A PowerShell toolkit for automated deployment and management of cybersecurity training lab environments. This repository provides scripts to set up realistic insider threat scenarios for forensic investigation exercises.
This toolkit automates the complete lifecycle of cybersecurity lab environments:
- Enable PowerShell Remoting on target computers
- Deploy realistic attack artifacts simulating insider threat scenarios
- Clean up artifacts after training exercises
Perfect for instructors setting up training labs with multiple student workstations.
Complete automated lab deployment workflow
Combines remoting setup and artifact deployment into a single streamlined process. Handles multiple targets simultaneously with comprehensive error handling.
Key Features:
- Automated PowerShell Remoting setup using PsExec
- Deploys realistic insider threat scenarios
- Flexible target input (parameter, pipeline, or file dialog)
- Customizable attack scenarios and timestamps
- Progress tracking and detailed reporting
Standalone PowerShell Remoting enablement
Enables WinRM/PowerShell Remoting on remote Windows hosts using PsExec with interactive file selection.
Key Features:
- Interactive file selection for target lists
- Automated TrustedHosts configuration
- Automatic PsExec detection
- Default training environment credentials
Comprehensive artifact cleanup
Safely removes all artifacts created by deployment scripts, supporting both local and remote cleanup operations.
Key Features:
- Removes user accounts, profiles, and group memberships
- Deletes firewall rules and suspicious files
- Cleans up event log sources
- Optional audit policy reset
- Safe operation with
-WhatIfsupport
- Windows 10/11 or Windows Server
- PowerShell 5.0 or higher
- Administrator privileges
- PsExec.exe (Download from Microsoft Sysinternals)
- Network connectivity to target computers
# 1. Deploy to multiple computers (interactive file selection)
.\Deploy-Lab-Combined.ps1
# 2. Deploy to specific targets
.\Deploy-Lab-Combined.ps1 -Targets "PC01", "PC02", "PC03"
# 3. Clean up after exercises
.\Undo-Events.ps1 -ComputerName "PC01"# Step 1: Create targets file (targets.txt) in the same directory as script (.\Deploy-Lab-Combined.ps1)
# PC-LAB-01 or full IP address
# PC-LAB-02 or full IP address
# PC-LAB-03 or full IP address
# Step 2: Oper PowerShell and navigate to that directory in PowerShell
cd [FULL PATH TO FOLDER WHERE SCRIPT IS]
# Example: cd C:\users\student\documents\Deploy-Lab-Combined.ps1
# Step 2: Deploy to all targets
.\Deploy-Lab-Combined.ps1 -TargetsFile "targets.txt"
# or if same artifacts will be used for every student
.\Deploy-Lab-Combined.ps1 -TargetsFile "targets.txt" -ArtifactReuse
# Step 3: Conduct training exercises
# Students investigate the deployed artifactsTarget Selection:
-Targets(string[]): Array of computer names or IP addresses-TargetsFile(string): Path to text file with targets (one per line)
Authentication:
-User(string): Username (default:student)-Password(string): Password (default:Training1)
Artifact Configuration:
-TimeBase(datetime): Starting timestamp for attack timeline (default: 24 hours ago)-ImpersonateUser(string): Attacker username (default:Marcus.Thompson)-TargetUser(string): Backdoor account name (default:JMartinez.Backup)-RuleName(string): Firewall rule name (default:Windows-System-Update-Service)-ExeName(string): Malicious executable name (default:WindowsUpdateManager.exe)-FirewallPort(int): TCP port for backdoor (default: 0 = auto-generate)
Options:
-ArtifactReuse(switch): Consistent artifacts across executions-SkipRemoting(switch): Skip remoting configuration
# Custom credentials
.\Deploy-Lab-Combined.ps1 -Targets "PC01","PC02" -User "Administrator" -Password "P@ssw0rd!"
