mitre-attack / attack-evals

ATT&CK Evaluations website (DEPRECATED)
https://attackevals.mitre.org
59 stars 24 forks source link

Evaluation Environment #28

Closed sgstudent2019 closed 4 years ago

sgstudent2019 commented 4 years ago

Hi there,

I understand this is not the right avenue to ask about the evaluation environment, but I could not find any other mediums to do so, so I must apologise first.

As I understand from the evaluation environment diagram here, Scranton, Utica, Nashua, NewYork, and Warehouse are in the Windows domain DMEVALS, while Yonkers and Schrutefarms are in another Windows domain. My interpretation for this is because the domain label appeared to only encapsulate the diagram box showing the 5 machines mentioned.

However, I read in the immediate paragraph that says that "A Windows domain with one domain controller...". This would mean that there is only 1 Windows domain (which would be DMEVALS) for all 7 machines.

May I ask if my interpretation of the diagram is correct, or should there be only 1 domain for all machines?

Thank you for your time and my apologies once again.

JeffJLi commented 4 years ago

Hey sgstudent2019,

Thanks for reaching out! Sounds like your interpretation was partially correct. As shown in the diagram you referenced, the 5 endpoints (NewYork, Warehouse, Scranton, Utica, and Nashua) are in the DMEVALS domain. The two additonal endpoints (Yonkers and Schrutfarms) are connected to the same network but are not domain joined.

Hopefully that clarifies the confusion!

Please feel free to email evals@mitre-engenuity.org if you have any other questions.