Cyberlium

Red › Module 10 › Lesson 1

BeginnerModule 10Lesson 1/5

Checklist

One-page Topic 21 capstone checklist — RoE, persistence, lateral, purple, report on $LAB_RT.

15 min+40 XP3 quiz
Module progress1 of 5

Visual · t21_capstone_checklist

Checklist consolidates red-team pillars. Original Cyberlium.

Opening

Capstone proves disciplined emulation on hosts blue authorized — not a montage of stranger pivots.

Assemble checklist covering Modules 1–9: RT mindset and written RoE ($LAB_RT only), ATT&CK and emulation plan literacy, initial access and C2 within brief, persistence and LOLBin literacy with teardown, lateral hops inside VLAN, exfil synthetic-only boundaries, purple detections map and loop, report with ATT&CK and remediation, evasion-vs-crime refusal signed. Use on capstone walk of YOUR $LAB_RT engagement — never stranger domains, cred dump cookbooks, real PII exfil, or cover-tracks. Notes chmod 600 under $HOME/cyberlium-lab. Each row links artifact or honest N/A.

1. Scope and RoE

$LAB_RT named with written RoE. NEVER stranger AD, cred dumps, real PII exfil, anti-forensics.

Time box, teardown, and purple collaboration acknowledged in header.

Command guide

Try these commands — Scope and RoE

═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)

Capstone checklist — https://attack.mitre.org/resources/adversary-emulation-plans/ RoE — https://www.cisa.gov/resources-tools/resources/red-team-exercises Atomic Red Team — https://redcanary.com/atomic-red-team/ (YOUR lab validation only)

═══ INSTALL ═══

Linux (Debian/Ubuntu):

Command — copy this

sudo apt install curl

macOS: Built-in

Windows: Built-in (PowerShell: Invoke-WebRequest)

═══ LINUX / macOS ═══

Command — copy this

ls -la "$HOME/cyberlium-lab/t21-rt/" 2>/dev/null
grep -h . "$HOME/cyberlium-lab/t21-rt/roe.txt" "$HOME/cyberlium-lab/t21-rt/success-criteria.txt" 2>/dev/null | head -12
curl -sS -o /dev/null -w "ATT&CK %{http_code}
" https://attack.mitre.org/

Primary tools to practice this lesson: grep, curl. Reference sites: Capstone checklist (https://attack.mitre.org/resources/adversary-emulation-plans/); RoE (https://www.cisa.gov/resources-tools/resources/red-team-exercises); Atomic Red Team (https://redcanary.com/atomic-red-team/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.

2. Red-team pillars

Emulation plan, persist/lateral labs, detections map, purple handoff, report + remediation — each row linked.

Integrity: synthetic data only, mandatory persistence teardown.

3. Purple and legal lines

Purple improves detections — not red hiding from blue.

Teardown: revoke lab creds, revert snapshots, secure evidence pack.

4. What you ship: Topic 21 capstone checklist

One-page red-team checklist for $LAB_RT engagement path.

5. What you record before the next lesson

Checklist file path.

6. Wrong vs right: stranger phishing vs authorized RT lab

Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.

  • Wrong

    Use checklist to justify cred dumps on stranger domain.

  • Right

    Checklist written. Next: Lab Path.

Mission: write red-team capstone checklist

1) RoE/scope section. 2) Persist through report pillars. 3) Purple integrity and teardown section.

Stuck? Ask Cyberlium AI Mentor

Ask Mentor: “Top five capstone artifacts?”

Knowledge Check

1

APPLY: Checklist includes:

Multiple choice

Knowledge Check

2

APPLY: True or False: Checklist authorizes unauthorized AD abuse.

True or False

Knowledge Check

3

APPLY: Teardown includes:

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)