Section_L-_Attachment_4.docx

DOCX document 488 KB Posted

Attached to
Solicitation Notice Federal contract opportunity
Solicitation number
FA8773-17-R-8005
Issued by
Department of the Air Force Space Command

About this file

Sample Psychomotor Lesson

View the file

Other files for this federal contract opportunity

Other files attached to Solicitation Notice, newest first.
File Type Posted
CyOFTS_II,_Section_M__September_2017_rev_2.docx DOCX document
FA8773-17-R-8005,_Amendment_4.docx DOCX document
CyOFTS_II,_Section_L_revision_3.docx DOCX document
FA8773-17-R-8005_Amendment_3.docx DOCX document
CyOFTS_II,_Section_L_revision_2.docx DOCX document
FA8773-17-R-8005,_amendment_2.docx DOCX document
CyOFTS_II_Section_L_September_2017_rev2.docx DOCX document
RFP_Questions_37_and_38.xlsx XLSX spreadsheet
Section_L,_Attachment_9,__Labor_Matrix_rev_2.xlsx XLSX spreadsheet
CyOFTSII_FINAL_RFP_QA__36.xlsx XLSX spreadsheet
CyOFTS_II_Section_L,_Attachment_7_Past_Performance_Questionnaire_rev_1.docx DOCX document
dd1423-1_FA8773-17-R-8005_A005_Sep_2017.pdf PDF
Section_L,_Attachment_9,__Labor_Matrix.xlsx XLSX spreadsheet
dd1423-1_FA8773-17-R-8005_A006_Sep_2017.pdf PDF
CyOFTS_II,_Section_L_September_2017,_rev_1.docx DOCX document
DDForm_254_CyOFTS_II.pdf PDF
FA8773-17-R-8005,_Amendment_1_CyOFTS_II.docx DOCX document
dd1423-1_FA8773-17-R-8005_A001_Sep_2017.pdf PDF
dd1423-1_FA8773-17-R-8005_A003_Sep_2017.pdf PDF
dd1423-1_FA8773-17-R-8005_A002_Sep_2017.pdf PDF
dd1423-1_FA8773-17-R-8005_A004_Sep_2017.pdf PDF
CyOFTS_II__Section_J,_Attachment_1_-_Pricing_Table.xlsx XLSX spreadsheet
Section_L_Attachment_8_-_Reading_Room_Library_Instructions.docx DOCX document
Amended_CyOFTS_II_Section_L_September_2017.docx DOCX document
CyOFTS_II_PWS_Sep_2017.docx DOCX document
CyOFTS_II_Section_L-_Attachment_1.docx DOCX document
CyOFTS_II,_Section_L,__Attachment_2.docx DOCX document
CyOFTS_II,_Section_M__September_2017.docx DOCX document
CyOFTS_II,_Section_M,__Attachment_1_September_2017.docx DOCX document
CyOFTS_II,_Section_L,_Attachment_3,_Pt_III.docx DOCX document
CyOFTS_II,_Section_L,_Attachment_3_Pt_I.docx DOCX document
CyOFTS_II_Section_L,_Attachment_7_Past_Performance_Questionnaire.docx DOCX document
dd1423-1_FA8773-16-R-8007_A004_Oct_2016.pdf PDF
CyOFTS_II,_Section_L,_Attachment_3_Pt_IV.docx DOCX document
dd1423-1_FA8773-16-R-8007_A002_Oct_2016.pdf PDF
Section_L,_Attachment_9,__Labor_Matrix.xlsx XLSX spreadsheet
dd1423-1_FA8773-16-R-8007_A003_Oct_2016.pdf PDF
CyOFTS_II,_Section_L,_Attachment_3_Part_II.pptx PPTX presentation
CyOFTS_II,_Section_L_Attachment_8-_Reading_Library_Instructions.docx DOCX document
dd1423-1_FA8773-16-R-8007_A006_Oct_2016.pdf PDF
CyOFTS_II__Section_J,_Attachment_2_-_Pricing_Table.xlsx XLSX spreadsheet
Final_FA8773-17-R-8005.docx DOCX document
CyOFTS_II,_Section_L,_Attachment_5_PPQ_Tracking_Record.doc DOC document
dd1423-1_FA8773-16-R-8007_A005_Oct_2016.pdf PDF
CyOFTSII_RFP_Q&A.xlsx XLSX spreadsheet
CyOFTS_II,_Section_L,_Attachment_6_PPQ_Cover_Letter.doc DOC document
dd1423-1_FA8773-16-R-8007_A007_Oct_2016.pdf PDF
Section_L_Attachment_10_-_Offeror_Compensation_Spreadsheet.xlsx XLSX spreadsheet
CyOFTS_II_PWS_Aug_2017.docx DOCX document
CyOFTS_II,_Section_L_September_2017.docx DOCX document
Show all 50

