configuration du reseau Créer les VMnets dans VMware VMnet Mode Usage VMnet10 Host-only VLAN AD/LAN VMnet11 Host-only VLAN DMZ VMnet12 Host-only VLAN SOC VMnet13 Host-only VLAN DevOps VMnet14 Host-only VLAN Red Team ![[Pasted image 20260707155924.png]] configuration du firewall nous avons mis sur une vm un parefeu OPNSense configuration de l’AD DS Déployer des contrôleurs de domaine AD DS ip add : 10.10.0.10 nom : DC01 VM VMnet correct IP attendue DC01, CL01 VMnet10 10.10.0.x ✅ Serveur Web (DMZ) VMnet11 10.20.0.x ✅ Kali (Red Team) VMnet12 10.50.0.x ✅ Wazuh (SOC) VMnet13 10.30.0.x ✅ Docker/K8s VMnet14 10.40.0.x ✅ Architecture Lab Cybersécurité — nyoma.local Informations générales Élément Valeur Domaine AD lab.local Hyperviseur VMware Workstation Pro Hôte Intel i7-11850H · 32 Go RAM · 954 Go Firewall OPNsense 26.1.6_2 (amd64) Contrôleur de domaine DC01 — Windows Server 2025 Topologie réseau Internet (WiFi — Livebox) │ │ NAT VMware (VMnet8 — 192.168.98.0/24) │ ┌───────▼────────────────────────────────────────────┐ │ OPNsense Firewall │ │ WAN : em1 → 192.168.98.133/24 (DHCP NAT) │ │ OPT1: em0 → 10.10.0.1/24 (AD/LAN) │ │ OPT2: em2 → 10.20.0.1/24 (DMZ) │ │ OPT3: em3 → 10.30.0.1/24 (SOC) │ │ OPT4: em4 → 10.40.0.1/24 (DevOps) │ │ OPT5: em5 → 10.50.0.1/24 (Red Team) │ └────┬──────────┬──────────┬──────────┬──────────────┘ │ │ │ │ VMnet10 VMnet11 VMnet13 VMnet14 AD/LAN DMZ SOC Red Team 10.10.0 10.20.0 10.30.0 10.50.0 Plan d’adressage VLAN VLAN Zone Subnet Gateway VMnet Plage DHCP OPT1 AD / LAN 10.10.0.0/24 10.10.0.1 VMnet10 10.10.0.100–200 OPT2 DMZ 10.20.0.0/24 10.20.0.1 VMnet11 10.20.0.100–200 OPT3 SOC / SIEM 10.30.0.0/24 10.30.0.1 VMnet13 10.30.0.100–200 OPT4 DevOps 10.40.0.0/24 10.40.0.1 VMnet14 10.40.0.100–200 OPT5 Red Team 10.50.0.0/24 10.50.0.1 VMnet12 10.50.0.100–200 Note mapping VMnet réel : VMnet12→OPT5 (Red Team), VMnet13→OPT3 (SOC), VMnet14→OPT4 (DevOps) ...

10 min · Michel NYOBE

![[Pasted image 20260809213119.png]] Bienvenue dans le laboratoire CADP — un environnement de test d’intrusion Active Directory multi-forêts conçu pour simuler un réseau d’entreprise réel. Votre objectif est de commencer en tant qu’attaquant externe et de compromettre le contrôleur de domaine racine de la forêt (DC01-VANGUARD) .

1 min · Michel NYOBE

Etapes Configurer le controleur de Domaine (DC01) nom du domaine : nyoma.local Créer des objets utilisateur departement / OU Direction IT Finance RH Marketing Sales Support Production Nom complet Username Groupe Michel Nyobe mnyobe GG_IT_Admin Sarah Laurent slaurent GG_RH Thomas Dubois tdubois GG_Finance Julien Moreau jmoreau GG_IT_Support Clara Petit cpetit GG_Marketing Antoine Martin amartin GG_Sales Laura Bernard lbernard GG_Sales Kevin Robert krobert GG_Production Sophie Leroy sleroy GG_RH Hugo Fontaine hfontaine GG_IT_Admin Emma Rousseau erousseau GG_Finance Lucas Garnier lgarnier GG_IT_Support Inès Chevalier ichevalier GG_Marketing Nathan Girard ngirard GG_Production Camille Bonnet cbonnet GG_Direction Maxime Marchand mmarchand GG_Server_Admins Léa Dupont ldupont GG_Backup_Operators Enzo Mercier emergier GG_IT_Support Chloé Faure cfaure GG_Marketing Adam Noel anoel GG_Sales 1 compte service faible : svc-backup Mot de passe : Backup123 Groupe : GG_Backup_Operators ...

