Lab 0.2: Atomic Red Team & Sysmon¶
Warning
This below method is no longer actively updated. It still works but screenshots & exact instructions may have changed.
**We recommend and support utilizing the provided Cloud VM: LAB 0.3: CloudLabs Setup
All lab instructions going forward assume the use of the CloudLabs VM.**
The instructions for the rest of this are provided as-is and for your convenience if you want them.
Goals:
- Successfully install Atomic Red Team (ART) and Sysmon on your VM or host machine.
- Verify the correct installation of ART by running a test.
Instructions¶
This lab only applies to you if you are not using the provided Virtual Machine.
-
The lab VM comes with these items already installed. If using your own host, follow these instructions to install Atomic Red Team:
- Refer to the installation guide on the Atomic Red Team GitHub page.
- Specifically, follow the instructions for installing the Framework AND the Atomics.
-
In a PowerShell admin window, run the following commands:
-
Confirm you have properly installed ART by running:
Invoke-AtomicTest T1087.001-10. This executes a basic and unobtrusive Atomic to ensure everything is installed correctly. -
Install Sysmon
-
Download the necessary lab scripts