Solicitation Notice has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

UNCLASSIFIED

UNCLASSIFIED
C-2106L-TM

39 IOS, 12 July 2017

Section L, Attachment 4

Windows Foundations

C-2106L-TM

Student Lab Manual

12 July 2017

Table of Contents

Table of Contents2
Initial Lab Setup9
IP Configuration9
Lab 1: PowerShell Familiarization10
Procedures10
Lab 2: WMIC Familiarization11
Procedures11

C-2106L-TM Windows Foundations

SECTION I – OVERVIEW

The following labs are intended to be used in conjunction with the Windows Foundations Student Guide and integrated within the lecture. The labs are intended to support the cognitive material to provide students with a deeper understanding of the concepts, security implications, and methods used to survey both local and remote systems within a domain environment. The labs will demonstrate methods for querying, navigating, and manipulating the Windows file system. Additionally, labs will have students querying and modifying registry and security settings as well as interrogating and manipulating services. The Windows Foundations lesson includes heavy emphasis on performance-based skills, whereas students implement tasks, and are required to utilize command line interface as well as utilities, regedit.exe, WMIC, PowerShell, and the Sysinternals Suite to analyze system information to identify normal, baselined activity versus anomalous, and malicious activity. Comment by RADOS, RACHEL A GG-13 USAF AFSPC 39 IOS/DOW: These ……. and Comment by RADOS, RACHEL A GG-13 USAF AFSPC 39 IOS/DOW: Delineate baselined from anomalous activity, and identify malicious activity.

PERFORMANCE OBJECTIVES:

CONDITION(S)
PERFORMANCE/BEHAVIOR
STANDARD(S)

Given (references, tools, etc.):

1. Access to the CWO Student Labnet environment

2. Copy of the Student Guide and Lab Guide

3. Students Notes

Task(s):

a. Leverage the PowerShell Help system

b. Perform Windows tasks on local system using PowerShell

c. Leverage the WMIC to perform basic tasks on a local Windows system

Criteria:

Go/ No-Go Demonstration:

Correctable to 100% in class

SUPPORT MATERIAL AND GUIDANCE

STUDENT INSTRUCTIONAL MATERIAL: Students will receive C-2106L/TM Student and Lab Guides

STUDENT PREPARATION/READING ASSIGNMENTS: Students should read all pages in the student guide prior to the lecture. Additional reading from the reference material will enhance understanding of the material contained in this lab guide.

SECTION II - STUDENT OUTLINE

Initial Lab Setup Introduction The labs in this manual use a virtualized environment that consists of individual student network environments and a shared training range. These labs are specifically designed to work within this environment, but could be modified to work within a production environment consisting of similar systems.

Purpose
Determine network interface settings for virtual machines (VM).

Determine the reachability of hosts on the network.

IP Configuration

1. Open the following virtual machines (VM) and use the provided credentials:

VM
Username
Password
Hostname
IP Address
Windows 10
Student
ST@dm1n!
Windows 7
Student
ST@dm1n!

2. Determine the IP addresses and hostname for each VM. Record this information in the table provided.

2.1. Note: If you are unsure of the commands to use, type help and a list of available commands will populate your screen. Once you see a command that may fit what your needs are, you can query the help for it by following the command with a “/?”.

Example: netsh /?

Lab 1: PowerShell Familiarization Introduction This lab is meant to provide the basic foundation for using PowerShell cmdlets to gather system details and utilize the help function to be able to build commands. PowerShell commands will be included in follow-on labs to provide additional usage options and alternative methods for gathering information and assessing systems. For further comprehension of the underlying concepts consult the references in Section I or the additional content in Appendix 1 and 2 of this Student Lab Manual.

Purpose
To gain practical experience with the PowerShell help cmdlet

To gain practical experience with <tab>complete functionality

To gain a basic understanding of PowerShell command usage

Procedures

Perform the following on the Windows 10 VM

Open an Administrative PowerShell prompt

PowerShell cmdlets follow a verb-noun format; such as the options below

a. Get-Something

b. Set-Something

c. New-Something

d. Remove-Something

Type get-help to view the help dialog

Using the output from the above command. How would you search for cmdlets relating to processes?

e. Answer:____________________________________________________________

Now we will explore the available cmdlets by using the get-command cmdlet

Get-command –verb get

Get-command –verb add

As you should have seen with the previous two commands, there are many different cmdlets and Functions available within PowerShell. Another option that we have to view available options is to leverage the tab complete functionality within PowerShell.

