Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
642 commits
Select commit Hold shift + click to select a range
cf075da
Update WebTesting.md
panterasbook29 Feb 17, 2026
7c7e0dc
Update Sysmon.md
panterasbook29 Feb 17, 2026
5df58a1
Update Sysmon.md
panterasbook29 Feb 17, 2026
ceb0f5e
Update Responder.md
panterasbook29 Feb 17, 2026
5064688
Update Nmap.md
panterasbook29 Feb 17, 2026
4558962
Update Nmap.md
panterasbook29 Feb 17, 2026
687e08b
Update AppLocker.md
panterasbook29 Feb 17, 2026
9aafb5e
Update AppLocker.md
panterasbook29 Feb 17, 2026
f7b68d8
Update Sysmon.md
panterasbook29 Feb 17, 2026
8b3d9ed
Update Portspoof.md
panterasbook29 Feb 17, 2026
f6d63bb
Update webhoneypot.md
panterasbook29 Feb 17, 2026
a9b8bf4
Update HoneyShare.md
panterasbook29 Feb 17, 2026
dd08e62
Update HoneyPorts.md
panterasbook29 Feb 17, 2026
c2c6355
Update AppLocker.md
panterasbook29 Feb 23, 2026
2c375fd
Update AppLocker.md
panterasbook29 Feb 23, 2026
85fee6e
Update AppLocker.md
panterasbook29 Feb 23, 2026
cccbacf
Update AppLocker.md
panterasbook29 Feb 23, 2026
19cfe8a
Update AppLocker.md
panterasbook29 Feb 23, 2026
c38c655
Update AppLocker.md
panterasbook29 Feb 23, 2026
d7c272a
Update AppLocker.md
panterasbook29 Feb 23, 2026
90149a5
Update AppLocker.md
panterasbook29 Feb 23, 2026
6143529
Update AppLocker.md
panterasbook29 Feb 23, 2026
f6d1e5e
Update AppLocker.md
panterasbook29 Feb 23, 2026
71d88c0
Update AppLocker.md
panterasbook29 Feb 23, 2026
d849da6
Update Bluespawn.md
panterasbook29 Feb 23, 2026
aae8f4f
Update Bluespawn.md
panterasbook29 Feb 23, 2026
cdbcb66
Update Bluespawn.md
panterasbook29 Feb 23, 2026
3a52131
Update Bluespawn.md
panterasbook29 Feb 23, 2026
51f43b7
Update Bluespawn.md
panterasbook29 Feb 23, 2026
a05dbad
Update DeepBlueCLI.md
panterasbook29 Feb 23, 2026
5ccb100
Update DeepBlueCLI.md
panterasbook29 Feb 23, 2026
5651088
Update DeepBlueCLI.md
panterasbook29 Feb 23, 2026
e571838
Update DeepBlueCLI.md
panterasbook29 Feb 23, 2026
06c857e
Update Nessus.md
panterasbook29 Feb 23, 2026
fc81755
Update Nessus.md
panterasbook29 Feb 23, 2026
606b60c
Update Nessus.md
panterasbook29 Feb 23, 2026
292c688
Update Nmap.md
panterasbook29 Feb 23, 2026
05074d5
Update Nmap.md
panterasbook29 Feb 23, 2026
80072b1
Update Nmap.md
panterasbook29 Feb 23, 2026
9dfbd1e
Update Nmap.md
panterasbook29 Feb 23, 2026
7f2b714
Update Nmap.md
panterasbook29 Feb 23, 2026
a42d763
Update Nmap.md
panterasbook29 Feb 23, 2026
cfbf62f
Update Nmap.md
panterasbook29 Feb 23, 2026
168791b
Update AppLocker.md
panterasbook29 Feb 23, 2026
518e454
Update AppLocker.md
panterasbook29 Feb 23, 2026
f94a6a1
Update Nmap.md
panterasbook29 Feb 23, 2026
110ea16
Update Nmap.md
panterasbook29 Feb 23, 2026
4f2764e
Update Nmap.md
panterasbook29 Feb 23, 2026
55c9f3c
Update Nmap.md
panterasbook29 Feb 23, 2026
266a0a5
Update Nmap.md
panterasbook29 Feb 23, 2026
7195774
Update Nmap.md
panterasbook29 Feb 23, 2026
cae85a6
Update PasswordSpray.md