# Custom scenario configuration
.\Deploy-Lab-Combined.ps1 -Targets "Lab01","Lab02","Lab03" `
-ImpersonateUser "John.Smith" `
-TargetUser "Admin.Backup" `
-RuleName "System-Service" `
-TimeBase (Get-Date).AddHours(-12)
# Variable reuse for consistent labs
.\Deploy-Lab-Combined.ps1 -Targets "PC01","PC02","PC03" -ArtifactReuse
# Skip remoting (already configured)
.\Deploy-Lab-Combined.ps1 -Targets "PC01","PC02" -SkipRemotingThe script creates a realistic insider threat scenario including:
Security Event Logs:
- Event ID 4624: Successful logon events
- Event ID 4720: User account creation
- Event ID 4732: Group membership changes (Administrator group)
- Event ID 4656/4663: File access attempts
- Event ID 4688: Process creation (malicious executable)
Application Event Logs:
- Remote Desktop connection events
- Simulated RDP access patterns
System Changes:
- Backdoor user account with administrative privileges
- Persistent firewall rules for network access
- Suspicious executable in temp directory
- Modified audit policies for detailed logging
Start
β
βββΊ Parse Parameters / Pipeline Input / File Dialog
β
βββΊ Configure TrustedHosts for WinRM
β
βββΊ Locate PsExec.exe
β
βββΊ For Each Target:
β
βββΊ [Optional] Enable PS Remoting via PsExec
β β
β βββΊ Success β Continue to Deployment
β βββΊ Failure β Skip Target
β
βββΊ Test WinRM Connectivity
β
βββΊ Execute Deployment via Invoke-Command
β (All artifact creation runs remotely)
β
βββΊ Report Success/Failure
- Interactive file selection dialog for target lists
- Automated TrustedHosts configuration (
Set-Item WSMan:\localhost\Client\TrustedHosts -Value "*") - Uses PsExec for reliable remote enabling of PowerShell Remoting
- Automatic PsExec location detection
- Username:
student - Password:
Training1
β οΈ Note: Credentials are hardcoded. Modify for production use.
# Run with file dialog (will prompt to select targets file)
.\Enable-Remoting-v2.ps1- Displays file selection dialog for targets file
- Configures WinRM TrustedHosts to allow all connections
- Locates PsExec.exe in common directories
- For each target:
- Uses PsExec to remotely execute
Enable-PSRemoting -Force - Executes with elevated privileges (
-hflag) - Uses provided credentials for authentication
- Uses PsExec to remotely execute
-TargetUser(string): User account to remove (default:JMartinez.Backup)-ruleName(string): Firewall rule to remove (default:Windows-System-Update-Service)-exeName(string): Executable to remove (default:WindowsUpdateManager.exe)-ComputerName(string): Remote computer to clean (empty = local)-Credential(PSCredential): Credentials for remote connection-KeepAuditPolicies(switch): Keep audit policies enabled-WhatIf(switch): Preview changes without executing
User Accounts & Profiles:
- Removes created local user
- Removes user from Administrators group
- Deletes user profile directory (
C:\Users\[username])
Firewall Rules:
- Removes created firewall rules
Files & Executables:
- Removes malicious executable from temp directory
- Cleans up temporary batch files
- Removes temporary XML event files
- Stops running processes
Event Log Sources:
- Removes custom sources:
SimLabGenerator,Security-Simulation,AdminActivity
Audit Policies:
- Optionally resets to default (disabled) state
# Local cleanup
.\Undo-Events.ps1
# Preview without changes
.\Undo-Events.ps1 -WhatIf
# Keep audit policies enabled
.\Undo-Events.ps1 -KeepAuditPolicies
# Remote cleanup
$cred = Get-Credential
.\Undo-Events.ps1 -ComputerName "RemotePC01" -Credential $cred
# Custom parameters
.\Undo-Events.ps1 -TargetUser "CustomUser" -ruleName "CustomRule" -exeName "CustomApp.exe"- Administrator rights required for local cleanup
- Log events cannot be removed programmatically (remain until log rotation)
- Event source removal requires system restart to fully take effect
- Safe to run multiple times (skips non-existent items)
Error: "psexec.exe not found"
Solution:
- Download from Microsoft Sysinternals
- Place in script directory or common location
- Verify file is not blocked: Right-click β Properties β Unblock
Symptom: Target skipped, deployment not attempted
Solutions:
- Verify network connectivity:
Test-Connection -ComputerName <target> - Ensure RPC/SMB ports accessible (135, 445)
- Check credentials have administrative rights
- Verify Windows Firewall allows remote management
- Confirm target computer is online
Error: WinRM authentication errors
Solutions:
- Script sets TrustedHosts to
*automatically - Manual fix:
Set-Item WSMan:\localhost\Client\TrustedHosts -Value "*" -Force - Production restriction:
Set-Item WSMan:\localhost\Client\TrustedHosts -Value "PC01,PC02" -Force
Symptom: Access denied errors
Solutions:
- Verify username/password are correct
- Ensure account has local administrator rights
- Use domain credentials for domain environments
- Check account is not locked out
Symptom: Undo-Events.ps1 fails on remote computer
Solutions:
- Verify PowerShell Remoting:
Test-WSMan -ComputerName <target> - Ensure administrative privileges on target
- Check network connectivity and WinRM ports (5985/5986)
- Verify WinRM service is running on target
- Use
-Credentialparameter with valid credentials
WARNING: These scripts are designed for isolated training environments only.
