Part 1 - Setting Up the Environment
Designed for SOC analysts, it simulates real-world cybersecurity scenarios using LimaCharlie, Sysmon, C2 Framework(sliver-server),
Prerequisites
Step 1: Install Ubuntu Server VM
Step 2: Set Up Windows 10 Machine
Disable Microsoft Defender Permanently
Install Sysmon on Windows VM
Step 1: Open PowerShell as Administrator
Step 2: Download Sysmon
Step 3: Extract Sysmon
Step 4: Download Sysmon Configuration File (Optional)
Step 5: Install Sysmon
Install with Custom Configuration (Recommended)
Install Without Configuration
Step 6: Verify Installation
Check if Sysmon Service is Running
Check Sysmon Event Logs


Install LimaCharlie EDR on Windows VM
Step 1: Create a LimaCharlie Account
Step 2: Add a Sensor

Step 3: Install LimaCha
Install LimaCharlie Agent on Windows VM
Step 4: Integrate Sysmon Logs to LimaCharlie
Step 5: Snapshot Your Windows VM
Setting Up the Attack System
What You Need
Connect to Ubuntu VM
Get Admin Access
Install Sliver C2 Server
Create a Sliver Folder
What’s Next?
Last updated






