دوره Altered Securitty – Global Central Bank (CRTM)

Global Central Bank (GCB) is a one of a kind Enterprise Windows and Active Directory Cyber Range. It helps enterprises test capabilities of both their Red and Blue teams in an Enterprise Windows network. GCB is a true multi-forest environment that mimics a financial institution’s network.

Teams can test cutting-edge TTPs as GCB is built completely on fully patched Server 2019 machines. It includes abuse or bypass of many recommended defence mechanisms LAPS, JEA, WSL, RBCD, WDAC, ASR, AWL, Credential Guard, CLM, virtualization and more. User simulation is used to make it a true enterprise network. Global Central Bank (CRTM)
It is useful for both Red and Blue teams as very verbose logging is configured across the lab and teams can analyse the logs using the ELK installation in the labs. GCB enables enterprises to simulate actual adversaries by focusing on goals rather than just getting privileged access to machines. For effective adversary simulation and exciting gamification, the end goal of GCB is to initiate a fake transfer of funds from the target bank.

Syllabus

  1. Abuse defence mechanisms, exploit modern Windows features, extract secrets
  2. Hunt for privileges, replay credentials, pivot across forest trusts 

  3. Enumerate permissions, exploit delegation, abuse enterprise application, utilize network sniffers, abuse user simulation

  4. Bypass logon restrictions, lateral movement across forest trust, play with Kerberos tickets

  5. Bypass AV, tackle Kerberos double-hop, abuse delegation, extract credentials from DC in the other forest, escalate from child to forest root in the other forests

  6. Enumerate across forest, access documents and emails to collect information, abuse remoting endpoints, modify ACLs, exploit delegation

  7. Abuse user simulation, craft payloads, bypass AV, bypass privilege restrictions, impersonate users, abuse exchange permissions, modify ACLs, escalate privileges to domain admin

  8. Retrieve credentials from process memory dump and replay them, Bypass Windows Defender Application Guard, ASR and CLM to extract credentials, escalate privileges on domain

  9. Abuse forest trust to hop to a third forest, enumerate privileges from the first hop forest and pivot to the second hop, avoid Kerberos double hop issue, extract secrets

  10. Collect information from various compromised forests, escalate to DA, escalate to forest root

  11. Abuse built-in Windows mechanisms, craft payloads, compromise air-gapped/not-reachable servers

  12. Abuse virtual servers, extract credentials from offline domain controllers and extract secrets to initiate the fund transfer

Altered Securitty – Certified Red Team Master (CRTM)