Threat Hunting Home Lab: Your Personal Playground for Learning Adversary Behavior
This article was originally published in the InfoSec Survival Guide: Teal Book — Threat Hunting. Read it free online HERE, or grab it on the Spearphish General Store (free digital download or a $1.25 physical copy, your call). |
Want to understand how attackers actually operate? Build a home lab where you can safely run Command and Control (C2) beacons, capture network traffic, and analyze the evidence like a real threat hunter.
The Three-Host Setup
You need four functions, but only three hosts to cover them all. Here's the topology:
Host 1: Control HQ (your command center)
- Any OS you want—personal preference rules here
- Where you orchestrate everything via browser, terminal (SSH), RDP/VNC
- Access C2 web interfaces, RITA, and remote into your victim
- Location: Local network (same as victim)
Host 2: The Victim (the compromised endpoint)
- Windows 10/11—realistic target environment
- Records both network traffic (for Zeek logs) and endpoint activity (Sysmon)
- Can be physical or VM, whatever works for your setup
- Location: Local network
Host 3: C2 Server + RITA (the adversary infrastructure)
- Ubuntu—universal choice for C2 frameworks
- Hosts your C2 server
- Also runs RITA for analyzing captured traffic
- Location: Must be external (different network from victim)
Critical Network Detail: Your C2 server MUST be on an external network. RITA needs to see north-south traffic (internal > external) to properly analyze C2 beaconing patterns.
Setting Up the Victim
This is where the magic happens—and where you intentionally make things vulnerable.
Step 1: Completely Disable Defender
Use the Windows Defender Remover script:
github.com/ionuttbara/windows-defender-remover
Download the latest release, follow the instructions. You need your victim to be actually vulnerable for this to work.
Step 2: Install Sysmon (Endpoint Telemetry)
Sysmon gives you the detailed system security logs that Windows doesn't provide by default.
# Download Sysmon
Invoke-WebRequest -Uri https://download.sysinternals.com/files/Sysmon.zip -OutFile C:\temp\sysmon.zip
# Extract it
Expand-Archive C:\temp\sysmon.zip -DestinationPath C:\temp\sysmon
Next, grab a baseline config. SwiftOnSecurity's config is a solid starting point:
# Download SwiftOnSecurity base config
Invoke-WebRequest -Uri https://raw.githubusercontent.com/SwiftOnSecurity/sysmon-config/master/sysmonconfig-export.xml -OutFile C:\temp\sysmon\sysmon-config.xml
Now install with the config:
# Install Sysmon with SwiftOnSecurity config
C:\temp\sysmon\Sysmon64.exe -accepteula -i C:\temp\sysmon\sysmon-config.xml
Start with this baseline, then customize the XML as you learn what matters for your hunts.
Step 3: Capture Network Traffic (for Zeek Logs)
You want both the raw packet capture AND Zeek logs. The good news: Zeek can convert pcap/pcapng files to Zeek logs, so capture the former and you get both.
Use TShark (command-line Wireshark). Install Wireshark from www.wireshark.org/download and TShark comes with it. Then capture traffic whenever you're running simulations.
Alternative: tcpdump works great too.
Setting Up the C2 Server
Ubuntu is typically your friend here; most C2 frameworks tend to play nicely with it.
Choosing Your C2 Framework
The open-source C2 landscape is rich with options: Sliver, Merlin, Mythic, Havoc, Empire, AdaptixC2. My recommendation for starting out:
- Sliver: Solid, stable, TUI-based. Written in Go. Supports HTTP/S, DNS, WireGuard, mTLS. Great first C2 to learn.
- Merlin: Another excellent beginner, supports HTTP/1.1, 2, and 3.
Once comfortable, level up to Mythic. (The GOAT, imho.)
Installing Sliver
Literally one command:
curl https://sliver.sh/install | sudo bash
Check sliver.sh for full documentation and getting started guides.
Why RITA Lives Here Too
Simple answer: RITA runs on Ubuntu, so why spin up a fourth host? Co-locating it with your C2 server keeps things simple for home labs.
RITA setup instructions can be found here: github.com/activecm/rita
Note: Installing RITA will also install Zeek.
Are There Other Ways to Do This?
Heck yes! Threat hunting labs are wonderfully flexible. Explore, experiment, ask questions, and make it your own. Consider this a playground for learning, not gospel.
The beauty of a home lab is that breaking things is encouraged.
Explore the Infosec Survival Guide and more… for FREE!
Get instant access to every issue of the Infosec Survival Guide, as well as our self-published infosec zine PROMPT#, and exclusive Darknet Diaries comics — all available at no cost.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.