#
Infrastructure for ATT&CK Evaluations - CL0P, LockBit, & DPRK (2024)
The infrastructure below was used for both CL0P, LockBit, & DPRK (2024). For convenience and cost savings, shared resources are used, including supporting infrastructure, including attacker platform, DNS, mail server, and traffic forwarding hosts.
Initial infrastructure was setup using Terraform, with configuration applied via scripts and configuration files.
Infrastructure for ATT&CK Evaluations - CL0P, LockBit, & DPRK (2024) Infrastructure Overview Scenario VMs Scenario A Domain - encryptpotter[.]net
Scenario B Domain - decryptmalfoy[.]net
Scenario Protections Domain - sonicbeats37[.]fm
Support and Red Team Hosts External Benevolent Hosts Red Team Hosts
Network Diagram
#
Infrastructure Overview
This document provides an overview of the infrastructure support used for the evaluation. In addition to setup and configuration of virtual machines, this document covers infrastructure support services, such as domain name services (DNS), mail, and traffic redirection, used to support the evaluation. Support services such as DNS and redirectors are used throughout the evaluation for resource efficiency.
The Harry Potter series was used as inspiration for the naming scheme of Scenarios A and B. The K-pop music genre inspired the naming scheme in the Protections subnet.
#
Scenario VMs
The scenario consists of an organization with two subsidiaries, with a bidirectional Active Directory domain trust relationship between the domains. A separate workstation, outside of the two domains, represents a 3rd party user with trusted access to the domain systems.
#
Scenario A Domain - encryptpotter[.]net
The Scenario A (CL0P) domain consists of six (6) virtual machines, all joined to the encryptpotter[.]net
Windows domain.
#
Scenario B Domain - decryptmalfoy[.]net
The Scenario B domain (LockBit) consists of six (6) virtual machines, all joined to the decryptmalfoy[.]net
Windows domain.
#
Scenario Protections Domain - sonicbeats37[.]fm
The Protections Scenario domain (DPRK) consists of seven (7) virtual machines, all joined to the sonicbeats37[.]fm
Windows domain.
#
Support and Red Team Hosts
The following hosts are used for overall network support, as well as for red team use. The hosts below are not accessible by evaluation participants.
#
External Benevolent Hosts
#
Red Team Hosts
#
Network Diagram
The diagram below shows the layout of all victim hosts, attack platform, and support hosts.