Section_L-_Attachment_4.docx
DOCX document 488 KB Posted
- Attached to
- Solicitation Notice Federal contract opportunity
- Solicitation number
- FA8773-17-R-8005
About this file
Sample Psychomotor Lesson
View the file
Other files for this federal contract opportunity
Show all 50
Solicitation Notice has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNCLASSIFIED
| UNCLASSIFIED |
| C-2106L-TM |
39 IOS, 12 July 2017
Section L, Attachment 4
Windows Foundations
C-2106L-TM
Student Lab Manual
12 July 2017
Table of Contents
| Table of Contents | 2 |
| Initial Lab Setup | 9 |
| IP Configuration | 9 |
| Lab 1: PowerShell Familiarization | 10 |
| Procedures | 10 |
| Lab 2: WMIC Familiarization | 11 |
| Procedures | 11 |
C-2106L-TM Windows Foundations
SECTION I – OVERVIEW
The following labs are intended to be used in conjunction with the Windows Foundations Student Guide and integrated within the lecture. The labs are intended to support the cognitive material to provide students with a deeper understanding of the concepts, security implications, and methods used to survey both local and remote systems within a domain environment. The labs will demonstrate methods for querying, navigating, and manipulating the Windows file system. Additionally, labs will have students querying and modifying registry and security settings as well as interrogating and manipulating services. The Windows Foundations lesson includes heavy emphasis on performance-based skills, whereas students implement tasks, and are required to utilize command line interface as well as utilities, regedit.exe, WMIC, PowerShell, and the Sysinternals Suite to analyze system information to identify normal, baselined activity versus anomalous, and malicious activity. Comment by RADOS, RACHEL A GG-13 USAF AFSPC 39 IOS/DOW: These ……. and Comment by RADOS, RACHEL A GG-13 USAF AFSPC 39 IOS/DOW: Delineate baselined from anomalous activity, and identify malicious activity.
PERFORMANCE OBJECTIVES:
| CONDITION(S) |
| PERFORMANCE/BEHAVIOR |
| STANDARD(S) |
Given (references, tools, etc.):
1. Access to the CWO Student Labnet environment
2. Copy of the Student Guide and Lab Guide
3. Students Notes
Task(s):
a. Leverage the PowerShell Help system
b. Perform Windows tasks on local system using PowerShell
c. Leverage the WMIC to perform basic tasks on a local Windows system
Criteria:
Go/ No-Go Demonstration:
Correctable to 100% in class
SUPPORT MATERIAL AND GUIDANCE
STUDENT INSTRUCTIONAL MATERIAL: Students will receive C-2106L/TM Student and Lab Guides
STUDENT PREPARATION/READING ASSIGNMENTS: Students should read all pages in the student guide prior to the lecture. Additional reading from the reference material will enhance understanding of the material contained in this lab guide.
SECTION II - STUDENT OUTLINE
Initial Lab Setup Introduction The labs in this manual use a virtualized environment that consists of individual student network environments and a shared training range. These labs are specifically designed to work within this environment, but could be modified to work within a production environment consisting of similar systems.
| Purpose |
| Determine network interface settings for virtual machines (VM). |
Determine the reachability of hosts on the network.
IP Configuration
1. Open the following virtual machines (VM) and use the provided credentials:
| VM |
| Username |
| Password |
| Hostname |
| IP Address |
| Windows 10 |
| Student |
| ST@dm1n! |
| Windows 7 |
| Student |
| ST@dm1n! |
2. Determine the IP addresses and hostname for each VM. Record this information in the table provided.
2.1. Note: If you are unsure of the commands to use, type help and a list of available commands will populate your screen. Once you see a command that may fit what your needs are, you can query the help for it by following the command with a “/?”.
Example: netsh /?
Lab 1: PowerShell Familiarization Introduction This lab is meant to provide the basic foundation for using PowerShell cmdlets to gather system details and utilize the help function to be able to build commands. PowerShell commands will be included in follow-on labs to provide additional usage options and alternative methods for gathering information and assessing systems. For further comprehension of the underlying concepts consult the references in Section I or the additional content in Appendix 1 and 2 of this Student Lab Manual.
| Purpose |
| To gain practical experience with the PowerShell help cmdlet |
To gain practical experience with <tab>complete functionality
To gain a basic understanding of PowerShell command usage
Procedures
Perform the following on the Windows 10 VM
Open an Administrative PowerShell prompt
PowerShell cmdlets follow a verb-noun format; such as the options below
a. Get-Something
b. Set-Something
c. New-Something
d. Remove-Something
Type get-help to view the help dialog
Using the output from the above command. How would you search for cmdlets relating to processes?
e. Answer:____________________________________________________________
Now we will explore the available cmdlets by using the get-command cmdlet
Get-command –verb get
Get-command –verb add
As you should have seen with the previous two commands, there are many different cmdlets and Functions available within PowerShell. Another option that we have to view available options is to leverage the tab complete functionality within PowerShell.