panterasbook29 Feb 23, 2026
14d28e3
Update PasswordSpray.md
panterasbook29 Feb 23, 2026
e4c379a
Update PasswordSpray.md
panterasbook29 Feb 23, 2026
06e5d6f
Update PasswordSpray.md
panterasbook29 Feb 23, 2026
63a1378
Update Responder.md
panterasbook29 Feb 23, 2026
dbe4d88
Update Responder.md
panterasbook29 Feb 23, 2026
30c709a
Update RITA.md
panterasbook29 Feb 23, 2026
63c74e8
Update RITA.md
panterasbook29 Feb 23, 2026
4a1abf0
Update RITA.md
panterasbook29 Feb 23, 2026
94b581b
Update RITA.md
panterasbook29 Feb 23, 2026
29b89aa
Update Sysmon.md
panterasbook29 Feb 23, 2026
1a30ee3
Update Sysmon.md
panterasbook29 Feb 23, 2026
cf1613b
Update Sysmon.md
panterasbook29 Feb 23, 2026
f4baefb
Update Sysmon.md
panterasbook29 Feb 23, 2026
d42e451
Update ACHunterCE.md
panterasbook29 Feb 23, 2026
4482371
Update Spidertrap.md
panterasbook29 Mar 7, 2026
f7d4ca6
Update Spidertrap.md
panterasbook29 Mar 7, 2026
50e469c
Update Cowrie.md
panterasbook29 Mar 7, 2026
d82f52a
Update Cowrie.md
panterasbook29 Mar 7, 2026
6c92f58
Update Portspoof.md
panterasbook29 Mar 8, 2026
65cea52
Update Portspoof.md
panterasbook29 Mar 8, 2026
70e942d
Update Portspoof.md
panterasbook29 Mar 8, 2026
6c34c22
Update Portspoof.md
panterasbook29 Mar 8, 2026
ed7c4df
Update HoneyPorts.md
panterasbook29 Mar 8, 2026
e1942ca
Update HoneyPorts.md
panterasbook29 Mar 8, 2026
d89ca9b
Update openCanary.md
panterasbook29 Mar 8, 2026
3fef40d
Update openCanary.md
panterasbook29 Mar 8, 2026
dc5f499
Add files via upload
panterasbook29 Mar 12, 2026
1691d7f
Update AdvancedC2PCAPAnalysis.md
panterasbook29 Mar 12, 2026
078bacf
Update AdvancedC2PCAPAnalysis.md
panterasbook29 Mar 12, 2026
e0c54b8
Update AdvancedC2PCAPAnalysis.md
panterasbook29 Mar 12, 2026
375a58e
Update Sysmon.md
panterasbook29 Mar 13, 2026
f39346f
Update Sysmon.md
panterasbook29 Mar 13, 2026
254c0d2
Update Sysmon.md
panterasbook29 Mar 13, 2026
c466286
Update Sysmon.md
panterasbook29 Mar 13, 2026
ef34316
Update WebTesting.md
panterasbook29 Mar 13, 2026
024d672
Update WebTesting.md
panterasbook29 Mar 13, 2026
f6b6e18
Update Beelzebub.md
panterasbook29 Mar 13, 2026
818eef0
Update WebTesting.md
panterasbook29 Mar 14, 2026
4a6ed85
Update WebTesting.md
panterasbook29 Mar 14, 2026
cbccd23
Update WebTesting.md
panterasbook29 Mar 14, 2026
cfd720c
Update WebTesting.md
panterasbook29 Mar 14, 2026
e1a82ab
Update WebTesting.md
panterasbook29 Mar 14, 2026
12c4bfe
Update WebTesting.md
panterasbook29 Mar 14, 2026
c903824
Update WebTesting.md
panterasbook29 Mar 14, 2026
dd6e08b
Update WebTesting.md
panterasbook29 Mar 14, 2026
07b2482
Update LinuxCLI.md
panterasbook29 Mar 14, 2026
945e220
Update LinuxCLI.md
panterasbook29 Mar 14, 2026
59bfae5
Update LinuxCLI.md
panterasbook29 Mar 14, 2026
b4bd882
Update LinuxCLI.md
panterasbook29 Mar 14, 2026
7604f2b
Update LinuxCLI.md
panterasbook29 Mar 14, 2026
7ab7303
Update LinuxCLI.md
panterasbook29 Mar 14, 2026
c963a9f
Update Haraka.md
