Skip to content

Kansa Hands-on Labs

Choose the Interactive Lab for a short guided investigation with no installation, or use the Full Lab to collect and compare endpoint evidence in an isolated Windows lab.

Interactive Lab

Browser-based · 10–20 min

Kansa Interactive Lab

No installation

Practise a guided Kansa workflow in a safe browser simulation with immediate feedback.

Case SUSA-014: unexpected processRun a simulated collection, query the TSV, and assess a process lead
Task 1 of 4
Safe simulationCommands run only inside this browser exercise. No PowerShell process, endpoint, or evidence is accessed.
  1. 1Validate
  2. 2Collect
  3. 3Query
  4. 4Assess
Windows PowerShellSUSA-LAB · Administrator

Windows PowerShell 5.1: Kansa training environment

Case: investigate an unexpected process on WIN11-LAB

Validate the collector to begin.

Full Lab

Self-hosted · Setup: 30–60 min · Core exercise: 45–90 min

Kansa Full Lab

Two Windows lab endpoints required

Hands-on live-response proof of concept

Collect it. Compare it. Explain it.

Collect a focused process baseline from two authorised endpoints, investigate the difference, and document a supported conclusion.

⏱ Setup: 30–60 min · Core exercise: 45–90 min◆ Supported intermediate✓ Evidence required

Outcome-led, not command-copying

The Full Lab provides a case question, boundaries, a checklist, and expected evidence. Choose the exact Kansa modules and commands from the preserved guide, record meaningful differences, and stop when a prerequisite fails.

Optional extension

Add network context

Run the focused network-connection module and correlate a process with its local and remote endpoints without expanding collection beyond the case scope.

Expected time: one additional 30–45 minute session.

Safety boundary

Use only an owned or explicitly authorised endpoint. Record the live-system changes caused by collection.

Evidence

an authorised Windows lab endpoint and a written collection question

Success evidence

targeted output whose source, time, tool version, and integrity are recorded

Full Lab scenario

Case SUSA-014: two authorised Windows lab endpoints should have the same approved software baseline. A triage note reports chrome_update.exe from C:\Users\Public on one host. Use a narrowly scoped Kansa process collection to determine which endpoint returned the row, preserve the relevant TSV and collection context, compare it with the second endpoint, and write a bounded finding. Do not treat the filename alone as proof of malware.

Your final evidence pack should include the target list, module selection, command or parameters, collection time, output directory, relevant TSV rows, hashes of retained output, errors, comparison result, and limitations.

01

Activity 1: Prepare the environment

  1. Create or restore two isolated Windows training VMs named WIN11-LAB01 and WIN11-LAB02. Record their addresses, time zones and clean snapshot names.
  2. Install Kansa only on the analyst VM or designated collection host. Record the Kansa commit or release and PowerShell version.
  3. Configure PowerShell Remoting by following the preserved guide. Test each endpoint individually before creating a target list.
  4. Create Targets-SUSA-014.txt containing only the two authorised endpoint names. Keep the lab network isolated from production systems.
Milestone 1Collection boundary readyBoth endpoints respond to the authorised remoting test, the target list contains only the two lab systems, and clean snapshots are recorded.

02

Activity 2: Collect and compare

  1. On WIN11-LAB01, create a harmless training copy of a known executable at C:\Users\Public\chrome_update.exe and start it with a recognisable test argument. Do not use malware or an unknown executable.
  2. Leave WIN11-LAB02 as the comparison endpoint. Record the time when the controlled process was started.
  3. Review Modules.conf and enable only the focused process module used in the guide. Save a copy of the module selection with the case material.
  4. Run Kansa against Targets-SUSA-014.txt with TSV output and verbose logging. Stop if either target falls outside the recorded authority or returns a remoting error.
  5. Confirm that the output directory contains attributable results for both endpoints and retain any Error.Log rather than deleting it.
Milestone 2Comparable process evidence returnedBoth authorised targets have reviewable output, and the controlled row remains linked to its endpoint, module, collection time and command.

03

Activity 3: Investigate and report

  1. Import the TSV results with the correct tab delimiter. Filter for executable paths under C:\Users\Public and compare the matching rows across both endpoints.
  2. Review process name, executable path, parent, command line, user, creation time and available hash fields. Record missing fields as limitations.
  3. Hash the retained output and preserve a working copy. Keep collection logs, target list and module configuration with the result.
  4. Write a short finding with four parts: observation, interpretation, confidence and limitations. State explicitly that the controlled row validates the workflow but does not prove compromise or user intent.
  5. Clean up the harmless process and restore both VMs to their clean snapshots.
Milestone 3Finding ready for reviewAnother beginner can reproduce the scoped collection, identify the same endpoint difference and understand what the evidence does and does not establish.

Full Lab evidence checklist

This checklist applies to the two-endpoint Full Lab. If you completed the Interactive Lab, retain its browser evidence summary instead.

Complete the exercise by showing that the scoped collection worked and that the conclusion is traceable to retained evidence.

  • Core completion

    Required to demonstrate the learning objective safely.

  • Good analyst practice

    Retain these supplementary records to improve reproducibility and review quality.

0 of 9 recorded Mark each item when you have saved the evidence.

Clean up

Protect retained output and case notes, remove harmless training material, clear temporary credentials or access and restore disposable systems to their recorded baseline. Confirm that no test collection remains active.