Skip to content

13. Windows

BaddKharma edited this page Jul 19, 2026 · 48 revisions

🪟 Windows

Windows Server 2022 operator workstation. The primary GUI workstation for driving the lab: Mythic web UI, file shuttling between C2 hosts and your local machine, and any payload work that needs a real Windows host.

At a glance
Hostname windows (private VPC only)
OS Windows Server 2022 (Datacenter, latest AMI from Amazon)
Access RDP via Guacamole (no public IP, no SSH server)
Username Administrator (auto-generated password, AWS-decrypted)
Pre-installed tools Chromium, VS Code, MobaXterm, 7-Zip, Git
Defender Disabled at deploy (lab-friendly; re-enable if you want to test AV evasion against Defender)
Firewall Disabled at deploy
Cross-host DNS C:\Windows\System32\drivers\etc\hosts populated with all lab hostnames

Considerations

Why a Windows workstation in the lab?

Three things only Windows can do well:

  1. Run the Mythic web UI in a browser. Mythic UI works on any browser, but having it on the lab box means you avoid the noise of routing browser traffic from your host machine through the redirector or setting up localhost:7443 SSH tunnels.
  2. Operator client host for Adaptix: the AdaptixClient GUI runs on this Windows workstation (C:\Tools\AdaptixClient), not on the Adaptix host, which is headless. Windows is the primary operator surface for Adaptix, and a second surface for running Mythic in the browser, staging payloads, and Windows-native tooling.
  3. Generic Windows-side ops: explore C# / .NET payload behavior, run native AD tooling like RSAT, test OPSEC against Windows Defender (re-enable it first), or use it as a generic Windows endpoint for testing payload execution.

Why not skip Windows entirely?

You could, but the Windows box is a convenient SSH staging point into the internal lab hosts (via MobaXterm) alongside Guacamole SSH. Guacamole's browser-based SSH works for quick commands but is painful for sustained ops: no persistent sessions, limited copy/paste, no split panes. MobaXterm on this box gives you proper terminal sessions to all internal hosts, pre-configured and ready to go. Most operators leave the Windows box running for the duration of a session.

Why is Defender disabled?

This box is the offensive operator workstation. It runs beacons and payload tooling by design. Defender stays off permanently. Re-enabling it will quarantine your tooling and break the lab workflow. If you want to test evasion against Defender, use a separate target, not this box.

Why is the firewall disabled?

The Windows host has no public IP and sits isolated within the lab VPC. The firewall is disabled to avoid interference with inter-VPC traffic between the main VPC and the redirector VPC. Leave it off.

Sizing tradeoffs

Default is t3.medium (2 vCPU, 4 GB RAM). That's enough for browser + a couple of tools. If you find Mythic UI sluggish or you want to run BloodHound CE GUI, Burp, AND Mythic UI simultaneously, bump to t3.large via windows_instance_type in tfvars.

Disk is 50 GB by default to accommodate the Server 2022 base + tools + agent generation artifacts. You can shrink to 30 GB if you're careful but cloud-init has more headroom at 50 GB.


Configuration

What's installed (and how)

The setup is in terraform/setup_scripts/windows_setup.ps1. Cloud-init runs it as user-data on first boot:

Step What happens
1 Phase 1 (batch): disable Defender via registry + stop service, disable Windows Firewall, enable RDP
2 Phase 2 (PowerShell): rename hostname to windows, populate hosts file, install Chocolatey, install Chromium / VS Code / MobaXterm / 7-Zip / Git, configure MobaXterm sessions, configure Chromium bookmarks

MobaXterm pre-configured sessions

After deploy, MobaXterm on this box has the redStack Lab session folder with these SSH bookmarks:

  • Mythic C2 (SSH)
  • Sliver C2 (SSH)
  • Adaptix C2 (SSH)
  • Apache Redirector (SSH)
  • Guacamole Server (SSH)
  • Kali Linux (SSH)

All use password auth (the lab password, baked into the bookmarks). Click any of them to land in a shell on that host without typing credentials.

Chromium bookmarks

Chromium launches with two bookmarks pre-pinned to the bookmark bar:

Bookmark URL
Mythic C2 https://mythic:7443
redStack Wiki https://github.com/BaddKharma/redStack/wiki

The bookmark bar is enabled by default. Hostnames resolve via the lab hosts file. No manual IP lookup needed.

GuacShare folder

The lab Windows box has a GuacShare folder visible in This PC in File Explorer. This is a special folder that the Guacamole RDP connection mounts as a virtual drive. Files placed here are visible in the Guacamole sidebar (Ctrl+Alt+Shift > Devices) for one-click download to your host laptop.

Use it for:

  • Pulling generated agents off the lab to your host machine (e.g. Downloads/apolloTest.exe > zip > drop in GuacShare > download from Guacamole sidebar)
  • Pushing files into the lab (drag onto Guacamole sidebar > shows up in GuacShare)

Tip

The session config is baked into terraform/setup_scripts/windows_setup.ps1 and written to %APPDATA%\MobaXterm\MobaXterm.ini during cloud-init. To re-apply it manually (e.g. after a MobaXterm reinstall), run terraform/setup_scripts/configure_mobaxterm.ps1 on the Windows box.