panterasbook29 Mar 14, 2026
91debd0
Update Beelzebub.md
panterasbook29 Mar 14, 2026
a307142
Update Beelzebub.md
panterasbook29 Mar 14, 2026
03dd955
Update Haraka.md
panterasbook29 Mar 14, 2026
967298d
Update Haraka.md
panterasbook29 Mar 14, 2026
fd09b66
Update Haraka.md
panterasbook29 Mar 14, 2026
a531d9b
Update WebTesting.md
panterasbook29 Mar 15, 2026
b325951
Update DomainLogReview.md
panterasbook29 Mar 15, 2026
51636fd
Update DomainLogReview.md
panterasbook29 Mar 15, 2026
10a65a7
Update Velociraptor.md
panterasbook29 Mar 15, 2026
93e4561
Update Velociraptor.md
panterasbook29 Mar 15, 2026
375d25c
Update Velociraptor.md
panterasbook29 Mar 15, 2026
e3e0a94
Update Velociraptor.md
panterasbook29 Mar 15, 2026
3333256
Update Velociraptor.md
panterasbook29 Mar 15, 2026
6727a1b
Update Velociraptor.md
panterasbook29 Mar 15, 2026
d19e710
Update Velociraptor.md
panterasbook29 Mar 15, 2026
cb54b93
Update Velociraptor.md
panterasbook29 Mar 15, 2026
05acc3e
Update Velociraptor.md
panterasbook29 Mar 15, 2026
05eff6e
Update Velociraptor.md
panterasbook29 Mar 15, 2026
67b4eec
Update Velociraptor.md
panterasbook29 Mar 15, 2026
cd77427
Update Velociraptor.md
panterasbook29 Mar 15, 2026
175aba4
Update Velociraptor.md
panterasbook29 Mar 15, 2026
5c50261
Update Velociraptor.md
panterasbook29 Mar 15, 2026
bb5395c
Update WebLogReview.md
panterasbook29 Mar 15, 2026
879e291
Update WebLogReview.md
panterasbook29 Mar 15, 2026
3f4cd3b
Update WindowsCLI.md
panterasbook29 Mar 15, 2026
4d05465
Update WebLogReview.md
panterasbook29 Mar 15, 2026
fd610ef
Update WebLogReview.md
panterasbook29 Mar 15, 2026
6a22291
Update WindowsCLI.md
panterasbook29 Mar 15, 2026
db572bb
Update WindowsCLI.md
panterasbook29 Mar 15, 2026
d80a5d2
Update WindowsCLI.md
panterasbook29 Mar 15, 2026
44b64bc
Update WindowsCLI.md
panterasbook29 Mar 15, 2026
a2ea21e
Update WindowsCLI.md
panterasbook29 Mar 15, 2026
e1af9b2
Update WindowsCLI.md
panterasbook29 Mar 15, 2026
b104603
Update WindowsCLI.md
panterasbook29 Mar 15, 2026
260ba02
Update Caldera.md
panterasbook29 Mar 16, 2026
c766618
Update Caldera.md
panterasbook29 Mar 16, 2026
485c2ff
Update Mailoney.md
panterasbook29 Mar 16, 2026
952668a
Update Mailoney.md
panterasbook29 Mar 16, 2026
f1d0794
Update Mailoney.md
panterasbook29 Mar 16, 2026
345ea02
Update GoPhish.md
panterasbook29 Mar 16, 2026
d621192
Update Canarytokens.md
panterasbook29 Mar 16, 2026
22b64bb
Update Canarytokens.md
panterasbook29 Mar 16, 2026
03cf23f
Update DNSChef.md
panterasbook29 Mar 17, 2026
e191877
Update DNSChef.md
panterasbook29 Mar 17, 2026
1dc8e8c
Update DNSChef.md
panterasbook29 Mar 17, 2026
daf695f
Update DNSChef.md
panterasbook29 Mar 17, 2026
cdf842a
Update FakeNet-NG.md
panterasbook29 Mar 17, 2026
78101b4
Update FakeNet-NG.md
panterasbook29 Mar 17, 2026
5aaf1b6
Update openCanary.md
ap0llo19 Mar 17, 2026
df421f9
Update openCanary.md
ap0llo19 Mar 17, 2026
3e61066
Update openCanary.md
ap0llo19 Mar 17, 2026
