splunk / attack_range_local

Build a attack range in your local machine
Apache License 2.0
130 stars 39 forks source link

Caldera Elevated Agents Keep Failing. #42

Closed jaco-za closed 3 years ago

jaco-za commented 3 years ago

I've tried different deployment variations of Attack Range Local, and it seems Elevated agents in Caldera keeps on failing.

VM setups I've tried:

I've tried different windows hosts, and have deleted rebuilt etc a few times.

Everything else works as expected. I.e. Splunk, Caldera in general etc, but Elevated agents show up, and then goes offline after a while.

If an operation is run while an Elevated agent is still live, it shows a red cross in the Operations tab for that agents job, and the message "Internal Server Error".

Operations using User level agents runs as expected.

I'm not sure though if this is due to the local Attack Range variant, or if this is a Caldera issue?

P4T12ICK commented 3 years ago

We had a lot of problems with the stability of Caldera. We follow the installation guidelines. Therefore, I assume it's something with Caldera. Can you open an issue in their project? Thank you.

jaco-za commented 3 years ago

Will do, thanks.