configuration du reseau

Créer les VMnets dans VMware

VMnetModeUsage
VMnet10Host-onlyVLAN AD/LAN
VMnet11Host-onlyVLAN DMZ
VMnet12Host-onlyVLAN SOC
VMnet13Host-onlyVLAN DevOps
VMnet14Host-onlyVLAN Red Team

![[Pasted image 20260707155924.png]]

configuration du firewall

nous avons mis sur une vm un parefeu OPNSense

configuration de l’AD DS

Déployer des contrôleurs de domaine AD DS

ip add : 10.10.0.10 nom : DC01

VMVMnet correctIP attendue
DC01, CL01VMnet1010.10.0.x ✅
Serveur Web (DMZ)VMnet1110.20.0.x ✅
Kali (Red Team)VMnet1210.50.0.x
Wazuh (SOC)VMnet1310.30.0.x
Docker/K8sVMnet1410.40.0.x

Architecture Lab Cybersécurité — nyoma.local

Informations générales

ÉlémentValeur
Domaine ADlab.local
HyperviseurVMware Workstation Pro
HôteIntel i7-11850H · 32 Go RAM · 954 Go
FirewallOPNsense 26.1.6_2 (amd64)
Contrôleur de domaineDC01 — Windows Server 2025

Topologie réseau

Internet (WiFi — Livebox)
        │
        │ NAT VMware (VMnet8 — 192.168.98.0/24)
        │
┌───────▼────────────────────────────────────────────┐
│              OPNsense Firewall                      │
│   WAN : em1 → 192.168.98.133/24 (DHCP NAT)        │
│   OPT1: em0 → 10.10.0.1/24  (AD/LAN)              │
│   OPT2: em2 → 10.20.0.1/24  (DMZ)                 │
│   OPT3: em3 → 10.30.0.1/24  (SOC)                 │
│   OPT4: em4 → 10.40.0.1/24  (DevOps)              │
│   OPT5: em5 → 10.50.0.1/24  (Red Team)            │
└────┬──────────┬──────────┬──────────┬──────────────┘
     │          │          │          │
  VMnet10    VMnet11    VMnet13    VMnet14
  AD/LAN      DMZ        SOC      Red Team
  10.10.0     10.20.0   10.30.0   10.50.0

Plan d’adressage VLAN

VLANZoneSubnetGatewayVMnetPlage DHCP
OPT1AD / LAN10.10.0.0/2410.10.0.1VMnet1010.10.0.100–200
OPT2DMZ10.20.0.0/2410.20.0.1VMnet1110.20.0.100–200
OPT3SOC / SIEM10.30.0.0/2410.30.0.1VMnet1310.30.0.100–200
OPT4DevOps10.40.0.0/2410.40.0.1VMnet1410.40.0.100–200
OPT5Red Team10.50.0.0/2410.50.0.1VMnet1210.50.0.100–200

Note mapping VMnet réel : VMnet12→OPT5 (Red Team), VMnet13→OPT3 (SOC), VMnet14→OPT4 (DevOps)


Inventaire des machines virtuelles

✅ Déployées

VMOSIPVMnetZoneRAMStatut
OPNsenseOPNsense 26.1.610.10.0.1 (LAN)NAT+tousFirewall2 Go✅ Opérationnel
DC01Windows Server 202510.10.0.10VMnet10AD/LAN4 Go✅ Opérationnel
CL01Windows 11 Pro10.10.0.101 (DHCP)VMnet10AD/LAN4 Go✅ Jointé au domaine
Wazuh-SOCUbuntu 22.04 LTS10.30.0.10VMnet13SOC8 Go🔧 En cours
Kali LinuxKali 2026.210.50.0.xVMnet12Red Team4 Go⚠️ Internet KO

⏳ À déployer

VMOSIP prévueVMnetZoneRAM
DC02Windows Server 202510.10.0.11VMnet10AD/LAN2 Go
Serveur WebUbuntu 22.04 LTS10.20.0.10VMnet11DMZ2 Go
Docker/K8sUbuntu 22.04 LTS10.40.0.10VMnet14DevOps6 Go