3 min · Michel NYOBE

Infrastructure as Code (IaC) — le cœur de l’automatisation. Terraform (ou OpenTofu) pour provisionner/détruire, Ansible pour configurer les machines, Packer pour fabriquer des images-templates prêtes à cloner. Orchestration & développement backend — c’est ce qui transforme le « bouton » en actions. Une API + une file d’attente de tâches (Celery, BullMQ, ou Temporal pour les workflows longs), qui déclenche un terraform apply, enregistre une échéance, et planifie le terraform destroy. C’est là que vit la logique « TTL 48 h ». Réseau & sécurité réseau — segmentation stricte, un VPN par utilisateur (WireGuard ou OpenVPN), et surtout l’isolation multi-tenant : un étudiant ne doit jamais pouvoir atteindre le lab d’un autre ni votre infrastructure. Active Directory & Windows — savoir construire des AD volontairement vulnérables (mauvaises ACL, Kerberoasting, délégations, chemins d’attaque BloodHound). ...

1 min · Michel NYOBE

Installation du lab Active Directory Creation des VM et preparation de l’infrastructure DC01 ip : 192.168.17.136 system : windows server 2019 nom du domaine : nyom.local ![[Pasted image 20260410092015.png]] Creation des roles ACtive directory ![[Pasted image 20260410092613.png]] Creation des utilisateurs nous avons creer 20 utilisateurs OU add ![[Pasted image 20260410094759.png]] ![[Pasted image 20260410094825.png]] Enumeration AD ![[Pasted image 20260410105303.png]] PORT STATE SERVICE REASON VERSION 53/tcp open domain syn-ack ttl 128 Simple DNS Plus 88/tcp open kerberos-sec syn-ack ttl 128 Microsoft Windows Kerberos (server time: 2026-04-10 08:48:31Z) 135/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC 139/tcp open netbios-ssn syn-ack ttl 128 Microsoft Windows netbios-ssn 389/tcp open ldap syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: nyoma.local0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? syn-ack ttl 128 464/tcp open kpasswd5? syn-ack ttl 128 593/tcp open ncacn_http syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped syn-ack ttl 128 3268/tcp open ldap syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: nyoma.local0., Site: Default-First-Site-Name) 3269/tcp open tcpwrapped syn-ack ttl 128 3389/tcp open ms-wbt-server syn-ack ttl 128 Microsoft Terminal Services | ssl-cert: Subject: commonName=DC01.nyoma.local | Issuer: commonName=DC01.nyoma.local | Public Key type: rsa | Public Key bits: 2048 | Signature Algorithm: sha256WithRSAEncryption | Not valid before: 2026-01-28T18:25:20 | Not valid after: 2026-07-30T18:25:20 | MD5: 2c2b:1e0c:36e6:d8de:d745:a6a9:5c6e:27a1 | SHA-1: e1fe:cdb0:a017:979d:41cb:b54a:8631:585a:ada8:539d | -----BEGIN CERTIFICATE----- | MIIC5DCCAcygAwIBAgIQWqkwZyg4GKBMLpqewwiuHzANBgkqhkiG9w0BAQsFADAb | MRkwFwYDVQQDExBEQzAxLm55b21hLmxvY2FsMB4XDTI2MDEyODE4MjUyMFoXDTI2 | MDczMDE4MjUyMFowGzEZMBcGA1UEAxMQREMwMS5ueW9tYS5sb2NhbDCCASIwDQYJ | KoZIhvcNAQEBBQADggEPADCCAQoCggEBALUaWl3/3aL9SD50lKCaDKBCTbWYPrEj | TAiEDNR2MJy1kE/Yy8UDan2FP+O8ThgocCYioXZODNINQuTq7mWzO7HtyRTYagRq | 