9a05c04
Update FakeNet-NG.md
panterasbook29 Mar 17, 2026
cadcf0c
Update FakeNet-NG.md
panterasbook29 Mar 17, 2026
2172074
Update FakeNet-NG.md
panterasbook29 Mar 17, 2026
188e8d1
Update FakeNet-NG.md
panterasbook29 Mar 17, 2026
8f09580
Update FakeNet-NG.md
panterasbook29 Mar 17, 2026
dfceb6a
Update GoPhish.md
panterasbook29 Mar 17, 2026
a9693e0
Update GoPhish.md
panterasbook29 Mar 17, 2026
00c7a2d
Update GoPhish.md
panterasbook29 Mar 17, 2026
d872684
Update GoPhish.md
panterasbook29 Mar 17, 2026
33c2065
Update GoPhish.md
panterasbook29 Mar 17, 2026
9a059cb
Update dionaea.md
panterasbook29 Mar 18, 2026
004aa71
Update dionaea.md
panterasbook29 Mar 18, 2026
9a22a5e
Update dionaea.md
panterasbook29 Mar 18, 2026
90c82cd
Update dionaea.md
panterasbook29 Mar 18, 2026
378f3dd
Update ModSecurity.md
panterasbook29 Mar 18, 2026
6dff47e
Update ModSecurity.md
panterasbook29 Mar 18, 2026
cde680d
Update ModSecurity.md
panterasbook29 Mar 18, 2026
ec76841
Update ModSecurity.md
panterasbook29 Mar 18, 2026
fbb15d9
Update ModSecurity.md
panterasbook29 Mar 18, 2026
bbfd900
Update ModSecurity.md
panterasbook29 Mar 18, 2026
0f5d97b
Update ModSecurity.md
panterasbook29 Mar 18, 2026
e2c7190
Update Glastopf.md
panterasbook29 Mar 18, 2026
03abdb2
Update openCanary.md
ap0llo19 Mar 18, 2026
0520b78
Update openCanary.md
ap0llo19 Mar 18, 2026
dd5125f
Update openCanary.md
ap0llo19 Mar 20, 2026
dc23498
Update openCanary.md
ap0llo19 Mar 20, 2026
93df591
Update openCanary.md
ap0llo19 Mar 20, 2026
47731d8
Update openCanary.md
ap0llo19 Mar 20, 2026
f710911
Update openCanary.md
ap0llo19 Mar 20, 2026
8d1949a
Update webhoneypot.md
panterasbook29 Mar 23, 2026
de0dee0
Update FirewallLog.md
panterasbook29 Mar 23, 2026
6baac75
Update FirewallLog.md
panterasbook29 Mar 23, 2026
d5faaab
Update Glastopf.md
panterasbook29 Mar 23, 2026
24a6f39
Update Glastopf.md
panterasbook29 Mar 23, 2026
c21505f
Update Glastopf.md
panterasbook29 Mar 23, 2026
5c8644c
Update HoneyShare.md
panterasbook29 Mar 23, 2026
b70d779
Update HoneyShare.md
panterasbook29 Mar 23, 2026
5485bb2
Update HoneyShare.md
panterasbook29 Mar 23, 2026
c42e5ff
Update Bluespawn.md
panterasbook29 Mar 23, 2026
87f6b0d
Update Bluespawn.md
panterasbook29 Mar 23, 2026
dafe3a1
Update Bluespawn.md
panterasbook29 Mar 23, 2026
69e20f1
Resolve merge conflicts with upstream master
panterasbook29 Mar 24, 2026
e411c2c
yMerge branch 'master' of https://github.com/panterasbook29/Revamped_…
panterasbook29 Mar 24, 2026
0bb73b0
Update Beelzebub.md
panterasbook29 Mar 24, 2026
df625bf
Update LocalPasswordSpray.ps1
panterasbook29 Mar 24, 2026
26c8629
Update WebTesting.md
panterasbook29 Mar 24, 2026
7077650
Update webhoneypot.md
ap0llo19 Mar 24, 2026
77f8a02
Update webhoneypot.md
ap0llo19 Mar 24, 2026
a4e1ffa
Update webhoneypot.md
ap0llo19 Mar 24, 2026
20609a8
Update webhoneypot.md
ap0llo19 Mar 24, 2026
1f10774
Update HoneyShare.md
ap0llo19 Mar 25, 2026
504c43e
Update HoneyShare.md