For this next step you will leverage tab to cycle through available options. Type in the following and then cycle through with tab.

Get-pr (Now hit the Tab key until you come to get-process, then hit enter)

Lab 2: WMIC Familiarization

Introduction

This lab is meant to provide you with some of the basics for utilizing the Windows Management Instrumentation Console (WMIC). It will highlight how to use help as well as the basic syntax for formulating queries. Where applicable, follow-on labs will provide examples and tasks for you to build off of the basic concepts outlined in this lab. WMIC is an outstanding tool that will be present on everything from Windows XP through Windows 10 and their associated Server systems. It is simply yet another way to gather information, and there may be times that means such as PowerShell may not be available, so knowing another way will be critical to your success.

Purpose
Learn how to use the help function

Learn how to build commands

Leverage WMIC to gather system details

Procedures

Perform the following on the Windows 10 VM

1. WMIC Help functions just like the Windows help function; meaning that we can simply add a /? following the command we want help with.

For example, if you need to know what alias options you have to use with WMIC you will enter the following command: (Type in the commands to add context to the statements below) wmic /?

If you want to find out what options you have for the “Startup” alias, you will build your help command to the following:

wmic startup /?

If you want a listing of the available options for the verb list, you would build out your help syntax to the following:

wmic startup list /?

We could then finalize our command to be:

wmic startup list full

The commands that you type into WMIC are formatted in the WMI Query Language (WQL), which Microsoft states is a subset of SQL. There are many elements of WQL which we'll use throughout this course, so the goal is for you to have the necessary foundation in place by the end of this lab.

The syntax includes these key words:

· list: shows a list of something.

· get: gets one or more values of an attribute. You could get a list of things, separated by commas.

· create: creates an element, which can be used to run programs.

· delete: deletes an element, which can be used to kill processes, among other things.

· where: these clauses can match some property to help us sort through a long list of things, for

· example: where name=“cmd.exe”

· /every:[N]: Run this command every N seconds, which works for displaying items, but not creating or deleting them.

The essential format of WMIC syntax revolves around WQL as follows. We type in a WMIC command followed by an area we are interested in, known as an “alias”. That is the arena we want WMIC to interact with, such as process, startup, ntevent, nicconfig, etc. For a full list, look at the output of wmic /?.

wmic [alias] [where with where clause] [verb with verb clause]

Then, we have an option of including a “where” keyword with a where clause. These clauses look rather like SQL, and we'll see that they have many of the same options as SQL, including OR, AND, and LIKE notation.

Finally, we get to a verb and verb clause, which tells WMIC what we want it to do with the instances of things within the given alias that match the where clause. Options here include get, delete, list, and call.

Also, you can get a list of process name, processids, and command-lines used to invoke each program with this little WQL:

wmic process get name, processid, commandline

Looking at processes is nice, but sometimes security pro or sys admin needs to kill processes. You can do this with WMIC as follows:

wmic process [pid] delete

Alternatively, you can kill all processes with a given name, rather like the “killall –9 [name]” command would work on Unix or Linux, as follows:

wmic process where name="cmd.exe" delete

You could even do that remotely, with the user name, password, and node syntax we described earlier, killing all cmd.exe's running on a different machine, provided that you had administrative credentials on that system.

But, WMIC doesn't let you just view and kill processes. You can also start processes, using this syntax to run calc.exe:

wmic process call create calc.exe

Now that you have a basic foundation with WMIC, we will leverage WMIC more in the following labs.

1. emonstrate how this key is populated, bring up Internet explorer and type in a few random URLs. Once refresh and record how the entries are sorted. _________________________________________________________________________

2. Navigate to HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR. This key stores information about USB devices connected to the system. You should see one device for this system. Record its information below.

a. Vendor (FriendlyName): ______________________________________________

b. Serial Number: ______________________________________________________

3. What would your command be to query the registry key in item 10 using reg.exe from the command line? ____________________________________________________

Procedures

Perform the following on the Windows 10 VM

1. The first thing you’ll do is discover the Windows Firewall's current configuration properties. You can query Windows Firewall settings using the following netsh advfirewall command:

netsh advfirewall firewall show rule name=all

2. It's typically a best practice to leave Windows Firewall enabled, but sometimes when you're performing testing or setting up new applications, you need to turn Windows Firewall off for a period. The following commands illustrate how to turn Windows Firewall off and then back on:

netsh advfirewall set allprofiles state off netsh advfirewall set allprofiles state on

3. If you make a mistake configuring Windows Firewall, you might want to use the following netsh command to reset it back to its default settings:

netsh advfirewall reset

NOTE: This would seldom, if ever, be used in the operational environment, but here in training this command can be useful to get things working.