Active Directory

Forêt et domaine

ParamètreValeur
Forest Rootlab.local
NetBIOSLAB
DC PrincipalDC01.lab.local (10.10.0.10)
DC SecondaireDC02.child.lab.local (à déployer)
OS DCWindows Server 2025 Datacenter Evaluation
Rôles FSMOSchemaMaster, DomainNamingMaster, PDCEmulator, RIDMaster

Structure OU

DC=lab,DC=local
└── OU=Corp
    ├── OU=Users
    │   ├── OU=Direction    → Groupe: GG_Direction
    │   ├── OU=IT           → Groupes: GG_IT_Admin, GG_IT_Support
    │   ├── OU=Finance      → Groupe: GG_Finance
    │   ├── OU=RH           → Groupe: GG_RH
    │   ├── OU=Marketing    → Groupe: GG_Marketing
    │   └── OU=Support      → Groupes: GG_Sales, GG_Production
    ├── OU=Servers
    ├── OU=Admins
    └── OU=ServiceAccounts  → Groupe: GG_Backup_Operators

Utilisateurs créés (25)

Nom completUsernameGroupeDépartement
Michel NyobemnyobeGG_IT_AdminIT
Sarah LaurentslaurentGG_DirectionDirection
Thomas DuboistduboisGG_DirectionDirection
Julien MoreaujmoreauGG_IT_SupportIT
Clara PetitcpetitGG_FinanceFinance
Antoine MartinamartinGG_MarketingMarketing
Laura BernardlbernardGG_FinanceFinance
Kevin RobertkrobertGG_ProductionSupport
Sophie LeroysleroyGG_RHRH
Hugo FontainehfontaineGG_IT_AdminIT
Emma RousseauerousseauGG_MarketingMarketing
Lucas GarnierlgarnierGG_IT_SupportIT
Inès ChevalierichevalierGG_MarketingMarketing
Nathan GirardngirardGG_IT_SupportIT
Camille BonnetcbonnetGG_FinanceFinance
Maxime MarchandmmarchandGG_Server_AdminsFinance
Léa DupontldupontGG_Backup_OperatorsRH
Enzo MercieremergierGG_IT_SupportSupport
Chloé FaurecfaureGG_MarketingMarketing
Adam NoelanoelGG_SalesSupport

Comptes spéciaux (Red Team)

UsernameMot de passeGroupeObjectif
jmoreauWelcome1GG_IT_SupportPassword Spray
svc-backupBackup123GG_Backup_OperatorsKerberoasting
adm-techAdmin@Tech2024!Domain AdminsPrivilege escalation

Services configurés

OPNsense

ServiceStatutConfig
Kea DHCPv4✅ Actif5 subnets (10.x0.0.100-200)
NAT Outbound✅ ActifHybrid mode — toutes interfaces
Firewall Rules✅ ActifPass sur OPT1–OPT5
DNS Unbound⏳ À configurer
NTP⏳ À configurerpool.ntp.org
SSH✅ ActifPort 22

Active Directory (DC01)

ServiceStatut
AD DS✅ Opérationnel
DNS Server✅ Opérationnel
DHCP (Windows)Non utilisé (OPNsense gère)
CL01 jointé✅ LAB\cpetit connecté

Phases du projet

PhaseDescriptionStatutProgression
Phase 1Infrastructure réseau (OPNsense + VLANs)🔧 En cours90%
Phase 2Active Directory (DC01 + users)✅ Terminée85%
Phase 3SOC / Blue Team (Wazuh + ELK)🔧 En cours5%
Phase 4DMZ & Applications web⏳ À faire0%
Phase 5DevOps (Docker + K8s)⏳ À faire0%
Phase 6Red Team (Kali + C2)⏳ À faire10%

Machines Virtuelles — Lab Cybersécurité

VMs déployées

VMOSIPVMnetRAMCPUDisqueStatut
OPNsenseOPNsense 26.1.610.10.0.1NAT + tous2 Go2 vCPU20 Go✅ Opérationnel
DC01Windows Server 202510.10.0.10VMnet104 Go2 vCPU60 Go✅ Opérationnel
CL01Windows 11 Pro10.10.0.101VMnet104 Go4 vCPU80 Go✅ Jointé au domaine
Kali LinuxKali 2026.210.50.0.xVMnet128 Go4 vCPU80 Go⚠️ Internet KO
Wazuh-SOCUbuntu 22.04 LTS10.30.0.10VMnet138 Go2 vCPU100 Go🔧 En cours

