#
Configuration Overview
The following is an overview of configurations (i.e., Ansible playbooks) applied to the ER6 infrastructure. Configurations are organized by:
- Scenario-specific playbooks - CL0P, LockBit, DPRK, and MITRE ATT&CK infrastructure
- Common playbooks that are generally applied to multiple instances across the environment, categorized against function (e.g., based on the operating system)
#
Table of Contents
Configuration Overview Table of Contents Per-Scenario Detections Scenario A Detections Scenario B Protections Scenario Internal Resources: Red (Attacker) and Support
Common Playbooks Role-Based Windows macOS Linux
#
Per-Scenario
#
Detections Scenario A
Emulated adversaries include CL0P
and DPRK
.
#
Detections Scenario B
Emulated adversaries include LockBit
.
#
Protections Scenario
The Protections/Prevention scenario consisted of standalone tests meant to evaluate product responses to specific adversary behaviors.
#
Internal Resources: Red (Attacker) and Support
Support infrastructure includes components such as the DNS server and Chocolatey mirror.