Skip to content

01. Quick Start

BaddKharma edited this page Sep 2, 2026 · 51 revisions

🚀 Quick Start

Abbreviated path for returning operators. If this is your first deploy, work through Prerequisites → Deploying Terraform → Verify → First Run instead.

Important

New to redStack? This page skips explanation and assumes you've been through the full flow before. Start at Prerequisites and follow the numbered pages in order.

At a glance
Active steps terraform apply ~5-10 min. Linux hosts and Guacamole ready shortly after. Windows RDP and Mythic UI need another ~10 min.
What you deploy 7 EC2 instances (Mythic / Sliver / Adaptix / Redirector / Guacamole / Windows op / Kali op) across 2 peered VPCs
Cost ~$0.27/hr compute. Stop after sessions, destroy on 3+ day breaks: ~$15-20/mo
Default mode Direct Access (public domain + Let's Encrypt). For cyber ranges: see Deployment Modes

Returning Operator Steps

Active steps only. This walkthrough assumes IAM is set up, aws configure is done, the SSH key pair exists in AWS, and you've accepted the Kali Marketplace EULA.

git clone https://github.com/BaddKharma/redStack.git
cd redStack/terraform
cp terraform.tfvars.example terraform.tfvars
# edit terraform.tfvars: set localPub_ip (a bracketed list of one or more "IP/32"),
#   ssh_key_name, ssh_private_key_path, redirector_domain
terraform init
terraform apply -auto-approve

Point your domain's A record at the redirector's Elastic IP (printed in deployment_info). Instances are typically ready within a few minutes after terraform apply finishes.

SSL cert (Direct Access):

SSH to the redirector via MobaXterm, then run:

sudo certbot --apache -d yourdomain.tld

Open the portal: https://<GUAC_PUBLIC_IP>/guacamole. Log in as guacadmin with the lab password from deployment_info. All connections are pre-registered.


Set Up C2 and Enumerate

Stand up your C2 framework so it's ready to receive callbacks, then use Kali to identify a viable initial access vector. You craft the beacon once you know how you're getting in.

Each C2 has a setup walkthrough:

  • Mythic, UI-driven, HTTP profile pre-installed. Web UI at https://mythic:7443 from the Windows operator.
  • Sliver, CLI-driven. SSH into the Sliver host and sliver-client.
  • Adaptix, Qt GUI client on the Windows workstation. See Adaptix for setup steps.

With C2 running, use Kali to enumerate your target and find your initial access path. It runs headless by default with the full AD/enum lineup pre-installed: Nmap, Netexec, BloodHound, Impacket, and more.

If you want to verify the full callback chain before working a real target, generate a payload pointed at the Windows operator and execute it there. It's an internal lab host, so traffic flows through the redirector exactly as it would against an external target.

Caution

Kali tools are loud. Subnet-wide nmap scans, netexec sprays, and mass BloodHound collection generate obvious noise. Enumerate deliberately: identify specific hosts and services, find your access vector, then craft a payload for it. A pentesting approach defeats the point of the exercise.


Tunneled Access (Cyber Ranges)?

Skip the domain step and the Certbot step. In terraform.tfvars:

redirector_domain                    = ""
enable_vpn_tunnel                    = true
enable_redirector_htaccess_filtering = false

Then follow OpenVPN Tunnel Environments for the OpenVPN + WireGuard routing setup.


Session Wrap-Up

End of session: stop all instances via the AWS Console (EC2 > Instances > Instance State > Stop) or CLI. Compute charges stop immediately.

Before a 3+ day break:

terraform destroy

Releases EIPs, terminates instances, removes VPCs. ~5 min. State is gone. See Cost Management for the full cost breakdown.


← Previous: Home | Next: Prerequisites →


"Slow is smooth, smooth is fast."

Naval Special Warfare adage

Clone this wiki locally