2YeXfO/rdkPuSe696N/n9y8KwFoBcwYd1iACogIRr2zGDKhMvXPJjaqt4LsRgCPQ | UFenrbh5EMnsgMEQzXZeTufkBGFn60dewdhh9dHWXnJnl1LpOB5YY82RZoQLAFqi | Md4/tpWxTxdjOMkjt4DOOQcML6NcjWK5BstXk87PE/sDpZGsoYbs5CweS0fbNwG2 | 9NIlTeeUhaeuDQxNpzznPiCTvS9fGOzpbO2I4ZUwpmBePWnv7gUwwOECAwEAAaMk | MCIwEwYDVR0lBAwwCgYIKwYBBQUHAwEwCwYDVR0PBAQDAgQwMA0GCSqGSIb3DQEB | CwUAA4IBAQCgR1WmKEJaLIhCCWoDT99ab3qcwPMqR6/CaJ2SEWgHmA46JsF9Jrwi | zMhynyGLgP+6wM8egv7186CMovUKkA+uRZWR8swBZ8ab+0dSMls37u+XcE78s/9g | gGYJSSYd6dkjvgBskSk09FEoyeQRFAU8tBbwpNeWQzDq8XPIM8Oet0q5HS6JjaIV | ab/aBqsv7xxvAGYltUJmWfE41Mjmq+XjWbxD/3gzk+6FRKcY2gnzJadlTTIqJHNe | h6kY3NL+OFOfQB15yeHFBr8sqDXoBqZBSHz64HBVuVdxAoPqCTj68tk33Qswi0tc | ZzeCTquxIiC8puxRBn8nKPGQDipbLrrd |_-----END CERTIFICATE----- | rdp-ntlm-info: | Target_Name: NYOMA | NetBIOS_Domain_Name: NYOMA | NetBIOS_Computer_Name: DC01 | DNS_Domain_Name: nyoma.local | DNS_Computer_Name: DC01.nyoma.local | DNS_Tree_Name: nyoma.local | Product_Version: 10.0.17763 |_ System_Time: 2026-04-10T08:49:19+00:00 |_ssl-date: 2026-04-10T08:49:59+00:00; 0s from scanner time. 5985/tcp open http syn-ack ttl 128 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 9389/tcp open mc-nmf syn-ack ttl 128 .NET Message Framing 49668/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC 49670/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC 49671/tcp open ncacn_http syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0 49673/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC 49674/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC 49684/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC 50092/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC MAC Address: 00:0C:29:7C:BC:93 (VMware) Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required | nbstat: NetBIOS name: DC01, NetBIOS user: <unknown>, NetBIOS MAC: 00:0c:29:7c:bc:93 (VMware) | Names: | DC01<20> Flags: <unique><active> | NYOMA<1c> Flags: <group><active> | DC01<00> Flags: <unique><active> | NYOMA<00> Flags: <group><active> | NYOMA<1b> Flags: <unique><active> | Statistics: | 00:0c:29:7c:bc:93:00:00:00:00:00:00:00:00:00:00:00 | 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00 |_ 00:00:00:00:00:00:00:00:00:00:00:00:00:00 | smb2-time: | date: 2026-04-10T08:49:19 |_ start_date: N/A |_clock-skew: mean: 0s, deviation: 0s, median: 0s | p2p-conficker: | Checking for Conficker.C or higher... | Check 1 (port 41481/tcp): CLEAN (Timeout) | Check 2 (port 46587/tcp): CLEAN (Timeout) | Check 3 (port 53334/udp): CLEAN (Timeout) | Check 4 (port 64454/udp): CLEAN (Timeout) |_ 0/4 checks are positive: Host is CLEAN or ports are blocked NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 10:49 Completed NSE at 10:49, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 10:49 Completed NSE at 10:49, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 10:49 Completed NSE at 10:49, 0.00s elapsed Read data files from: /usr/share/nmap Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 195.90 seconds Raw packets sent: 131125 (5.769MB) | Rcvd: 97 (4.252KB)

3 min · Michel NYOBE