Repository navigation
13. Windows
Windows Server 2022 operator workstation. The primary GUI workstation for driving the lab: Mythic web UI, file shuttling between C2 hosts and your local machine, and any payload work that needs a real Windows host.
| At a glance | |
|---|---|
| Hostname |
windows (private VPC only) |
| OS | Windows Server 2022 (Datacenter, latest AMI from Amazon) |
| Access | RDP via Guacamole (no public IP, no SSH server) |
| Username |
Administrator (auto-generated password, AWS-decrypted) |
| Pre-installed tools | Chromium, VS Code, MobaXterm, 7-Zip, Git |
| Defender | Disabled at deploy (lab-friendly; re-enable if you want to test AV evasion against Defender) |
| Firewall | Disabled at deploy |
| Cross-host DNS |
C:\Windows\System32\drivers\etc\hosts populated with all lab hostnames |
Three things only Windows can do well:
-
Run the Mythic web UI in a browser. Mythic UI works on any browser, but having it on the lab box means you avoid the noise of routing browser traffic from your host machine through the redirector or setting up
localhost:7443SSH tunnels. -
Operator client host for Adaptix: the AdaptixClient GUI runs on this Windows workstation (
C:\Tools\AdaptixClient), not on the Adaptix host, which is headless. Windows is the primary operator surface for Adaptix, and a second surface for running Mythic in the browser, staging payloads, and Windows-native tooling. -
Generic Windows-side ops: explore C# / .NET payload behavior, run native AD tooling like
RSAT, test OPSEC against Windows Defender (re-enable it first), or use it as a generic Windows endpoint for testing payload execution.
You could, but the Windows box is a convenient SSH staging point into the internal lab hosts (via MobaXterm) alongside Guacamole SSH. Guacamole's browser-based SSH works for quick commands but is painful for sustained ops: no persistent sessions, limited copy/paste, no split panes. MobaXterm on this box gives you proper terminal sessions to all internal hosts, pre-configured and ready to go. Most operators leave the Windows box running for the duration of a session.
This box is the offensive operator workstation. It runs beacons and payload tooling by design. Defender stays off permanently. Re-enabling it will quarantine your tooling and break the lab workflow. If you want to test evasion against Defender, use a separate target, not this box.
The Windows host has no public IP and sits isolated within the lab VPC. The firewall is disabled to avoid interference with inter-VPC traffic between the main VPC and the redirector VPC. Leave it off.
Default is t3.medium (2 vCPU, 4 GB RAM). That's enough for browser + a couple of tools. If you find Mythic UI sluggish or you want to run BloodHound CE GUI, Burp, AND Mythic UI simultaneously, bump to t3.large via windows_instance_type in tfvars.
Disk is 50 GB by default to accommodate the Server 2022 base + tools + agent generation artifacts. You can shrink to 30 GB if you're careful but cloud-init has more headroom at 50 GB.
The setup is in terraform/setup_scripts/windows_setup.ps1. Cloud-init runs it as user-data on first boot:
| Step | What happens |
|---|---|
| 1 | Phase 1 (batch): disable Defender via registry + stop service, disable Windows Firewall, enable RDP |
| 2 | Phase 2 (PowerShell): rename hostname to windows, populate hosts file, install Chocolatey, install Chromium / VS Code / MobaXterm / 7-Zip / Git, configure MobaXterm sessions, configure Chromium bookmarks |
After deploy, MobaXterm on this box has the redStack Lab session folder with these SSH bookmarks:
- Mythic C2 (SSH)
- Sliver C2 (SSH)
- Adaptix C2 (SSH)
- Apache Redirector (SSH)
- Guacamole Server (SSH)
- Kali Linux (SSH)
All use password auth (the lab password, baked into the bookmarks). Click any of them to land in a shell on that host without typing credentials.
Chromium launches with two bookmarks pre-pinned to the bookmark bar:
| Bookmark | URL |
|---|---|
| Mythic C2 | https://mythic:7443 |
| redStack Wiki | https://github.com/BaddKharma/redStack/wiki |
The bookmark bar is enabled by default. Hostnames resolve via the lab hosts file. No manual IP lookup needed.
The lab Windows box has a GuacShare folder visible in This PC in File Explorer. This is a special folder that the Guacamole RDP connection mounts as a virtual drive. Files placed here are visible in the Guacamole sidebar (Ctrl+Alt+Shift > Devices) for one-click download to your host laptop.
Use it for:
- Pulling generated agents off the lab to your host machine (e.g.
