?

Cybereason Sandbox

Bookmark
20 people launched
Solution Overview
WWT's Cybereason Lab exists to provide a sandbox environment that can be used to evaluate the solution suite across a wide variety of endpoints, including both Windows and Unix-based operating systems. There is also an attack machine, running Kali Linux, with which to test the efficacy of these tools using benign, non-weaponized malware. 
 
Cybereason, creators of the leading Cyber Defense Platform, gives the advantage back to the defender through a completely new approach to cybersecurity. Cybereason offers endpoint detection and response (EDR), next-generation antivirus (NGAV) and active monitoring services, powered by its cross-machine correlation engine and proprietary AI hunting engine. The Cybereason suite of products provides unmatched visibility, increases analyst efficiency and effectiveness, and reduces security risk. 
 
You will access the environment using a Windows-based jumphost from which you can browse web consoles, open RDP/SSH sessions, etc. See topology diagram above and to the right.

Goals & Objectives

The purpose of the sandbox lab is to help you develop proficiency in deploying, managing and monitoring the Cybereason solution. The lab guide provides a flexible framework for evaluating the solution, its installation and behavior in a sample customer environment.

The lab environment will allow you to:
  • Access the ESA baseline sSandbox environment.
  • Login to the cloud-based portal.
  • Navigate the portal's interface and workflow.
  • Deploy agents on Windows systems.
  • Deploy agents on Linux systems.

Hardware & Software

This lab consists of the following hardware and software:
 
Software
  • Cybereason (current version). 
 
Server Devices 
  • 1x Windows Jumphost (Windows Server 2016). 
  • 1x Generic Server (Windows Server 2012). 
  • 1x Generic Server (Windows Server 2016). 
  • 1x Generic Server (Red Hat Enterprise Linux 7). 
  • 1x Generic Server (CentOS 7). 
  • 1x Generic Server (Solaris 11). 
 
Client Devices 
  • 1x Attack Client (Windows 10 Enterprise). 
  • 1x Generic Client (Windows 7 Enterprise). 
  • 1x Attack Host (Kali Linux 2018). 

Technologies