ap0llo19 Mar 25, 2026
a3a7cea
Update Responder.md
ap0llo19 Mar 25, 2026
a275466
Update Responder.md
ap0llo19 Mar 25, 2026
9a67e1f
Add files via upload
ap0llo19 Mar 25, 2026
ce2f6e8
Update Responder.md
ap0llo19 Mar 25, 2026
a48d3b1
Update Responder.md
ap0llo19 Mar 25, 2026
25569f0
Update Responder.md
ap0llo19 Mar 25, 2026
533a0e0
Update Responder.md
ap0llo19 Mar 25, 2026
68b9381
Update Responder.md
ap0llo19 Mar 25, 2026
5aafb4b
Update WebTesting.md
panterasbook29 Mar 26, 2026
54e95e5
Update WebTesting.md
panterasbook29 Mar 26, 2026
ec31b87
Update PasswordSpray.md
panterasbook29 Mar 26, 2026
7ae1a5b
Update honeyuser.md
panterasbook29 Mar 26, 2026
89b8fe3
Update honeyuser.md
panterasbook29 Mar 26, 2026
2440eec
Update honeyuser.md
panterasbook29 Mar 26, 2026
cc45690
Update Bluespawn.md
panterasbook29 Mar 26, 2026
788d1de
Update Bluespawn.md
panterasbook29 Mar 26, 2026
bd0267f
Update Bluespawn.md
panterasbook29 Mar 26, 2026
992ddb0
Update Bluespawn.md
panterasbook29 Mar 26, 2026
9d5b51a
Update Bluespawn.md
panterasbook29 Mar 26, 2026
3a827f2
Update Bluespawn.md
panterasbook29 Mar 26, 2026
febebcd
Update Bluespawn.md
panterasbook29 Mar 26, 2026
2a2176e
Update Bluespawn.md
panterasbook29 Mar 26, 2026
f917e6c
Update Bluespawn.md
panterasbook29 Mar 26, 2026
ffd5e3a
Update Bluespawn.md
panterasbook29 Mar 26, 2026
06bef99
Update Bluespawn.md
panterasbook29 Mar 26, 2026
214e45a
Update Bluespawn.md
panterasbook29 Mar 26, 2026
acae7dd
Update Sysmon.md
panterasbook29 Mar 26, 2026
68b191f
Update AppLocker.md
panterasbook29 Mar 26, 2026
af93ae5
Update AppLocker.md
panterasbook29 Mar 26, 2026
68f2aa3
Update AppLocker.md
panterasbook29 Mar 26, 2026
89f6481
Update Bluespawn.md
panterasbook29 Mar 26, 2026
10d8e50
Update FileAudit.md
panterasbook29 Mar 26, 2026
8d50f30
Update Canarytokens.md
ap0llo19 Mar 28, 2026
145eea2
Update Canarytokens.md
ap0llo19 Mar 28, 2026
9a61b0c
Update Canarytokens.md
ap0llo19 Mar 28, 2026
59ff1ed
Update Canarytokens.md
ap0llo19 Mar 28, 2026
a187577
Update Canarytokens.md
ap0llo19 Mar 28, 2026
aeeaf70
Update Canarytokens.md
ap0llo19 Mar 28, 2026
89df432
Update Canarytokens.md
ap0llo19 Mar 28, 2026
1fdb051
Update Canarytokens.md
ap0llo19 Mar 28, 2026
c67d89c
Update Canarytokens.md
ap0llo19 Mar 28, 2026
9ffd524
Update Canarytokens.md
ap0llo19 Mar 28, 2026
e697eb8
Update Canarytokens.md
ap0llo19 Mar 28, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
Binary file removed DeepBlueCLI-master.zip
Binary file not shown.
Binary file not shown.
Binary file removed IntroClassFiles/GraphRunner_Outputs (1).zip
Binary file not shown.
Binary file removed IntroClassFiles/SampleReports (1).zip
Binary file not shown.
231 changes: 157 additions & 74 deletions IntroClassFiles/Tools/IntroClass/ACHCE/ACHunterCE.md
Original file line number Diff line number Diff line change
@@ -1,97 +1,121 @@
![image](https://github.com/user-attachments/assets/068fae26-6e8f-402f-ad69-63a4e6a1f59e)