Downloads/apolloTest.exe> zip > drop in GuacShare > download from Guacamole sidebar) - Pushing files into the lab (drag onto Guacamole sidebar > shows up in GuacShare)
Tip
The session config is baked into terraform/setup_scripts/windows_setup.ps1 and written to %APPDATA%\MobaXterm\MobaXterm.ini during cloud-init. To re-apply it manually (e.g. after a MobaXterm reinstall), run terraform/setup_scripts/configure_mobaxterm.ps1 on the Windows box.
After Verify confirms the desktop loads:
[!NOTE] Windows finishes provisioning a little after the desktop first loads. While a
_SETUP-IN-PROGRESS.txtfile sits on the desktop, setup is still running; the box is ready when it is replaced by_SETUP-COMPLETE.txt. TheSetup Logdesktop shortcut tails the live provisioning log. If MobaXterm opens without the redStack Lab session folder, wait for_SETUP-COMPLETE.txt, then reopen it.
- Open Chromium: It's pinned to the taskbar.
-
Navigate to
https://mythic:7443: Hostname resolves viahostsfile. Accept the self-signed cert warning. Login asmythic_admin(password fromdeployment_info.txt). - Generate an Apollo agent: Follow the Mythic walkthrough.
-
Execute the agent: From PowerShell, run
Start-Process -FilePath "C:\Users\Administrator\Desktop\apolloTest.exe" -WindowStyle Hidden. See Mythic > Test Agent for details on why to use this over double-clicking. - Watch the callback appear in Mythic Active Callbacks within ~10 seconds.
For Sliver and Adaptix, the corresponding flows are in Sliver and Adaptix.
| Direction | Method |
|---|---|
| Lab Linux host → Windows |
scp from Windows PowerShell: scp admin@mythic:/tmp/payload.exe C:\Users\Administrator\Desktop\
|
| Windows → Lab Linux host |
scp from Windows: scp .\file.txt admin@mythic:/tmp/ (or use MobaXterm's SFTP browser) |
| Lab Windows → your host machine | Place file in GuacShare, click it in Guacamole sidebar > Devices, browser downloads |
| Your host machine → Lab Windows | Drag file onto Guacamole sidebar > Devices, lands in GuacShare
|
The scp direction works because OpenSSH client is built into Windows Server 2022. Hostnames resolve via C:\Windows\System32\drivers\etc\hosts.
Most common cause: Windows is still initializing. The AMI takes ~10 minutes from terraform apply completion to RDP availability, compared to ~5 minutes for the Linux hosts. The AWS Administrator password generation (which Terraform consumes via rsadecrypt) happens late in cloud-init.
Verify:
# From Guacamole or any Linux host:
nc -zv windows 3389Should return Connection succeeded. If not, wait five more minutes and retry.
If still failing:
- Check
terraform output deployment_infofor the Windows password. If it shows(not yet available), AWS hasn't finished generating it. Wait and re-runterraform refresh && terraform output deployment_info. - In the AWS Console, EC2 > Instances > windows > Get system log. Look for cloud-init errors near the end of the log.
The session config is dropped at %APPDATA%\MobaXterm\MobaXterm.ini during cloud-init. If MobaXterm was running during cloud-init it may not have picked up the config.
# Restart MobaXterm
Stop-Process -Name "MobaXterm*" -Force -ErrorAction SilentlyContinue
Start-Process "C:\ProgramData\chocolatey\bin\MobaXterm.exe"Mythic's container stack takes 5-10 minutes to come up after cloud-init starts on the Mythic host. During that window, https://mythic:7443 will fail. Wait, then retry. If still failing after 15 minutes, see Troubleshooting > Component Health Checks > Mythic.
Chocolatey install ran during cloud-init. If any package failed to install, check the cloud-init log:
# View Windows user-data log
Get-Content C:\Windows\Temp\user-data.log | Select-String -Pattern "ERROR|FAIL"To re-install a missing package:
choco install chromium vscode mobaxterm 7zip git -yMicrosoft's update cadence sometimes flips Defender real-time monitoring back on. Re-disable:
Set-MpPreference -DisableRealtimeMonitoring $true
Set-MpPreference -DisableBehaviorMonitoring $true
Set-MpPreference -DisableIOAVProtection $trueIf scp from Linux to Windows fails, OpenSSH server isn't running on Windows by default in the lab (only the OpenSSH client is). Push from Windows instead, or use the GuacShare drag-and-drop pattern.
This is expected. Rename-Computer in windows_setup.ps1 runs without an automatic reboot, so the computer name stays the EC2 default until the box is rebooted. It does not affect the lab: every host resolves windows (and every other hostname) via the hosts file, RDP works, and a beacon running on this box reports EC2AMAZ-XXXXX\Administrator for whoami. If you want the name to actually change, reboot once:
Rename-Computer -NewName "windows" -Force -Restart← Previous: Adaptix | Next: Kali →
"Know your tools. The bad guys do."
DFIR / SANS adage