Initial Use

After Verify confirms the desktop loads:

[!NOTE] Windows finishes provisioning a little after the desktop first loads. While a _SETUP-IN-PROGRESS.txt file sits on the desktop, setup is still running; the box is ready when it is replaced by _SETUP-COMPLETE.txt. The Setup Log desktop shortcut tails the live provisioning log. If MobaXterm opens without the redStack Lab session folder, wait for _SETUP-COMPLETE.txt, then reopen it.

  1. Open Chromium: It's pinned to the taskbar.
  2. Navigate to https://mythic:7443: Hostname resolves via hosts file. Accept the self-signed cert warning. Login as mythic_admin (password from deployment_info.txt).
  3. Generate an Apollo agent: Follow the Mythic walkthrough.
  4. Execute the agent: From PowerShell, run Start-Process -FilePath "C:\Users\Administrator\Desktop\apolloTest.exe" -WindowStyle Hidden. See Mythic > Test Agent for details on why to use this over double-clicking.
  5. Watch the callback appear in Mythic Active Callbacks within ~10 seconds.

For Sliver and Adaptix, the corresponding flows are in Sliver and Adaptix.


File Transfer Patterns

Direction Method
Lab Linux host → Windows scp from Windows PowerShell: scp admin@mythic:/tmp/payload.exe C:\Users\Administrator\Desktop\
Windows → Lab Linux host scp from Windows: scp .\file.txt admin@mythic:/tmp/ (or use MobaXterm's SFTP browser)
Lab Windows → your host machine Place file in GuacShare, click it in Guacamole sidebar > Devices, browser downloads
Your host machine → Lab Windows Drag file onto Guacamole sidebar > Devices, lands in GuacShare

The scp direction works because OpenSSH client is built into Windows Server 2022. Hostnames resolve via C:\Windows\System32\drivers\etc\hosts.


Troubleshooting

Can't connect to Windows via Guacamole RDP

Most common cause: Windows is still initializing. The AMI takes ~10 minutes from terraform apply completion to RDP availability, compared to ~5 minutes for the Linux hosts. The AWS Administrator password generation (which Terraform consumes via rsadecrypt) happens late in cloud-init.

Verify:

# From Guacamole or any Linux host:
nc -zv windows 3389

Should return Connection succeeded. If not, wait five more minutes and retry.

If still failing:

  • Check terraform output deployment_info for the Windows password. If it shows (not yet available), AWS hasn't finished generating it. Wait and re-run terraform refresh && terraform output deployment_info.
  • In the AWS Console, EC2 > Instances > windows > Get system log. Look for cloud-init errors near the end of the log.

MobaXterm sessions don't appear

The session config is dropped at %APPDATA%\MobaXterm\MobaXterm.ini during cloud-init. If MobaXterm was running during cloud-init it may not have picked up the config.

# Restart MobaXterm
Stop-Process -Name "MobaXterm*" -Force -ErrorAction SilentlyContinue
Start-Process "C:\ProgramData\chocolatey\bin\MobaXterm.exe"

Mythic UI returns "connection refused"

Mythic's container stack takes 5-10 minutes to come up after cloud-init starts on the Mythic host. During that window, https://mythic:7443 will fail. Wait, then retry. If still failing after 15 minutes, see Troubleshooting > Component Health Checks > Mythic.

Chromium / VS Code / MobaXterm missing

Chocolatey install ran during cloud-init. If any package failed to install, check the cloud-init log:

# View Windows user-data log
Get-Content C:\Windows\Temp\user-data.log | Select-String -Pattern "ERROR|FAIL"

To re-install a missing package:

choco install chromium vscode mobaxterm 7zip git -y

Defender re-enabled itself after a Windows Update

Microsoft's update cadence sometimes flips Defender real-time monitoring back on. Re-disable:

Set-MpPreference -DisableRealtimeMonitoring $true
Set-MpPreference -DisableBehaviorMonitoring $true
Set-MpPreference -DisableIOAVProtection $true

File transfer to/from Windows fails

If scp from Linux to Windows fails, OpenSSH server isn't running on Windows by default in the lab (only the OpenSSH client is). Push from Windows instead, or use the GuacShare drag-and-drop pattern.

Hostname shows EC2AMAZ-XXXXX instead of windows

This is expected. Rename-Computer in windows_setup.ps1 runs without an automatic reboot, so the computer name stays the EC2 default until the box is rebooted. It does not affect the lab: every host resolves windows (and every other hostname) via the hosts file, RDP works, and a beacon running on this box reports EC2AMAZ-XXXXX\Administrator for whoami. If you want the name to actually change, reboot once:

Rename-Computer -NewName "windows" -Force -Restart

← Previous: Adaptix | Next: Kali →


"Know your tools. The bad guys do."

DFIR / SANS adage

Clone this wiki locally