# Overview + Setup

In this lab we are going to set up the Community Edition of AC Hunter so it can intercept and inspect traffic on a home network without the need for expensive managed switches with SPAN or TAP ports. This is done through the amazing power of ARP cache poisoning.

Step 0, Download AC Hunter Community Edition Here:

https://www.activecountermeasures.com/ac-hunter-community-edition/download/
- Download AC Hunter Community Edition [Here](https://www.activecountermeasures.com/ac-hunter-community-edition/download/)

![](attachments/ACHCE_Download.png)

![](attachments/ClickDownload.png)

-----------------------------------------
This next section will walk through how to launch the AC Hunter VM using VMware.
-----------------------------------------

<br><br>

This next section will walk through how to launch the **AC Hunter VM** using **VMware**.

Start by opening file explorer and navigating to your downloads directory.
- Start by opening **file explorer** and navigating to your downloads directory.

![](attachments/OpeningFileExplorer.png)

![](attachments/navigatetodownloads.png)

You should see the AC Hunter .zip archive that we just downloaded. We need to extract this. Click on the .zip archive and hit `Extract all` at the top of the screen.
- You should see the `AC-Hunter.zip` archive that we just downloaded. We need to extract this. Click on the `.zip` archive and hit `Extract all` at the top of the screen.

![](attachments/extractall.png)

When the pop-up appears, click extract. This will extract the .zip archive to the downloads folder.
- When the pop-up appears, click **extract**. This will extract the `.zip` archive to the downloads folder.

![](attachments/extract.png)

Next, open your VMware application. In this instance, we use VMware Workstation. Once opened, first make sure you have the home tab selected. Then, click `Open a Virtual Machine`.
- Next, open your VMware application. In this instance, we use **VMware Workstation**. Once opened, first make sure you have the home tab selected. Then, click `Open a Virtual Machine`.

![](attachments/openvmware.png)

Once again, navigate to your downloads folder, and then into the extracted `AC-Hunter-v...` folder. If done correctly, you should only see one file that can be selected. Go ahead and double click on it.
- Once again, navigate to your downloads folder, and then into the extracted `AC-Hunter-v...` folder. If done correctly, you should only see one file that can be selected. Go ahead and double click on it.

![](attachments/openfolder.png)

![](attachments/doubleclick.png)

After doing this, you should see a new tab appear shown in the screenshot below.
- After doing this, you should see a new tab appear shown in the screenshot below.

![](attachments/newtab.png)

--------------------------------------------

Now that we have successfully loaded the AC Hunter VM into our VMware application, we need to do two things.
Now that we have successfully loaded the **AC Hunter VM** into our VMware application, we need to change the network settings.

1. The first thing we will need to do is to change VM to Bridged networking from NAT. This can be done in the settings for the VM which can be accessed via VM > Settings > Network Adapter
- What we will need to do is to change **VM** to `Bridged networking` from **NAT**. This can be done in the settings for the VM which can be accessed via `VM` > `Settings` > `Network Adapter`

![](attachments/editsettings.png)

![](attachments/networkadapter.png)

![](https://github.com/strandjs/IntroLabs/blob/master/IntroClassFiles/Tools/IntroClass/ACHCE/VMWare_Bridge.png)

2. Go ahead and hit `Power on this virtual machine`.
When the VM is done booting it is essential you copy password before login!!!! It is displayed in the logon banner at first boot and will go away once it is used.
- Go ahead and hit `Power on this virtual machine`.