4. The Windows Firewall log can be configured to either use the default location or a custom location. The default path for the Windows Firewall log files is \Windows\system32\LogFiles\Firewall\pfirewall.log.

5. The netsh command below changes the location of the log file to the C:\temp directory:

netsh advfirewall set currentprofile logging filename "C:\temp\pfirewall.log"

Allow and Prevent Ping

Perform the following on the Windows 10 VM

6. You can use netsh to control how a given system responds to ping requests. The following two netsh commands show how you can block and then open Windows Firewall to ping requests:

netsh advfirewall firewall add rule name="All ICMP V4" dir=in action=block protocol=icmpv4

Perform the following on the Windows 7 VM

7. Perform a ping against the Windows 10 system. Did you get a response? ___________

Hint: If the ping isn’t blocked, ensure the firewall is ON.

Perform the following on the Windows 10 VM

8. For the purposes of our labs, we want to allow ping, so we want to enable ping. Document your command below:

Enable and Delete a Port

9. One of the most common things you need to do with Windows Firewall is open ports that are used by different programs. The following examples show how to use netsh to create a rule to open and then close port 1433, which is used by Microsoft SQL Server:

netsh advfirewall firewall add rule name="Open SQL Server Port 1433" dir=in action=allow protocol=TCP localport=1433 netsh advfirewall firewall delete rule name="Open SQL Server Port 1433" protocol=tcp localport=1433

Enable a Program

Another common task is opening Windows Firewall for a given program. The following example illustrates how to add a rule that enables Windows Live Messenger to work through Windows Firewall:

netsh advfirewall firewall add rule name="Allow Messenger" dir=in action=allow program="C:\programfiles\messenger\ msnmsgr.exe"

Enable Remote Management

Another common requirement, especially when you're setting up new systems, is to enable remote management so that tools such as the Microsoft Management Console (MMC) can connect to remote systems. To open Windows Firewall for remote management, you can use the following command:

netsh advfirewall firewall set rule group="windows remote management" new enable=yes

Enable Remote Desktop Connection

One of the first things to do with most of the server systems is to set up “enable Remote Desktop Connection” for easy remote systems management. The following command shows how to use netsh to open Windows Firewall for Remote Desktop Connections:

netsh advfirewall firewall set rule group="remote desktop" new enable=Yes

Export and import firewall settings

After you get Windows Firewall configured, it's a good idea to export your settings so that you can easily reapply them later or import them into another system. In the following netsh commands, you can see how to export and then import your Windows Firewall configuration:

netsh advfirewall export "C:\temp\WFconfiguration.wfw" netsh advfirewall import "C:\temp\WFconfiguration.wfw"

NOTE: Blockinbound will block inbound network traffic that does not match an inbound rule. This is the default setting and allows rules to come in. Blockinboundalways blocks all inbound network traffic, including traffic that matches an inbound rule. If Blockinboundalways is used, there must be instructions in the rule for how to handle outbound traffic.

Perform the following on the Windows 7 VM

Record your commands:

1. Reset firewalls to previous state.

2. View the current state of the Windows firewall for all profiles.

3. Set the firewall to be on and not allowing incoming traffic.

4. Remove all inbound rules from the firewall. (Note: In #3, we made a rule to turn on the firewall and block incoming traffic. In #4, we are clearing out any previously set inbound rules.)

5. Enable ping through the firewall. Test by pinging the Windows 10 VM.

6. Add an inbound rule(s), to a local machine to allow inbound TCP traffic across port 445. For the remote IP, use the 10 VM IP address.

7. Set the firewall to allow incoming traffic on current profile.

8. View all the rules.

9. View only the inbound rules.

10. Reset firewall to previous state.

Appendix 1 – Command Refresher

1. Useful aides that will help the students in the labs here. Example: Command Line quick reference.

Appendix 2 – Advanced Challenges This section is for stuff pertaining to Labs. Place additional advances labs here for student who excel.

1. Putt stuff here

Attachment 1 – Lab Solutions Lab 1 Solutions

1. An Answer

2. An Answer

Lab 2 Solutions

1. An Answer

2. An Answer

UNCLASSIFIED

UNCLASSIFIED
2

image3.jpeg image2.png

File details come from the government source that posted it. Updated .