Module Introduction
In this module, you’ll start building Layer 3 from the topology map—the external-facing layer of your C2 infrastructure—and securely connect it to on-premises systems. You will deploy VPS instances at a cloud provider, register and configure realistic domain names, and set up dedicated redirectors using tools such as RedWarden (for Cobalt Strike) and HAProxy (for Mythic). Along the way, you will make conscious choices about providers, sizing, and access methods (via Mgmt-server and Guacamole), so that exposed infrastructure remains controlled, secure, and cost-effective.
You will then implement Nebula as a mesh VPN to securely connect on-prem teamservers and cloud redirectors in a private overlay network, and use autossh to forward accepted beacon traffic from each redirector to the appropriate teamserver. By the end of this module, you will understand the role of redirectors, how to build them on public cloud infrastructure, and how to connect them to your teamservers in a way that minimizes exposure while keeping the environment flexible and scalable.