iT邦幫忙

2026 iThome 鐵人賽

DAY 14
0
問題 風險
Ubuntu 版本不合 高
KVM 沒正常 高
nested virtualization 高
Guest Python 裝 x64 高
Agent 沒 administrator 高
Agent 沒在 8000 port 高
VM 沒 Snapshot 高
VM 名稱與 kvm.conf 不一致 高
resultserver IP 填錯 高
routing 設錯 非常高
Malware VM 接公司 LAN 非常高
Host/Guest 共用資料夾 高
不小心讓 Guest 出 Internet 非常高
所有 CAPE 程式都 sudo 高
apt upgrade 破壞 libvirt 高
磁碟太小 中/高
CPU 沒 AVX 中
直接 git pull production 中/高

最建議採用的第一版架構

考慮你前面一直在研究:

Windows
Docker Desktop
Ubuntu
地端 AI
MCP
CAPEsolo

如果現在把 CAPEv2 也放進來,我會建議分成:

                  實體伺服器
                       │
               Ubuntu 24.04 LTS
                       │
        ┌──────────────┼─────────────┐
        │              │             │
        ▼              ▼             ▼
     CAPEv2          KVM          管理網卡
        │              │
        │        ┌─────┴─────┐
        │        │           │
        │      Win10       Win11
        │       VM           VM
        │        │            │
        │     Agent         Agent
        │
        └──────────────┐
                       │
                  Analysis Data
                       │
               JSON / PCAP / IOC
                       │
                       ▼
                 AI / LLM Host
                       │
                      MCP

而你的:

Docker Desktop / Ubuntu

繼續負責:

LLM
MCP
API
開發環境
Knowledge Base
ERP 開發

不要讓 Docker 成為 malware execution layer。


安裝順序Checklist

[ ] 1. 準備 Ubuntu 24.04 LTS
[ ] 2. 確認 CPU VT-x / AMD-V
[ ] 3. 確認 /dev/kvm
[ ] 4. 安裝 git / tmux
[ ] 5. clone CAPEv2
[ ] 6. 閱讀 installer/kvm-qemu.sh
[ ] 7. 處理 <WOOT>
[ ] 8. 執行 kvm-qemu.sh
[ ] 9. reboot
[ ] 10. 驗證 KVM/libvirt
[ ] 11. 安裝 virt-manager
[ ] 12. 建立 Windows 10 / Win11 23H2 VM
[ ] 13. 使用 QCOW2
[ ] 14. 安裝 Python x86
[ ] 15. 安裝 Pillow
[ ] 16. 複製 agent.py
[ ] 17. Task Scheduler 啟動 Agent
[ ] 18. 測試 VM_IP:8000
[ ] 19. 建立隔離網路
[ ] 20. 配置 static IP
[ ] 21. 配置 CAPE routing
[ ] 22. 建立 clean snapshot
[ ] 23. 安裝 cape2.sh
[ ] 24. 驗證 Poetry / UV
[ ] 25. 驗證 cape.service
[ ] 26. 驗證 cape-processor.service
[ ] 27. 驗證 cape-web.service
[ ] 28. 驗證 cape-rooter.service
[ ] 29. 設定 custom/conf
[ ] 30. 設定 kvm.conf
[ ] 31. 測試 CAPE
[ ] 32. 測試 Web UI
[ ] 33. 測試第一個安全樣本
[ ] 34. 再進行 Malware Analysis

部署建議

如果你是要「真的架一套」而不是只研究 GitHub,我會建議第一版直接採:

Ubuntu 24.04 LTS
        +
KVM/QEMU
        +
virt-manager
        +
Windows 10 x64 Guest
        +
Python 3.12 x86
        +
CAPE Agent
        +
QCOW2 Snapshot
        +
隔離分析網路
        +
CAPEv2

先把單 VM、無 Internet、可成功分析、可正常回復 Snapshot這條路跑通,再增加第二台 Windows 11、Internet Routing、InetSim、Suricata、MongoDB、Distributed CAPE、AI/MCP。

這樣排錯成本最低,也符合 CAPE 官方目前的部署方向。([CAPE Sandbox][17])

官方主要文件:

## 1. Host Installation

- [CAPEv2 GitHub Repository](https://github.com/kevoreilly/CAPEv2)
- [Host Installation](https://github.com/kevoreilly/CAPEv2/blob/master/docs/book/src/installation/host/installation.rst)
- [KVM/QEMU Installation Script](https://github.com/kevoreilly/CAPEv2/blob/master/installer/kvm-qemu.sh)
- [CAPE Installation Script](https://github.com/kevoreilly/CAPEv2/blob/master/installer/cape2.sh)
- [Host Configuration](https://capev2.readthedocs.io/en/latest/installation/host/configuration.html)

## 2. Guest VM

- [Guest Requirements](https://capev2.readthedocs.io/en/latest/installation/guest/requirements.html)
- [Create Virtual Machine](https://capev2.readthedocs.io/en/latest/installation/guest/creation.html)
- [Guest Agent](https://github.com/kevoreilly/CAPEv2/blob/master/docs/book/src/installation/guest/agent.rst)
- [Save / Snapshot Virtual Machine](https://capev2.readthedocs.io/en/latest/installation/guest/saving.html)

## 3. Network

- [Host Routing Configuration](https://github.com/kevoreilly/CAPEv2/blob/master/docs/book/src/installation/host/routing.rst)
- [Per-Analysis Network Routing](https://capev2.readthedocs.io/en/latest/installation/host/routing.html)
- [Guest Network Configuration](https://capev2.readthedocs.io/en/latest/installation/guest_physical/network.html)
- [KVM Configuration](https://github.com/kevoreilly/CAPEv2/blob/master/conf/default/kvm.conf.default)

## 4. Operation

- [Web Interface](https://capev2.readthedocs.io/en/latest/usage/web.html)
- [Starting CAPE](https://capev2.readthedocs.io/en/latest/usage/start.html)

## 5. Documentation

- [CAPE Sandbox Installation](https://capev2.readthedocs.io/en/latest/installation/)
- [CAPE Sandbox Documentation](https://capev2.readthedocs.io/en/latest/)


上一篇
省時間的人(需熟悉環境)
下一篇
[Day 15] conf 相關設定
系列文
從情資收集到資安鑑識:30 天建構自動化威脅情資與鑑識平台 共 18 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言