Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Security_incident_report — React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트 | Kitploit
Tools/GitHubGitHub/kevin9480/security_incident_report
Vulnerability AnalysisWeb SecurityNetwork SecurityDigital ForensicsIntrusion DetectionIncident ResponseLog AnalysisLabs & Practice
GitHub
kevin9480/security_incident_report

Security_incident_report

React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트

View Repository
171 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

01. Infrastructure Configuration

The infrastructure for this project is not managed with IaC (e.g., Terraform) code; instead, it was built by installing pfSense and Wazuh and then changing settings directly from the admin GUI. So instead of "code", this document records the network diagram, screenshots of each settings screen, and what values were changed and why, to make it reproducible.

Network Configuration

Based on pfSense, the external (WAN) and internal (LAN) networks are separated, and the internal network is further divided into 4 zones using a switch.

Infrastructure structure diagram

CategoryTarget SystemIP RangeRole
DMZWEB01 (WAF + WAS)10.10.10.0/24External-facing web service
Internal ServerInternal Portal + DB0110.10.20.0/24Internal portal, posts/attachments DB
SIEMWazuh10.10.50.0/24Security event collection & analysis
OfficePC-USER01~0410.10.30.0/24Office PCs (user terminals)

pfSense Settings

Only the settings actually changed after the default installation are listed here. (For the overall flow reflecting the full plan, see 04-response)

Offloading Disabled — System - Advanced - Networking

If packet processing is handled directly by the NIC instead of the CPU, Suricata cannot inspect the packets, so hardware checksum, TCP segmentation, and large receive offload were all disabled.

pfsense offloading setting

Alert & Block Settings — Services - Interfaces - WAN - WAN Settings

To automatically block attacker IPs detected by Suricata, Block Offenders was enabled, IPS Mode was set to Legacy, and Kill States was also enabled.

pfsense alert/block setting

Port Variable Settings — Services - Interfaces - WAN - WAN Variables

Since the internal web service uses both ports 80 and 8080, the two ports were registered as a group under HTTP_PORTS.

pfsense port setting

Notes

  • Wazuh agents were installed on the DMZ Web (10.10.10.2), DB (10.10.20.3), and office PCs (10.10.30.2~5) to centrally collect Sysmon, PowerShell, and auditd logs.
  • If there are more screenshots of the detailed installation/configuration procedures for each server (Wazuh manager settings, Coraza WAF rules, etc.), we recommend adding them to this folder in the form of wazuh-setup.md, coraza-waf-setting.md, etc. (Those captures are not in the original PDF, so they could not be included this time — let me know if needed.)
Download Tool