VMs à déployer

VMOSIP prévueVMnetRAMCPUDisqueZone
DC02Windows Server 202510.10.0.11VMnet102 Go2 vCPU60 GoAD/LAN
Serveur WebUbuntu 22.04 LTS10.20.0.10VMnet112 Go2 vCPU40 GoDMZ
ZabbixUbuntu 22.04 LTS10.30.0.20VMnet134 Go2 vCPU50 GoSOC
Docker/K8sUbuntu 22.04 LTS10.40.0.10VMnet146 Go2 vCPU100 GoDevOps

Budget RAM total

VMRAMCPUStatut
OPNsense2 Go2 vCPU✅ Active
DC014 Go2 vCPU✅ Active
DC022 Go2 vCPU⏳ À déployer
CL014 Go2 vCPU✅ Active
Wazuh4 Go2 vCPU✅ Active
Zabbix3 Go2 vCPU✅ Active
Kali Linux8 Go4 vCPU✅ Active
Serveur Web1 Go2 vCPU✅ Active
Docker/K8s6 Go2 vCPU⏳ À déployer
TOTAL40 Go22 vCPU⚠️ Dépasse 32 Go

⚠️ Attention : Le total prévu (40 Go) dépasse la RAM de l’hôte (32 Go). Ne jamais démarrer toutes les VMs en même temps. Démarrer uniquement les VMs nécessaires à la phase en cours.

Recommandation démarrage par phase

PhaseVMs à démarrerRAM utilisée
Phase 1-2 (AD)OPNsense + DC01 + CL0110 Go
Phase 3 (SOC)+ Wazuh + Zabbix22 Go
Phase 4 (DMZ)+ Serveur Web24 Go
Phase 5 (DevOps)+ Docker/K8s30 Go
Phase 6 (Red Team)+ Kali (arrêter Docker)28 Go

Règles firewall inter-VLAN

SourceDestinationActionRègle
OPT1 (LAN)Any✅ PassAllow LAN to any
OPT2 (DMZ)Any✅ PassAllow DMZ to any
OPT3 (SOC)Any✅ PassAllow SOC to any
OPT4 (DevOps)Any✅ PassAllow DevOps to any
OPT5 (RedTeam)Any✅ PassAllow RedTeam to any
WANNATHybrid outbound NAT

Roadmap Lab Cybersécurité — Réaliste & Avancé

Objectifs : CPTS (HTB) · CWES · CRTL (ZeroPoint) · Red Team · Exploit Dev · SOC Avancé


Architecture finale visée

Internet
    │
OPNsense (Firewall/Router)
    │
    ├── VLAN 10 (AD/LAN)     → DC01, DC02, CL01, Matrix (Jump)
    ├── VLAN 20 (DMZ)        → Serveur Web vulnérable
    ├── VLAN 30 (SOC)        → Wazuh, Zabbix
    ├── VLAN 40 (DevOps)     → Docker/K8s (plus tard)
    └── VLAN 50 (Red Team)   → Kali, C2

ÉTAT ACTUEL DES VMs

VMStatutIPRôle
OPNsense✅ Opérationnel10.10.0.1Firewall/Router
DC01✅ Opérationnel10.10.0.10Forest lab.local
CL01✅ Jointé domaine10.10.0.101Poste victime
Kali Linux✅ Opérationnel10.50.0.xAttaquant
Wazuh✅ Opérationnel10.30.0.100SIEM/EDR
Zabbix✅ Opérationnel10.30.0.101Monitoring
Matrix✅ Opérationnel10.20.0.101Application web
DC02⏳ À installer10.10.0.11Child domain

PHASE 1 — Socle réseau et sécurité (FAIT À 90%)