>[!IMPORTANT]
> When the VM is done booting it is essential you **copy password** before login!!!! It is displayed in the logon banner at **first boot** and will go away once it is used.
>
> **User ID** is `dataimport`

User ID is dataimport

5. Change the default password after initial login by running the following:
<pre>passwd</pre>
- Change the **default password** after initial login by running the following:
```bash
passwd
```

6. Next, get your IP Address by running the following command:
- Next, get your **IP Address** by running the following command:

<pre>ip addr show dev ens33 | grep inet </pre>
```bash
ip addr show dev ens33 | grep inet
```

![](attachments/IP.png)

5. Now lets open Terminal on Windows and open two SSH sessions. I like to have one as root and another as dataimport for the install.
- Now lets open Terminal on Windows and open two **SSH sessions**. I like to have one as **root** and another as **dataimport** for the install.

<br>

From Windows Terminal.

Terminal 1:
- **Terminal 1:**

```bash
ssh dataimport@YourACHCE_IPADDRESS
```

<pre>ssh dataimport@YourACHCE_IPADDRESS</pre>
- **Terminal 2:**

Terminal 2:
```bash
ssh dataimport@YOURACHCE_IPADDRESS
```

`ssh dataimport@YOURACHCE_IPADDRESS`
```bash
sudo su -
```

`sudo su -`
<br>

6. As dataimport, pull down and install zeek
- As **dataimport**, pull down and install **zeek**

`sudo wget -O /usr/local/bin/zeek https://raw.githubusercontent.com/activecm/docker-zeek/master/zeek`
```bash
sudo wget -O /usr/local/bin/zeek https://raw.githubusercontent.com/activecm/docker-zeek/master/zeek
```

`sudo chmod +x /usr/local/bin/zeek`
```bash
sudo chmod +x /usr/local/bin/zeek
```

`zeek pull`
```bash
zeek pull
```

7. Choose your ens adaptor!!
>[!IMPORTANT]
> Choose your **ens adaptor**!!

It should look like it does below:

Expand All @@ -109,15 +133,22 @@ It should look like it does below:

```

`zeek start`
- Start **zeek**
```bash
zeek start
```

8. Add a password for the web user for AC Hunter
- Add a password for the web user for AC Hunter

`manage_web_user.sh reset -u 'welcome@activecountermeasures.com'`
```bash
manage_web_user.sh reset -u 'welcome@activecountermeasures.com'
```

It should look like it does below:

```dataimport@achce:~$ manage_web_user.sh reset -u 'welcome@activecountermeasures.com'
```
dataimport@achce:~$ manage_web_user.sh reset -u 'welcome@activecountermeasures.com'

Please enter a password
Please re-enter to confirm:
achunter_db is up-to-date
Expand All @@ -134,23 +165,34 @@ dataimport@achce:~$

9. Get the proper scripts to connect the Zeek Sensor

`curl -fsSL https://raw.githubusercontent.com/activecm/zeek-log-transport/master/connect_sensor.sh -O`
```bash
curl -fsSL https://raw.githubusercontent.com/activecm/zeek-log-transport/master/connect_sensor.sh -O
```

`curl -fsSL https://raw.githubusercontent.com/activecm/shell-lib/master/acmlib.sh -O`
```bash
curl -fsSL https://raw.githubusercontent.com/activecm/shell-lib/master/acmlib.sh -O
```

`curl -fsSL https://raw.githubusercontent.com/activecm/zeek-log-transport/master/zeek_log_transport.sh -O`
```bash
curl -fsSL https://raw.githubusercontent.com/activecm/zeek-log-transport/master/zeek_log_transport.sh -O
```

10. Get your hostname
- Get your **hostname**

`hostname`
```bash
hostname
```

11. run the script with your ac-hunter system hostname:
- Run the script with your **ac-hunter** system **hostname**:

`bash connect_sensor.sh achce`
```bash
bash connect_sensor.sh achce
```

It should look like it does below:

```================ Creating a new RSA key with no passphrase ================
```
================ Creating a new RSA key with no passphrase ================
Generating public/private rsa key pair.
Your identification has been saved in /home/dataimport/.ssh/id_rsa_dataimport
Your public key has been saved in /home/dataimport/.ssh/id_rsa_dataimport.pub
Expand Down Expand Up @@ -178,35 +220,54 @@ dataimport@achce's password:

```

12. Install bettercap as root!!! Please switch to the other Terminal where you are running as root.
- Install **bettercap** as **root**!!! Please switch to the other Terminal where you are running as root.