For this next step you will leverage tab to cycle through available options. Type in the following and then cycle through with tab.
Get-pr (Now hit the Tab key until you come to get-process, then hit enter)
Lab 2: WMIC Familiarization
Introduction
This lab is meant to provide you with some of the basics for utilizing the Windows Management Instrumentation Console (WMIC). It will highlight how to use help as well as the basic syntax for formulating queries. Where applicable, follow-on labs will provide examples and tasks for you to build off of the basic concepts outlined in this lab. WMIC is an outstanding tool that will be present on everything from Windows XP through Windows 10 and their associated Server systems. It is simply yet another way to gather information, and there may be times that means such as PowerShell may not be available, so knowing another way will be critical to your success.
| Purpose |
| Learn how to use the help function |
Learn how to build commands
Leverage WMIC to gather system details
Procedures
Perform the following on the Windows 10 VM
1. WMIC Help functions just like the Windows help function; meaning that we can simply add a /? following the command we want help with.
For example, if you need to know what alias options you have to use with WMIC you will enter the following command: (Type in the commands to add context to the statements below) wmic /?
If you want to find out what options you have for the “Startup” alias, you will build your help command to the following:
wmic startup /?
If you want a listing of the available options for the verb list, you would build out your help syntax to the following:
wmic startup list /?
We could then finalize our command to be:
wmic startup list full
The commands that you type into WMIC are formatted in the WMI Query Language (WQL), which Microsoft states is a subset of SQL. There are many elements of WQL which we'll use throughout this course, so the goal is for you to have the necessary foundation in place by the end of this lab.
The syntax includes these key words:
· list: shows a list of something.
· get: gets one or more values of an attribute. You could get a list of things, separated by commas.
· create: creates an element, which can be used to run programs.
· delete: deletes an element, which can be used to kill processes, among other things.
· where: these clauses can match some property to help us sort through a long list of things, for
· example: where name=“cmd.exe”
· /every:[N]: Run this command every N seconds, which works for displaying items, but not creating or deleting them.
The essential format of WMIC syntax revolves around WQL as follows. We type in a WMIC command followed by an area we are interested in, known as an “alias”. That is the arena we want WMIC to interact with, such as process, startup, ntevent, nicconfig, etc. For a full list, look at the output of wmic /?.
wmic [alias] [where with where clause] [verb with verb clause]
Then, we have an option of including a “where” keyword with a where clause. These clauses look rather like SQL, and we'll see that they have many of the same options as SQL, including OR, AND, and LIKE notation.
Finally, we get to a verb and verb clause, which tells WMIC what we want it to do with the instances of things within the given alias that match the where clause. Options here include get, delete, list, and call.
Also, you can get a list of process name, processids, and command-lines used to invoke each program with this little WQL:
wmic process get name, processid, commandline
Looking at processes is nice, but sometimes security pro or sys admin needs to kill processes. You can do this with WMIC as follows:
wmic process [pid] delete
Alternatively, you can kill all processes with a given name, rather like the “killall –9 [name]” command would work on Unix or Linux, as follows:
wmic process where name="cmd.exe" delete
You could even do that remotely, with the user name, password, and node syntax we described earlier, killing all cmd.exe's running on a different machine, provided that you had administrative credentials on that system.
But, WMIC doesn't let you just view and kill processes. You can also start processes, using this syntax to run calc.exe:
wmic process call create calc.exe
Now that you have a basic foundation with WMIC, we will leverage WMIC more in the following labs.
1. emonstrate how this key is populated, bring up Internet explorer and type in a few random URLs. Once refresh and record how the entries are sorted. _________________________________________________________________________
2. Navigate to HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR. This key stores information about USB devices connected to the system. You should see one device for this system. Record its information below.
a. Vendor (FriendlyName): ______________________________________________
b. Serial Number: ______________________________________________________
3. What would your command be to query the registry key in item 10 using reg.exe from the command line? ____________________________________________________
Procedures
Perform the following on the Windows 10 VM
1. The first thing you’ll do is discover the Windows Firewall's current configuration properties. You can query Windows Firewall settings using the following netsh advfirewall command:
netsh advfirewall firewall show rule name=all
2. It's typically a best practice to leave Windows Firewall enabled, but sometimes when you're performing testing or setting up new applications, you need to turn Windows Firewall off for a period. The following commands illustrate how to turn Windows Firewall off and then back on:
netsh advfirewall set allprofiles state off netsh advfirewall set allprofiles state on
3. If you make a mistake configuring Windows Firewall, you might want to use the following netsh command to reset it back to its default settings:
netsh advfirewall reset
NOTE: This would seldom, if ever, be used in the operational environment, but here in training this command can be useful to get things working.