Objectif : infrastructure stable et sécurisée

  • OPNsense installé et configuré
  • 5 VLANs opérationnels (10/20/30/40/50)
  • Kea DHCP fonctionnel sur tous les VLANs
  • Règles firewall inter-VLAN
  • NAT Outbound configuré
  • DNS Unbound activé
  • NTP configuré (pool.ntp.org)
  • IDS/IPS Suricata activé sur OPNsense
  • Réparer internet Kali (VMnet12)

PHASE 2 — Active Directory réaliste (FAIT À 85%)

Objectif : environnement AD d’entreprise avec vulnérabilités intentionnelles

  • DC01 Windows Server 2025 — Forest lab.local
  • 25 utilisateurs + groupes (script PowerShell)
  • Structure OU réaliste (IT/Finance/RH/Direction…)
  • CL01 jointé au domaine
  • Comptes faibles : jmoreau (Welcome1) · svc-backup (Backup123)
  • Domain Admin : adm-tech
  • DC02 — Child domain child.lab.local
  • GPO de sécurité de base
  • Auditing activé (logon, object access, privilege use)
  • Matrix — Jump server configuré
  • Kerberoasting : SPN sur svc-backup
  • AS-REP Roasting : compte sans pré-auth Kerberos
  • ACL abusable : WriteDACL, GenericAll sur certains objets
  • Délégation Kerberos non contrainte (unconstrained)
  • AdminSDHolder mal configuré
  • AD CS vulnérable (ESC1, ESC8) sur DC01

PHASE 3 — SOC & Monitoring (EN COURS)

Objectif : détection en temps réel de toutes les attaques

3.1 Wazuh (SIEM/EDR)

  • Wazuh Manager installé (Ubuntu 22.04 — 10.30.0.10)
  • Internet fonctionnel sur Wazuh
  • Dashboard Wazuh accessible
  • Agent Wazuh sur DC01
  • Agent Wazuh sur CL01
  • Agent Wazuh sur DC02 (après install)
  • Règles de détection AD :
    • Kerberoasting (Event 4769)
    • Pass-the-Hash (Event 4624 type 3)
    • DCSync (Event 4662)
    • Golden Ticket (Event 4768)
    • BloodHound (LDAP massif)
    • Mimikatz (lsass access)
  • Alertes email/Slack configurées

3.2 Zabbix (Monitoring infrastructure)

  • Zabbix Server installé (Ubuntu 22.04 — 10.30.0.20)
  • Monitoring DC01 (CPU, RAM, services AD)
  • Monitoring CL01
  • Monitoring OPNsense (SNMP)
  • Monitoring Wazuh lui-même
  • Dashboard personnalisé lab
  • Alertes sur services critiques (AD DS, DNS, Kerberos)

3.3 ELK Stack (optionnel — avancé)

  • Elasticsearch + Kibana sur Wazuh ou VM dédiée
  • Intégration logs OPNsense → ELK
  • Intégration logs DC01 → ELK
  • Dashboards de visualisation

PHASE 4 — Jump Server & Matrix (Pivoting)

Objectif : simuler un accès réaliste au SI via un point d’entrée

Matrix (Jump server — 10.10.0.50)

  • VM Ubuntu ou Windows Server installée
  • SSH/RDP accessible depuis Kali
  • Connecté au VLAN AD/LAN (VMnet10)
  • Agent Wazuh installé
  • Pivot depuis Kali → Matrix → DC01

Scénarios de pivoting

  • Port forwarding SSH (ssh -L, -R, -D)
  • Chisel/Ligolo-ng pour tunneling
  • Pivoting via SOCKS5
  • Double pivot : Kali → Matrix → CL01 → DC01

PHASE 5 — Red Team & C2 (Kali + C2)

Objectif : attaques réalistes, techniques CPTS/CWES/CRTL

5.1 C2 Framework

  • Réparer internet Kali (VMnet12 → 10.50.0.x)
  • Havoc C2 installé sur Kali
    • Team server configuré
    • Listener HTTPS sur port 443
    • Payload généré pour CL01
  • Sliver C2 (backup/alternative)
    • mTLS listener
    • Implant généré

