Red › Module 5 › Lesson 3
Lab C2 Only
C2 runs only on $LAB_RT under written RoE — isolated listeners, snapshot revert, no production or classmate callbacks.
Visual · rt_lab_c2_only
Lab C2 only — hard boundary. $LAB_RT only. Original Cyberlium.
Opening
If the callback is not $LAB_RT per RoE, the listener does not go up.
Lab C2 means: framework approved in RoE, listener on lab segment IP, agents only on lab VMs you snapshot, egress blocked to stranger networks, campaign stop time enforced, and blue notified. Real C2 against production, classmates, or purchased CS cracks is explicitly out of Cyberlium scope. This lesson is the hard boundary before any optional lab exercise. Next: C2 Lab.
1. Lab C2 checklist before listener start
RoE names framework and $LAB_RT IP plan. Snapshot lab VMs. Firewall: deny lab egress except allowlisted lab C2 IP. Blue has detection rules staged. Stop time and kill switch documented.
No checklist item substitutes for written RoE — verbal 'it's fine' is not authorization.
Command guide
Try these commands — Lab C2 checklist before listener start
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
Lab C2 only — https://docs.mythic-c2.net/ (isolated lab callbacks) Sliver wiki — https://github.com/BishopFox/sliver/wiki (never aim at production/strangers) CISA red team — https://www.cisa.gov/resources-tools/resources/red-team-exercises
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
curl -sS https://docs.mythic-c2.net/ | head -8 curl -sS https://github.com/BishopFox/sliver/wiki | head -5 grep -iE 'never|refuse|production' "$HOME/cyberlium-lab/t21-rt/roe.txt" "$HOME/cyberlium-lab/t21-rt/success-criteria.txt" 2>/dev/null | head -5
Primary tools to practice this lesson: curl, grep. Reference sites: Lab C2 only (https://docs.mythic-c2.net/); Sliver wiki (https://github.com/BishopFox/sliver/wiki); CISA red team (https://www.cisa.gov/resources-tools/resources/red-team-exercises). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. What lab C2 is not
Not: beacon on employer laptop, CS crack against campus Wi-Fi, C2 through classmate project, persistent callback to home ISP from non-lab host. Not ransomware staging on any non-$LAB_RT asset.
Detection literacy can be paper-only if infra unavailable — still no stranger C2.
3. Revert and evidence for purple debrief
After lab C2 exercise: capture SIEM screenshots, revert snapshots, archive beacon profile and detection outcome in chmod 600 pack. Gaps feed Module 8 purple content later.
Ship: lab C2 checklist for $LAB_RT — ten lines. Next: C2 Lab.
4. What you ship: lab C2 only checklist for $LAB_RT
Ten-line checklist: RoE, snapshot, listener IP, egress deny, blue notify, stop time. $LAB_RT only. chmod 600.
5. What you record before the next lesson
Date. Lab C2 checklist. $LAB_RT named. File t21-m05-l03-lab-c2-only.txt chmod 600.
6. Wrong vs right: stranger phishing vs authorized RT lab
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Skip snapshot and beacon production ' briefly.' Use CS crack because 'lab is expensive.'
Right
Write lab C2 only checklist for $LAB_RT. Next: C2 Lab.
Mission: freeze lab C2 boundary checklist
1) Write ten-line lab C2 checklist for $LAB_RT. 2) Include NEVER production/classmate lines. 3) chmod 600. Never start listener without RoE checklist complete.
Stuck? Ask Cyberlium AI Mentor
Kill switch and stop time are part of professional RoE — write them.
Knowledge Check
APPLY: Lab C2 only on Cyberlium means:
Multiple choice
Knowledge Check
APPLY: True or False: Snapshot before lab C2 is recommended.
True or False
Knowledge Check
APPLY: Lab egress during C2 exercise should:
Multiple choice