS Remoting on PC02... 
[REMOTING] Successfully enabled PS Remoting on PC02
[DEPLOY] Deploying lab artifacts to PC02...
[DEPLOY] Successfully deployed artifacts to PC02

[REMOTING] Enabling PS Remoting on PC03... 
WARNING: [REMOTING] Failed to enable PS Remoting on PC03 (Exit Code: 1)
[DEPLOY] Skipping PC03 - remoting not available

═══════════════════════════════════════════════════════════════
                    DEPLOYMENT SUMMARY
═══════════════════════════════════════════════════════════════
Total Targets:         3
Successful:            2
Failed:               0
Skipped (No Remote):  1
═══════════════════════════════════════════════════════════════

πŸ“„ Files in This Repository

  • Deploy-Lab-Combined.ps1 - Main deployment script (combined workflow)
  • Deploy-LabArtifacts.ps1 - Artifact generation script (called remotely)
  • Enable-Remoting-v2.ps1 - Standalone remoting setup script
  • Undo-Events.ps1 - Cleanup script
  • Insider-Threat-Intel-Brief.pptx - PowerPoint template for student briefs
  • README.md - This file

πŸ†˜ Support

For issues or questions:

  1. Check troubleshooting section above
  2. Verify all prerequisites are met
  3. Test connectivity to target computers manually
  4. Review PowerShell error messages carefully
  5. Test with single target before batch deployment

πŸ“œ License

MIT License - see the LICENSE file for details.

πŸ“… Version History

  • v2.0 (2025-12-15): Combined deployment workflow with enhanced error handling
  • v1.x: Initial standalone scripts

πŸ™ Acknowledgments

  • Microsoft Sysinternals for PsExec
  • PowerShell community for best practices and patterns

Remember: This toolkit is for educational purposes in isolated lab environments only. Always ensure proper network isolation and never use in production environments.

About

Forked repo from PostWarTacos

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages