All playbooks

Playbook · intermediate · 2–3 hours

Purple loop: noisy scan vs detection

Run a controlled Nmap/Hydra burst in lab, then find yourself in logs and write a detection note.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Scenario

You have an attacker VM and a target with logging (even simple auth.log + optional Wazuh/Suricata). Generate intentional noise, hunt it, and document a detection idea.

Goals

Generate timestamped offensive activity

Recover events in logs/IDS

Write one ATT&CK-mapped detection note

Compare noisy vs quieter alternatives

Requirements

Lab Zero + logging target

Optional DetectionLab/Wazuh

Safety

Isolated lab only

Do not point Hydra at production

Steps

Step 1

Baseline

Intent: Know normal before attack.

Actions

  • Note time sync; capture quiet log sample
  • Record detection stack components
Expected: Baseline note with timestamps.
Step 2

Attack window

Intent: Create clear telemetry.

Actions

  • nmap -sV against lab target; record start/stop
  • Optional: hydra limited attempts against lab SSH
Expected: Commands logged in operator notes with UTC times.
Step 3

Hunt

Intent: See yourself as blue.

Actions

  • grep auth.log / Windows Security / Wazuh for your IP
  • If PCAPs exist, filter in Wireshark
Expected: Screenshots of correlating events.
Step 4

Detection artifact

Intent: Leave something reusable.

Actions

  • Write data source, logic, FP risks, ATT&CK technique
  • Suggest quieter red-team alternative for contrast
Expected: One-page detection note added to eng folder.

Remediation outcomes

Ensure SSH/RDP logging and alerting thresholds exist

Rate-limit auth; fail2ban or equivalent where appropriate

Network IDS on lab gateway for learning