Skip to content

Aurora Lite Hands-on Labs

Choose the browser lab for a guided first experience, or use the complete guide when you have an isolated Windows VM. Both routes teach the same evidence-first workflow: verify the agent, create a controlled event, inspect the Sigma match, and record what the evidence supports.

Hands-on endpoint proof of concept

Prepare it. Detect it. Validate it.

Build or restore an isolated Windows VM, verify Aurora Lite, reproduce a controlled detection, and extend the working baseline with one additional harmless validation test.

⏱ 1–2 hours ◆ Beginner ✓ Evidence required
Self-hosted · Several hours

Aurora Lite Full Lab

Installation required

Use the complete Aurora Lite guide to retain the original screenshots, configuration options, function tests, response examples, and proof-of-concept record.

Use an isolated, authorised system

Start with the harmless function tests documented by Nextron. Snapshot the VM before testing response actions. The historical ransomware demonstration in the complete guide requires specialist malware-handling controls and is not part of this beginner route.

Objective

Prove that one controlled Windows event travels through Aurora's complete detection path and can be explained using process, rule, user, host, and timing evidence.

01

Activity 1: Prepare the environment

  1. Build or restore an isolated Windows VM.
  2. Record its hostname, Windows version, address, administrator account, and snapshot name.
  3. Follow Install and verify to prepare Aurora and its dashboard.
  4. Confirm that Aurora is healthy before changing configuration.

Expected result The service is running, rules load successfully, the local dashboard opens, and a clean snapshot is available.

02

Activity 2: Reproduce a detection

  1. Review the lab topology.
  2. Download and prepare Aurora Lite.
  3. Install Aurora with its dashboard.
  4. Note the current time and run whoami /priv from an ordinary terminal—not from the Aurora dashboard.
  5. Refresh Aurora Overview and locate the matching event by time and title.
  6. Expand the record and save the rule title, severity, match, image, command line, user, parent process, host, and timestamp.
  7. Compare it with a routine service or updater event.
  8. Record the event as a controlled test; do not claim compromise when the activity was intentionally generated.

Expected result The controlled command produces a Sigma match, while the routine comparison event is not incorrectly included in the finding.

03

Activity 3: Extend and validate

Choose one additional harmless function test from Test and investigate. Before running it, predict which event source, rule type, and severity you expect. Then:

  1. Run the positive test and preserve its matching record.
  2. Run or identify a benign control that should not match the same rule.
  3. Explain any difference between your prediction and the result.
  4. If appropriate, reproduce the reversible Notepad response test.
  5. Restore the last known-good snapshot if the baseline changes unexpectedly.

Expected result Your evidence contains a positive result, a benign control, the exact configuration used, and a conclusion limited to what those records prove.

Full Lab evidence checklist

This checklist applies to the VM-based lab. If you completed the browser lab, retain its downloaded evidence summary instead.

0 of 6 recorded Mark each item when you have saved the evidence.

Troubleshooting

Symptom First check
No event appears Confirm service health, preset coverage, test timestamp, and dashboard refresh.
Rule compilation error Preserve the error, identify the affected rule, and confirm other rules loaded before editing anything.
Duplicate-looking events Compare event IDs, timestamps, sources, and match fields before deduplicating.
Test matches but response does not run Confirm responses are activated and the rule references the intended response set.
Unexpected system impact Stop testing and restore the last verified snapshot.

Clean up

Delete harmless test artifacts using their documented cleanup commands, remove temporary exclusions that are no longer approved, export the evidence note, and return the VM to its clean or known-good snapshot.

Where to go next