`docker pull bettercap/bettercap`
>[!IMPORTANT]
> Make sure you are in the right **terminal**

`docker run -it --privileged --net=host bettercap/bettercap -eval "caplets.update; ui.update; q"`
```bash
docker pull bettercap/bettercap
```

```bash
docker run -it --privileged --net=host bettercap/bettercap -eval "caplets.update; ui.update; q"
```

13. Install mlocate
- Install **mlocate**

`apt install mlocate`
>[!NOTE]
> From the **kali** terminal

14. Updated the database
```bash
apt install mlocate
```

- Updated the **database**

`updatedb`
```bash
updatedb
```

15. Search for the config files
- Search for the **config files**

`locate https-ui.cap`
```bash
locate https-ui.cap
```

16. Edit the https-ui.cap file:
- Edit the `https-ui.cap` file:

Please note your path will be different!!!!!

`vi /var/lib/docker/overlay2/5146307503ac713827d090d51b88a622af068579060d8e1f1d97cda56415e018/diff/app/https-ui.cap`
```bash
vi /var/lib/docker/overlay2/5146307503ac713827d090d51b88a622af068579060d8e1f1d97cda56415e018/diff/app/https-ui.cap
```

Change the line set https.server.port to 4443
- Change the line set `https.server.port` to **4443**

It should look like it does below:

```# api listening on https://0.0.0.0:8083/ and ui on https://0.0.0.0
```
# api listening on https://0.0.0.0:8083/ and ui on https://0.0.0.0
set api.rest.address 0.0.0.0
set api.rest.port 8083
set https.server.address 0.0.0.0
Expand All @@ -230,19 +291,21 @@ https.server on
```


log out of vi with esc :wq!
- Log out of vi with by pressing `esc` and **typing** `:wq!` and pressing `Enter`

###Please note, there seems to be a weird bug in Bettercap where it updates the port to 4444443. If you get a bind error, just re-edit the above file to set the port to 443.
### Please note, there seems to be a weird bug in Bettercap where it updates the port to 4444443. If you get a bind error, just re-edit the above file to set the port to 443.

17. Start bettercap


`docker run -it --privileged --net=host bettercap/bettercap -caplet https-ui`
- Start **bettercap**

```bash
docker run -it --privileged --net=host bettercap/bettercap -caplet https-ui
```

18. Show the network
- Show the **network**

`net.show`
```bash
net.show
```


```
Expand All @@ -263,9 +326,11 @@ log out of vi with esc :wq!

```

19. Show help for options!
- Show **help** for **options**!

`help`
```bash
help
```

It should look like it does below:

Expand Down Expand Up @@ -323,17 +388,35 @@ Modules

```

20. Start the poison
- Start the **poison**

```bash
arp.spoof on
```

- Start the https proxy

```bash
https.proxy on
```

Now, surf to your **AC-Hunter system**!!!

`https://<YOUR_ACHCE_IP_ADDR>`


***
<b><i>Continuing the course? </br>[Next Lab](https://github.com/strandjs/IntroLabs/tree/master/IntroClassFiles/Tools/IntroClass/PoisoningtheWellIR-main)</i></b>

`arp.spoof on`
<b><i>Want to go back? </br>[Previous Lab](/IntroClassFiles/Tools/IntroClass/FirewallLog/FirewallLog.md)</i></b>

21. Start the https proxy
<b><i>Looking for a different lab? </br>[Lab Directory](/IntroClassFiles/navigation.md)</i></b>

`https.proxy on`
***Finished with the Labs?***

Now, surf to your AC-Hunter system!!!
Please be sure to destroy the lab environment!

https://<YOUR_ACHCE_IP_ADDR>
[Click here for instructions on how to destroy the Lab Environment](/IntroClassFiles/Tools/IntroClass/LabDestruction/labdestruction.md)

[Return To Lab List](https://github.com/strandjs/IntroLabs/blob/master/IntroClassFiles/navigation.md)
---

Loading