0% found this document useful (0 votes)
12 views11 pages

Enterprise Infrastructure Specification Document

The document outlines the specification for Phase 1 of building a secure enterprise infrastructure for SecurinetsENIT, focusing on designing and deploying an Active Directory domain and configuring essential Windows services. It details project goals, technical architecture, Active Directory design, security measures, and testing protocols, culminating in comprehensive documentation of the setup. The project is structured into phases, with a total duration of approximately 8 weeks, emphasizing hands-on experience in enterprise IT security and networking.

Uploaded by

Joudi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views11 pages

Enterprise Infrastructure Specification Document

The document outlines the specification for Phase 1 of building a secure enterprise infrastructure for SecurinetsENIT, focusing on designing and deploying an Active Directory domain and configuring essential Windows services. It details project goals, technical architecture, Active Directory design, security measures, and testing protocols, culminating in comprehensive documentation of the setup. The project is structured into phases, with a total duration of approximately 8 weeks, emphasizing hands-on experience in enterprise IT security and networking.

Uploaded by

Joudi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Specification Document

Phase 1: Building Entreprise Infrastructure

Prepared by: SecurinetsENIT


November, 2025
CONTENTS

1 Executive Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
2 Project Goals and Learning Objectives . . . . . . . . . . . . . . . . . . . . . 1
2.1 Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
2.2 Key Takeaways . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
3 Technical Architecture and Environment . . . . . . . . . . . . . . . . . . . . 2
4 Technical Architecture and Environment . . . . . . . . . . . . . . . . . . . . 2
5 Active Directory Design and Configuration . . . . . . . . . . . . . . . . . . . 3
5.1 Organizational Unit (OU) Structure . . . . . . . . . . . . . . . . . . . 3
5.2 Delegation of Control Matrix . . . . . . . . . . . . . . . . . . . . . . 3
5.3 Group Policy Objects (GPOs) Strategy . . . . . . . . . . . . . . . . . 5
6 System and Network Services Configuration . . . . . . . . . . . . . . . . . . 6
7 Network Security and Perimeter Defense . . . . . . . . . . . . . . . . . . . . 6
8 Security Testing, Validation, and Deliverables . . . . . . . . . . . . . . . . . 7
8.1 Attack Testing and Infrastructure Validation . . . . . . . . . . . . . . 7
8.2 Final Product Deliverables . . . . . . . . . . . . . . . . . . . . . . . . 7
9 Project Timeline and Evaluation Schedule . . . . . . . . . . . . . . . . . . . 8
CONTENTS

1 Executive Summary
This project represents the first phase in establishing a secure, reliable, and fully operational
enterprise network infrastructure for SecurinetsENIT within a controlled virtualized en-
vironment. Its primary objective is to design and deploy an Active Directory (AD)
domain, configure critical Windows services (DNS, LDAP, ADCS, and Kerberos), and
implement granular access controls through Group Policy Objects (GPOs) and delega-
tion mechanisms. In addition, the project aims to reinforce network security by integrating
an IDS/IPS-based firewall for perimeter protection.
The implementation will conclude with a testing to validate the effectiveness of all deployed
controls, supported by detailed technical documentation of the entire setup.

2 Project Goals and Learning Objectives

2.1 Prerequisites

The primary prerequisite for this project is a strong motivation to learn and explore new
concepts in enterprise IT security and networking.

2.2 Key Takeaways

Successful completion of this project phase will demonstrate proficiency and practical expe-
rience in the following areas:

• Network Fundamentals: In-depth understanding of network architecture, IP address-


ing, subnetting, and connectivity testing across virtualized network segments.

• Active Directory Administration: Deployment and management of Domain Con-


trollers (DCs), users, groups, Organizational Units (OUs), and Group Policy Objects
(GPOs).

• Enterprise Environment Familiarity: Hands-on experience with Windows Server


2022 and Windows client systems within a domain-joined enterprise environment.

• Windows Services Configuration: Configuration and troubleshooting of critical ser-


vices such as LDAP, Active Directory Certificate Services (ADCS), and Domain Name
System (DNS).

1
CONTENTS

• Kerberos Authentication: Comprehensive understanding of the Kerberos authenti-


cation protocol, including ticket exchange, encryption mechanisms, and common vulner-
abilities.

• Attack and Defense Techniques: practical exposure to common attack vectors and
implementation of effective mitigation strategies.

• Perimeter Security Implementation: Deployment and configuration of an Intrusion


Detection and Prevention System (IDS/IPS) using OPNsense and Zenarmor/Suricata for
enhanced network defense.

