Red › Module 10 › Lesson 1
Checklist
One-page Topic 21 capstone checklist — RoE, persistence, lateral, purple, report on $LAB_RT.
Visual · t21_capstone_checklist
Checklist consolidates red-team pillars. Original Cyberlium.
Opening
Capstone proves disciplined emulation on hosts blue authorized — not a montage of stranger pivots.
Assemble checklist covering Modules 1–9: RT mindset and written RoE ($LAB_RT only), ATT&CK and emulation plan literacy, initial access and C2 within brief, persistence and LOLBin literacy with teardown, lateral hops inside VLAN, exfil synthetic-only boundaries, purple detections map and loop, report with ATT&CK and remediation, evasion-vs-crime refusal signed. Use on capstone walk of YOUR $LAB_RT engagement — never stranger domains, cred dump cookbooks, real PII exfil, or cover-tracks. Notes chmod 600 under $HOME/cyberlium-lab. Each row links artifact or honest N/A.
1. Scope and RoE
$LAB_RT named with written RoE. NEVER stranger AD, cred dumps, real PII exfil, anti-forensics.
Time box, teardown, and purple collaboration acknowledged in header.
Command guide
Try these commands — Scope and RoE
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
Capstone checklist — https://attack.mitre.org/resources/adversary-emulation-plans/ RoE — https://www.cisa.gov/resources-tools/resources/red-team-exercises Atomic Red Team — https://redcanary.com/atomic-red-team/ (YOUR lab validation only)
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
ls -la "$HOME/cyberlium-lab/t21-rt/" 2>/dev/null
grep -h . "$HOME/cyberlium-lab/t21-rt/roe.txt" "$HOME/cyberlium-lab/t21-rt/success-criteria.txt" 2>/dev/null | head -12
curl -sS -o /dev/null -w "ATT&CK %{http_code}
" https://attack.mitre.org/Primary tools to practice this lesson: grep, curl. Reference sites: Capstone checklist (https://attack.mitre.org/resources/adversary-emulation-plans/); RoE (https://www.cisa.gov/resources-tools/resources/red-team-exercises); Atomic Red Team (https://redcanary.com/atomic-red-team/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Red-team pillars
Emulation plan, persist/lateral labs, detections map, purple handoff, report + remediation — each row linked.
Integrity: synthetic data only, mandatory persistence teardown.
3. Purple and legal lines
Purple improves detections — not red hiding from blue.
Teardown: revoke lab creds, revert snapshots, secure evidence pack.
4. What you ship: Topic 21 capstone checklist
One-page red-team checklist for $LAB_RT engagement path.
5. What you record before the next lesson
Checklist file path.
6. Wrong vs right: stranger phishing vs authorized RT lab
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Use checklist to justify cred dumps on stranger domain.
Right
Checklist written. Next: Lab Path.
Mission: write red-team capstone checklist
1) RoE/scope section. 2) Persist through report pillars. 3) Purple integrity and teardown section.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Top five capstone artifacts?”
Knowledge Check
APPLY: Checklist includes:
Multiple choice
Knowledge Check
APPLY: True or False: Checklist authorizes unauthorized AD abuse.
True or False
Knowledge Check
APPLY: Teardown includes:
Multiple choice