
Global Central Bank (GCB) is a one of a kind Enterprise Windows and Active Directory Cyber Range. It helps enterprises test capabilities of both their Red and Blue teams in an Enterprise Windows network. GCB is a true multi-forest environment that mimics a financial institution’s network.
Teams can test cutting-edge TTPs as GCB is built completely on fully patched Server 2019 machines. It includes abuse or bypass of many recommended defence mechanisms LAPS, JEA, WSL, RBCD, WDAC, ASR, AWL, Credential Guard, CLM, virtualization and more. User simulation is used to make it a true enterprise network. Global Central Bank (CRTM)
It is useful for both Red and Blue teams as very verbose logging is configured across the lab and teams can analyse the logs using the ELK installation in the labs. GCB enables enterprises to simulate actual adversaries by focusing on goals rather than just getting privileged access to machines. For effective adversary simulation and exciting gamification, the end goal of GCB is to initiate a fake transfer of funds from the target bank.
Syllabus
- Abuse defence mechanisms, exploit modern Windows features, extract secrets
-
Hunt for privileges, replay credentials, pivot across forest trusts
-
Enumerate permissions, exploit delegation, abuse enterprise application, utilize network sniffers, abuse user simulation
-
Bypass logon restrictions, lateral movement across forest trust, play with Kerberos tickets
-
Bypass AV, tackle Kerberos double-hop, abuse delegation, extract credentials from DC in the other forest, escalate from child to forest root in the other forests
-
Enumerate across forest, access documents and emails to collect information, abuse remoting endpoints, modify ACLs, exploit delegation
-
Abuse user simulation, craft payloads, bypass AV, bypass privilege restrictions, impersonate users, abuse exchange permissions, modify ACLs, escalate privileges to domain admin
-
Retrieve credentials from process memory dump and replay them, Bypass Windows Defender Application Guard, ASR and CLM to extract credentials, escalate privileges on domain
-
Abuse forest trust to hop to a third forest, enumerate privileges from the first hop forest and pivot to the second hop, avoid Kerberos double hop issue, extract secrets
-
Collect information from various compromised forests, escalate to DA, escalate to forest root
-
Abuse built-in Windows mechanisms, craft payloads, compromise air-gapped/not-reachable servers
-
Abuse virtual servers, extract credentials from offline domain controllers and extract secrets to initiate the fund transfer
Security Education
OffSec
iNE
Antisyphon
EC-Council
Applied Network Defense
Kaspersky
Sektor7
CompTIA
TCM Security
BlackHat
13Cubed
Dark Vortex
Enciphers
Forty North
Cyber warfare Labs
Maltrak
Scorpio Software
Security Onion
Zero Point Security
SentinelOne
Altered Security
SpecterOps
Pentester Academy
CQURE
PluralSight
StationX
Cybr
موسسههای دیگر