Cyberlium

Red › Module 10 › Lesson 3

BeginnerModule 10Lesson 3/5

Evidence Pack

Bundle redacted red-team evidence from YOUR $LAB_RT — index, report, purple map, integrity statement.

15 min+40 XP3 quiz
Module progress3 of 5

Visual · t21_evidence_pack

Evidence pack = mentor handoff bundle from $LAB_RT engagement. Original Cyberlium.

Opening

One indexed pack with redactions beats a folder called shells_and_dumps_final.

Assemble evidence pack: RoE copy, lab path diagram, ATT&CK map, detections map, purple handoff, persist/lateral lab notes redacted, red-team report, remediation table, evasion-vs-crime refusal, integrity statement (no unauthorized targets, no real PII, no cover-tracks, synthetic exfil only). Single directory chmod 600 — index.md lists contents with UTC dates and redactions. Mentor copy redacts internal IPs if required. No stranger breach paste, no credential dump files, no anti-forensics tools. Gap paragraph: next purple cycle on same $LAB_RT bench.

1. Pack contents

Minimum: RoE, lab path, report, ATT&CK map, detections map, purple handoff, remediation, refusal lines, index.

Optional: emulation plan excerpt, debrief notes.

Command guide

Try these commands — Pack contents

═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)

Evidence pack — https://sigmahq.io/ (attach ss + journal captures) MITRE ATT&CK — https://attack.mitre.org/ (technique mapping in pack)

═══ INSTALL ═══

Linux (Debian/Ubuntu):

macOS:

Windows:

═══ LINUX / macOS ═══

Command — copy this

ls -la "$HOME/cyberlium-lab/t21-rt/"*evidence* "$HOME/cyberlium-lab/t21-rt/"*purple* "$HOME/cyberlium-lab/t21-rt/"*baseline* 2>/dev/null | head -10
journalctl --no-pager -n 20 2>/dev/null | tail -8
grep -hE 'T[0-9]{4}|detection|never' "$HOME/cyberlium-lab/t21-rt/"*.txt 2>/dev/null | head -12

Primary tools to practice this lesson: grep, journalctl. Reference sites: Evidence pack (https://sigmahq.io/); MITRE ATT&CK (https://attack.mitre.org/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.

2. Index fields

Artifact name, module lesson, path, UTC date, description, redactions applied.

Cross-link checklist row to index row.

3. Integrity

Statement: $LAB_RT only, synthetic data, persistence teardown completed, purple collaborative.

Secure pack — no public upload of raw logs with lab creds.

4. What you ship: red-team evidence pack

Bundled deliverables + index + integrity lines — chmod 600.

5. What you record before the next lesson

Evidence pack path.

6. Wrong vs right: stranger phishing vs authorized RT lab

Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.

  • Wrong

    Add stranger NTDS dump to pack for 'impact.'

  • Right

    Evidence pack assembled. Next: Capstone Lab.

Mission: assemble evidence pack

1) Bundle report map purple path RoE index. 2) Write integrity statements. 3) Gap paragraph; secure pack.

Stuck? Ask Cyberlium AI Mentor

Ask Mentor: “Minimum index rows for capstone?”

Knowledge Check

1

APPLY: Evidence pack includes:

Multiple choice

Knowledge Check

2

APPLY: True or False: Live hashes in mentor pack OK.

True or False

Knowledge Check

3

APPLY: Integrity line states:

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)