Playbook · intermediate · 2–3 hours
Purple loop: noisy scan vs detection
Run a controlled Nmap/Hydra burst in lab, then find yourself in logs and write a detection note.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Scenario
You have an attacker VM and a target with logging (even simple auth.log + optional Wazuh/Suricata). Generate intentional noise, hunt it, and document a detection idea.
Goals
Generate timestamped offensive activity
Recover events in logs/IDS
Write one ATT&CK-mapped detection note
Compare noisy vs quieter alternatives
Requirements
Lab Zero + logging target
Optional DetectionLab/Wazuh
Safety
Isolated lab only
Do not point Hydra at production
Steps
Baseline
Intent: Know normal before attack.
Actions
- Note time sync; capture quiet log sample
- Record detection stack components
Attack window
Intent: Create clear telemetry.
Hunt
Intent: See yourself as blue.
Actions
- grep auth.log / Windows Security / Wazuh for your IP
- If PCAPs exist, filter in Wireshark
Detection artifact
Intent: Leave something reusable.
Actions
- Write data source, logic, FP risks, ATT&CK technique
- Suggest quieter red-team alternative for contrast
Remediation outcomes
Ensure SSH/RDP logging and alerting thresholds exist
Rate-limit auth; fail2ban or equivalent where appropriate
Network IDS on lab gateway for learning