4. The Windows Firewall log can be configured to either use the default location or a custom location. The default path for the Windows Firewall log files is \Windows\system32\LogFiles\Firewall\pfirewall.log.
5. The netsh command below changes the location of the log file to the C:\temp directory:
netsh advfirewall set currentprofile logging filename "C:\temp\pfirewall.log"
Allow and Prevent Ping
Perform the following on the Windows 10 VM
6. You can use netsh to control how a given system responds to ping requests. The following two netsh commands show how you can block and then open Windows Firewall to ping requests:
netsh advfirewall firewall add rule name="All ICMP V4" dir=in action=block protocol=icmpv4
Perform the following on the Windows 7 VM
7. Perform a ping against the Windows 10 system. Did you get a response? ___________
Hint: If the ping isn’t blocked, ensure the firewall is ON.
Perform the following on the Windows 10 VM
8. For the purposes of our labs, we want to allow ping, so we want to enable ping. Document your command below:
Enable and Delete a Port
9. One of the most common things you need to do with Windows Firewall is open ports that are used by different programs. The following examples show how to use netsh to create a rule to open and then close port 1433, which is used by Microsoft SQL Server:
netsh advfirewall firewall add rule name="Open SQL Server Port 1433" dir=in action=allow protocol=TCP localport=1433 netsh advfirewall firewall delete rule name="Open SQL Server Port 1433" protocol=tcp localport=1433
Enable a Program
Another common task is opening Windows Firewall for a given program. The following example illustrates how to add a rule that enables Windows Live Messenger to work through Windows Firewall:
netsh advfirewall firewall add rule name="Allow Messenger" dir=in action=allow program="C:\programfiles\messenger\ msnmsgr.exe"
Enable Remote Management
Another common requirement, especially when you're setting up new systems, is to enable remote management so that tools such as the Microsoft Management Console (MMC) can connect to remote systems. To open Windows Firewall for remote management, you can use the following command:
netsh advfirewall firewall set rule group="windows remote management" new enable=yes
Enable Remote Desktop Connection
One of the first things to do with most of the server systems is to set up “enable Remote Desktop Connection” for easy remote systems management. The following command shows how to use netsh to open Windows Firewall for Remote Desktop Connections:
netsh advfirewall firewall set rule group="remote desktop" new enable=Yes
Export and import firewall settings
After you get Windows Firewall configured, it's a good idea to export your settings so that you can easily reapply them later or import them into another system. In the following netsh commands, you can see how to export and then import your Windows Firewall configuration:
netsh advfirewall export "C:\temp\WFconfiguration.wfw" netsh advfirewall import "C:\temp\WFconfiguration.wfw"
NOTE: Blockinbound will block inbound network traffic that does not match an inbound rule. This is the default setting and allows rules to come in. Blockinboundalways blocks all inbound network traffic, including traffic that matches an inbound rule. If Blockinboundalways is used, there must be instructions in the rule for how to handle outbound traffic.
Perform the following on the Windows 7 VM
Record your commands:
1. Reset firewalls to previous state.
2. View the current state of the Windows firewall for all profiles.
3. Set the firewall to be on and not allowing incoming traffic.
4. Remove all inbound rules from the firewall. (Note: In #3, we made a rule to turn on the firewall and block incoming traffic. In #4, we are clearing out any previously set inbound rules.)
5. Enable ping through the firewall. Test by pinging the Windows 10 VM.
6. Add an inbound rule(s), to a local machine to allow inbound TCP traffic across port 445. For the remote IP, use the 10 VM IP address.
7. Set the firewall to allow incoming traffic on current profile.
8. View all the rules.
9. View only the inbound rules.
10. Reset firewall to previous state.
Appendix 1 – Command Refresher
1. Useful aides that will help the students in the labs here. Example: Command Line quick reference.
Appendix 2 – Advanced Challenges This section is for stuff pertaining to Labs. Place additional advances labs here for student who excel.
1. Putt stuff here
Attachment 1 – Lab Solutions Lab 1 Solutions
1. An Answer
2. An Answer
Lab 2 Solutions
1. An Answer
2. An Answer
UNCLASSIFIED
| UNCLASSIFIED |
| 2 |
image3.jpeg image2.png
File details come from the government source that posted it. Updated .