Skip to content

05. Verify

BaddKharma edited this page Jul 19, 2026 · 44 revisions

✅ Verify

Three quick checks after terraform apply finishes: Guacamole portal reachable, Windows operator reachable via RDP, internal hostname resolution working. Total time: ~5 minutes.

At a glance
Pre-req Deploying Terraform complete + cloud-init finished (~5-10 min after apply)
What you confirm Portal access · Windows desktop · cross-host DNS
What this doesn't cover C2 listeners (those come later in Mythic / Sliver / Adaptix)

All credentials and IPs come from:

terraform output deployment_info

Tip

Hostnames (mythic, sliver, adaptix, guac, redirector, windows, kali) are pre-configured in /etc/hosts on every Linux machine and C:\Windows\System32\drivers\etc\hosts on Windows. Use hostnames instead of IPs anywhere inside the lab.


Step 1: Access the Guacamole Portal

https://<GUAC_PUBLIC_IP>/guacamole
  • Username: guacadmin
  • Password: from terraform output deployment_info

After login you should see the pre-configured connections:

Windows (RDP)        - auto-connects with Administrator credentials
Mythic (SSH)
Guacamole (SSH)
Redirector (SSH)
Sliver (SSH)
Adaptix (SSH)
Kali (SSH)
Kali (XRDP)          - only when kali_deployment_mode = "gui"

All SSH connections are pre-configured with the auto-generated lab password and use password auth (no key prompt).

Guacamole portal connection list after a clean deploy
[Figure 5.1.1: Guacamole portal after login showing all pre-registered connections]

✅ Checkpoint: Guacamole accessible, all connections visible.

Note

Your browser will warn about a self-signed certificate when opening the Guacamole portal. This is expected. The portal runs over HTTPS with a self-signed cert. Accept and proceed. The certificate is only used to encrypt the operator session; it is not part of the C2 traffic path.


Step 2: Access the Windows Operator

In Guacamole, click Windows (RDP). RDP connects automatically; wait 10-30 seconds for the desktop to load.

Verify the pre-installed tools are present:

  • Chromium
  • VS Code
  • MobaXterm (with the redStack Lab session folder)
  • 7-Zip
  • Git

MobaXterm with redStack Lab session folder expanded
[Figure 5.2.1: MobaXterm on the Windows operator with the redStack Lab session folder expanded showing all six pre-configured SSH bookmarks]

If the connection fails: wait five more minutes. Windows is the slowest component to initialize, and the AWS-decrypted Administrator password isn't applied until late in cloud-init.

✅ Checkpoint: Windows desktop accessible, tools present, MobaXterm sessions visible.

Tip

Open MobaXterm on the Windows operator workstation. The redStack Lab folder has pre-configured SSH sessions for all Linux lab machines. Each one connects without a password prompt because the lab password is baked into the bookmark.


Step 3: Verify Internal Connectivity

From the Windows workstation, open PowerShell or Command Prompt and ping each lab machine to confirm hostname resolution and network connectivity:

ping mythic
ping sliver
ping adaptix
ping redirector
ping guac
ping kali

Expected: all hostnames resolve and respond.

✅ Checkpoint: All lab machines reachable by hostname from Windows.

Important

If any host fails to ping, see Troubleshooting > Connectivity Checks before proceeding. The C2 setup walkthroughs assume cross-host DNS is working.


Optional: Quick Sanity Check on Each C2 Host

Before diving into C2 setup, you can confirm each backend is healthy. These commands run on each Linux host, accessed via Guacamole SSH connections:

Host Command Expected
mythic cd /opt/Mythic && sudo ./mythic-cli status 8+ containers running, including apollo and http
sliver which sliver-server && systemctl status sliver Binary in PATH, service active
adaptix ls /opt/AdaptixC2/dist/adaptixserver File missing until the build finishes, see Adaptix
redirector sudo /home/admin/test_redirector.sh Apache active, modules loaded, decoy page working
kali MOTD banner shown on login? Mode line, install-kali-tools and kali-go-gui hints

If anything looks off, Troubleshooting has the recipes for common failure modes.


Lab Fully Operational: The Milestone

Verify confirms the lab is up. The lab is fully operational when you have received a first callback beacon from each of the three C2 frameworks: Mythic, Sliver, and Adaptix. Until you have all three beacons, the C2 stack is not confirmed end-to-end.

Follow First Run for the staged walkthrough that takes you from here through all three first beacons in the most efficient order.

← Previous: Deploying Terraform | Next: First Run →


"Trust, but verify."

Russian proverb popularized by Ronald Reagan (1987)

Clone this wiki locally