5.2 Attaques AD (CPTS/CRTL)

  • Reconnaissance
    • BloodHound + SharpHound (graphe AD)
    • ldapdomaindump
    • enum4linux-ng
    • CrackMapExec / NetExec
  • Initial Access
    • Password Spray (jmoreau → Welcome1)
    • AS-REP Roasting
    • Phishing simulé (GoPhish)
  • Privilege Escalation
    • Kerberoasting (svc-backup → Backup123)
    • ACL abuse (WriteDACL)
    • Token impersonation
    • Unconstrained delegation
  • Lateral Movement
    • Pass-the-Hash
    • Pass-the-Ticket
    • OverPass-the-Hash
    • WMI / PSExec / SMBExec
  • Domain Dominance
    • DCSync (secretsdump)
    • Golden Ticket
    • Silver Ticket
    • Diamond Ticket
    • AD CS ESC1/ESC8
    • Cross-domain attack (lab.local → child.lab.local)
  • Persistence
    • Skeleton Key
    • AdminSDHolder backdoor
    • GPO abuse
    • DCShadow

5.3 Développement d’exploit (CWES)

  • VM dédiée exploit dev (Windows 10 + outils)
  • Buffer overflow (x86/x64)
  • SEH exploitation
  • ROP chains
  • Bypass DEP/ASLR
  • Shellcode custom

5.4 Evasion EDR (CRTL)

  • Bypass Wazuh/AV
    • Process hollowing
    • DLL sideloading
    • AMSI bypass
    • ETW patching
    • Unhooking NTDLL
  • Obfuscation payloads
    • Encodage shellcode
    • Payload chiffré AES
    • In-memory execution
  • Living off the Land (LOLBins)
    • certutil, regsvr32, mshta
    • PowerShell constrained mode bypass

PHASE 6 — DMZ & Applications Web (après certifs)

Objectif : pentest web réaliste

  • Serveur Ubuntu en DMZ (VMnet11 — 10.20.0.10)
  • Apache/Nginx installé
  • DVWA (Damn Vulnerable Web App)
  • WebGoat
  • Juice Shop (OWASP)
  • Application custom avec vulnérabilités :
    • SQLi, XSS, SSRF, IDOR, LFI/RFI
  • WAF OPNsense en frontal

PHASE 7 — Docker & Kubernetes (PLUS TARD)

  • VM Ubuntu DevOps (VMnet14 — 10.40.0.10)
  • Docker installé
  • Kubernetes K3s cluster
  • Jenkins CI/CD
  • Pipeline sécurisé avec scan SAST/DAST

PLANNING RECOMMANDÉ

Semaine 1-2 (maintenant)

1. Finir Phase 1 → DNS Unbound + NTP + Suricata
2. Réparer internet Kali
3. Installer Wazuh complètement + agents
4. Configurer Zabbix monitoring

Semaine 3-4

5. DC02 child domain
6. Vulnérabilités AD intentionnelles
7. Jump server Matrix
8. BloodHound reconnaissance

Semaine 5-6

9. C2 Havoc opérationnel
10. Premières attaques AD avec détection Wazuh
11. Password Spray + Kerberoasting
12. Exercice Red vs Blue

Semaine 7-8

13. Lateral movement + Domain dominance
14. Evasion EDR
15. Développement exploit (CWES)
16. Préparation certifs CPTS/CRTL

CERTIFICATIONS VISÉES

CertifOrganismeCompétencesLien avec le lab
CPTSHackTheBoxPentest complet, AD, WebPhases 2+5+6
CWESHackTheBoxExploit Web avancéPhase 6
CRTLZeroPointRed Team, C2, EvasionPhase 5

RESSOURCES RAM — DÉMARRAGE PAR SCÉNARIO

ScénarioVMs activesRAM
AD lab seulOPNsense+DC01+CL0110 Go
SOC actif+Wazuh+Zabbix18 Go
Red Team+Kali+C226 Go
Avec DC02+Matrix+DC02+Matrix30 Go
Tout (max)Toutes~40 Go ⚠️

Ne jamais dépasser 28-30 Go actifs simultanément sur 32 Go RAM hôte.