splunk/attack_range ? reverse-engineered prompt
Reverse engineered prompt
Build me a tool that can spin up a small realistic security lab in the cloud or locally, with Splunk receiving the logs so I can test detections. I want to be able to choose a template for AWS, Azure, or GCP, create the environment, wait for VPN access, connect through WireGuard, and then continue the setup. It should also let me tear everything down when I am done.
I’d like a simple web app for managing the range, plus a REST API and a command line option for automation. The app should show the current status, let me start attack simulations, and let me share access with other people by generating extra VPN configs. It should use Terraform and Ansible under the hood, and include a few built in attack simulations so I can generate real telemetry for Splunk. If you need to look up current docs online, go ahead and do that.
Are you gonna build this?
make sure you review the code using coderabbit