3 Technical Architecture and Environment


The project environment is fully virtualized and hosted on a VMware platform, providing an
isolated and controllable setup for deploying and testing enterprise-grade network services.
This architecture ensures scalability, ease of snapshot-based recovery, and realistic emulation
of a corporate IT infrastructure.

4 Technical Architecture and Environment


The project environment is fully virtualized and hosted on a VMware platform, providing
an isolated and controllable setup for deploying and testing enterprise-grade network services.

Component Role Operating System Notes


/ Tool
Domain Primary Identity Windows Server Hosts AD DS, DNS,
Controller and Authentication 2022 ADCS, LDAP, and
Server the Kerberos KDC.
Workstation Standard Client Windows 10 or 11 Domain-joined client
Endpoint used for testing user
access, GPO
application, and
authentication
workflows.
Firewall Network Security OPNsense (with Provides routing,
and Traffic Zenarmor and NAT, firewall, and
Management Suricata) IDS/IPS capabilities;
positioned between
external and internal
virtual networks.

2
CONTENTS

5 Active Directory Design and Configuration

5.1 Organizational Unit (OU) Structure

The OU structure is designed to logically separate directory objects and facilitate targeted
Group Policy Object (GPO) application and delegation of control based on the Principle of
Least Privilege (PoLP).

→ [Link] (Root Domain)

• _SERVICE_ACCOUNTS

• COMPUTERS

◦ Workstations

◦ Servers

• USERS

◦ Admins

– DomainAdmins

– Technical Team

◦ Departments

– Finance

– Marketing

– IT

5.2 Delegation of Control Matrix

Control is delegated to specific security groups (rather than individual users) at the appro-
priate OU level, ensuring accountability and maintainability. The following table outlines
the delegation design.

3
CONTENTS

Group / Role Target OU(s) Permissions Granted Permissions


(Delegated Control) Denied
(Implicitly)
DomainAdmins Root Domain, All Full administrative control, No
OUs including Domain Controller administrative
management, schema restrictions
modification, and GPO linking within the lab
at the domain level. environment.
Technical COMPUTERS/Servers, Manage server objects, reset Modifying
Team USERS/Departments computer accounts, apply GPOs domain-level
/IT for IT systems, and perform policies,
routine AD maintenance. altering admin
accounts, or
schema
changes.
Finance USERS/Departments Read and write access to Installing
Department /Finance financial shared folders, logon software,
rights to accounting servers, and modifying
use of department-specific GPOs. network
configurations,
or accessing
Marketing/IT
data.
Marketing USERS/Departments Read/write access to marketing Accessing
Department /Marketing drives and collaboration tools, Finance or IT
use of standard GPO-based systems,
security settings. modifying
system settings,
or installing
unauthorized
software.
IT Department USERS/Departments Elevated permissions to maintain Schema
/IT workstations, manage network modifications,
configurations, and assist with domain-level
technical troubleshooting. GPO linking, or
management of
DomainAdmins.
Workstations COMPUTERS/Worksta- Standard user permissions for Any
OU Users tions business operations and administrative
workstation logon. privileges,
software
installation, or
system
configuration
changes.

4
CONTENTS

5.3 Group Policy Objects (GPOs) Strategy

GPOs will be linked to the appropriate Organizational Units (OUs) to enforce security
baselines, ensure consistent configuration, and maintain compliance across the environment.
Each GPO targets a specific OU or group of users and computers.

GPO Name Link Location Target Key Settings (Example)


Default Domain Domain Root All Users/- Password Policy: Enforce complex-
Policy Computers ity, Min Length (14 chars), Max Age
(45 days), Lockout Threshold (5 at-
tempts). Kerberos Policy: Max
ticket lifetime (10 hours).
User - Standard USERS/Depart- Finance, Enforce screen lock after 10 mins
Security ments Marketing, idle, disable Control Panel access
IT (Finance/Marketing), apply desk-
top background (branding), restrict
command-line tools for non-IT users.
Computer - COMPUTERS/Work- Domain- Enable Windows Firewall (block un-
Hardening stations joined used inbound ports), disable guest ac-
Computers counts, restrict USB auto-run, enforce
secure channel signing, remove local
admin privileges.
Server - Secu- COMPUTERS/Servers Domain Audit object access, disable anony-
rity Baseline and mous SID enumeration, enforce
Service NTLMv2, restrict PowerShell execu-
Servers tion, enable NTP sync with DC.
IT Admin Tools USERS/Admins/ IT Admin- Allow PowerShell execution, enable
Policy Technical Team istrators remote management, disable sleep-
/hibernation, enforce event log reten-
tion, enable RSAT tools.
Finance Appli- USERS/Departments Finance Apply AppLocker/SRP rules (signed
cation Control /Finance Users executables only), disable removable
drives, enforce restricted access to fi-
nancial shares.
Marketing En- USERS/Departments Marketing Enforce browser proxy settings, set
vironment Pol- /Marketing Users homepage, restrict registry editing,
icy disable time zone and network config-
uration changes.
IT Worksta- USERS/Departments IT Staff Enable developer tools (Wireshark,
tions Policy /IT Systems Nmap), allow lab PowerShell scripts,
enable PowerShell and privilege esca-
lation auditing.