Security concerns intentionally introduced for training:
- Sets TrustedHosts to
*(all hosts) - Stores credentials in plain text
- Opens firewall rules
- Creates administrative backdoor accounts
- Modifies audit policies
If adapting for production environments:
- Use secure credential management (
Get-Credential, vaults) - Restrict TrustedHosts to specific computers
- Implement proper logging and auditing
- Use Kerberos/domain authentication
- Follow least privilege principles
- Use Group Policy for WinRM configuration
- Ensure lab network is completely isolated from production
- Use appropriate network segmentation
- Implement proper access controls
- Monitor for unauthorized access
Create a plain text file with one computer name or IP address per line:
PC-LAB-01
PC-LAB-02
PC-LAB-03
192.168.1.100
192.168.1.101
STUDENT-WS-01
Comments and blank lines are ignored.
- Test First: Verify script works on single target before batch deployment
- Consistent Timestamps: Use
-TimeBaseparameter for realistic timeline - Document Scenarios: Keep track of custom parameters for each session
- Verify Prerequisites: Ensure all targets meet requirements
- Monitor Progress: Watch output for errors during deployment
- Always Clean Up: Run Undo-Events.ps1 after exercises complete
- Network Isolation: Keep training labs on isolated networks
- Backup Systems: Always have backups of important systems
[INIT] Loading targets from file dialog...
[INIT] Found 3 target computer(s)
[INIT] Configuring TrustedHosts for WinRM...
[INIT] TrustedHosts set to * (all hosts)
[INIT] Locating PsExec.exe...
[INIT] Found psexec.exe at: C:\Tools\psexec.exe
[REMOTING] Enabling PS Remoting on PC01...
[REMOTING] Successfully enabled PS Remoting on PC01
[DEPLOY] Deploying lab artifacts to PC01...
[DEPLOY] Successfully deployed artifacts to PC01
[REMOTING] Enabling PS Remoting on PC02...
[REMOTING] Successfully enabled PS Remoting on PC02
[DEPLOY] Deploying lab artifacts to PC02...
[DEPLOY] Successfully deployed artifacts to PC02
[REMOTING] Enabling PS Remoting on PC03...
WARNING: [REMOTING] Failed to enable PS Remoting on PC03 (Exit Code: 1)
[DEPLOY] Skipping PC03 - remoting not available
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
DEPLOYMENT SUMMARY
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Total Targets: 3
Successful: 2
Failed: 0
Skipped (No Remote): 1
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
- Deploy-Lab-Combined.ps1 - Main deployment script (combined workflow)
- Deploy-LabArtifacts.ps1 - Artifact generation script (called remotely)
- Enable-Remoting-v2.ps1 - Standalone remoting setup script
- Undo-Events.ps1 - Cleanup script
- Insider-Threat-Intel-Brief.pptx - PowerPoint template for student briefs
- README.md - This file
For issues or questions:
- Check troubleshooting section above
- Verify all prerequisites are met
- Test connectivity to target computers manually
- Review PowerShell error messages carefully
- Test with single target before batch deployment
MIT License - see the LICENSE file for details.
- v2.0 (2025-12-15): Combined deployment workflow with enhanced error handling
- v1.x: Initial standalone scripts
- Microsoft Sysinternals for PsExec
- PowerShell community for best practices and patterns
Remember: This toolkit is for educational purposes in isolated lab environments only. Always ensure proper network isolation and never use in production environments.