Sign inSign up

cohort3213/ubuntu-ssh-victim

By cohort3213

•Updated 5 months ago

GNS3 Ubuntu SSH victim node for lateral movement emulation. Part of the COHORT framework.

Image
Networking
Security
0

379

cohort3213/ubuntu-ssh-victim repository overview

⁠cohort-ubuntu-ssh-victim

An Ubuntu Noble (24.04) container acting as the passive lateral movement target in COHORT⁠ — a multi-agent AI framework for autonomous network defense. More information and source material at cohort-experiments-app.streamlit.app⁠.

Runs an OpenSSH server with a weak-credential account and pre-populated sensitive files, simulating a vulnerable endpoint for adversary emulation experiments. No Caldera agent is installed — this node is the victim, not the attacker.

⁠Credentials

UserPassword
agentpassword123

⁠Environment variables

VariableDescription
IPIP address to assign to eth0
DEFAULT_GATEWAYDefault gateway for eth0

Important: Network configuration is applied by entrypoint.sh at startup using these environment variables. Do not edit the network settings via GNS3's "Edit Config" — changes there will be overridden on every restart. Always configure IP and gateway through the environment variables in the GNS3 appliance settings.

⁠Exposed port

22 (SSH)

⁠Pre-populated files

/home/agent/documents/ contains sample PNG files used as sensitive data targets in collection/exfiltration steps.

⁠Security note

This image intentionally uses weak credentials and is designed for use in isolated network emulation environments only. Do not deploy on production or internet-accessible networks.

⁠License

CC BY-NC-SA 4.0⁠ — free to share and adapt for non-commercial purposes, with attribution and under the same license.

Tag summary

Content type

Image

Digest

sha256:a868268a8…

Size

112.6 MB

Last updated

5 months ago

docker pull cohort3213/ubuntu-ssh-victim