5
CONTENTS

6 System and Network Services Configuration


This phase focuses on core AD services crucial for the secure operation and future attack
validation steps.

1. DNS & DHCP: Configure the Domain Controller to act as the authoritative DNS
server for the domain. Ensure all client VMs are properly utilizing the DC for DNS
resolution.

2. LDAP: Verify secure LDAP (LDAPS) functionality.

3. AD Certificate Services (ADCS): Install and configure a basic Enterprise Certifi-


cate Authority (CA) on the DC.

4. Kerberos Authentication: Verify correct ticket generation (TGT and TGS) using
command-line tools (klist). Document SPN requirements for later testing.

7 Network Security and Perimeter Defense


1. Firewall (OpenSense) Setup: Configure the firewall VM to separate the internal
AD network from the external simulated network/Internet access.

2. Zenarmor/Suricata IDS/IPS Configuration:

• Enable and configure Zenarmor/Suricata for IDS mode initially (monitoring).

• Test baseline alerts by simulating basic unauthorized traffic.

• Switch to IPS mode for active blocking and validate that configured AD attacks
are blocked.

You are encouraged to research, evaluate, and propose additional or alternative network
security tools to complement the baseline IDS/IPS deployment.

6
CONTENTS

8 Security Testing, Validation, and Deliverables

8.1 Attack Testing and Infrastructure Validation

This phase ensures the defense mechanisms built in the AD and Firewall are effective.

• Credential Attacks:

– AS-REP Roasting: Targeting user accounts where pre-authentication is inten-


tionally disabled (lab only).

– Kerberoasting: Exploiting weak SPNs (Service Principal Name) against service


accounts.

– Password Spraying/Brute Force: Validate Account Lockout policies.

• Access Control Validation: Attempt delegated tasks and verify restrictions.

• GPO Enforcement Test: Verify GPOs apply correctly to Workstation VM.

• Firewall/IPS Test: Attempt port scanning and simple exploits to validate log-
ging/blocking.

8.2 Final Product Deliverables

1. Full Connected Network: All three VMs configured per spec.

2. Firewall Configuration: OpenSense with Suricata/Zenarmor configured and opera-


tional.

3. Presentation: Summary of design decisions, implementation steps, controls and find-


ings.

4. Full Documentation (GitBook/Blog/GitHub):

• Step-by-step installation and configuration.

• Complete AD Design documentation (OU Structure, Groups, Delegation).

• GPO implementation details and screenshots.

• Summary of Kerberos concepts and attack simulation results.

• References.

7
CONTENTS

9 Project Timeline and Evaluation Schedule

Phase Duration Tasks Evaluation Cri-


teria (Weekly)
Phase 1: Setup 1 Week Download ISOs, configure VMs, install Proof: VMs suc-
and Connectiv- OS, verify connectivity. cessfully ping each
ity other and resolve
DNS.
Phase 2: Core 1–2 Weeks Promote Domain Controller, design Demo: OU struc-
AD & Services OU structure, create users/groups, ture, delegated
configure LDAP/DNS/GPOs. rights, GPO en-
forcement.
Phase 3: 1 Week Install OPNsense, configure Report: Firewall
Perimeter WAN/LAN, deploy Zenarmor/- rules, IDS logs,
Defense & Suricata in IDS mode and tune rules. and tuning notes.
Hardening
Phase 4: Ad- 1–2 Weeks Research Kerberos, configure ADCS, Quiz/Demo: Ker-
vanced AD & register SPNs and prepare Kerberoast- beros flow expla-
Kerberos ing lab scenarios. nation and SPN
documentation.
Phase 5: Attack 1 Week Execute test scenarios, validate detec- Presentation:
Testing & Final tions and blocks, finalize documenta- Test results, logs,
Deliverables tion and presentation. mitigations, and
completed docu-
mentation.
Total Project Duration: ≈ 8 Weeks

8
CONTENTS

You might also like