| 問題 | 風險 |
|---|---|
| Ubuntu 版本不合 | 高 |
| KVM 沒正常 | 高 |
| nested virtualization | 高 |
| Guest Python 裝 x64 | 高 |
| Agent 沒 administrator | 高 |
| Agent 沒在 8000 port | 高 |
| VM 沒 Snapshot | 高 |
| VM 名稱與 kvm.conf 不一致 | 高 |
| resultserver IP 填錯 | 高 |
| routing 設錯 | 非常高 |
| Malware VM 接公司 LAN | 非常高 |
| Host/Guest 共用資料夾 | 高 |
| 不小心讓 Guest 出 Internet | 非常高 |
| 所有 CAPE 程式都 sudo | 高 |
apt upgrade 破壞 libvirt |
高 |
| 磁碟太小 | 中/高 |
| CPU 沒 AVX | 中 |
| 直接 git pull production | 中/高 |
考慮你前面一直在研究:
Windows
Docker Desktop
Ubuntu
地端 AI
MCP
CAPEsolo
如果現在把 CAPEv2 也放進來,我會建議分成:
實體伺服器
│
Ubuntu 24.04 LTS
│
┌──────────────┼─────────────┐
│ │ │
▼ ▼ ▼
CAPEv2 KVM 管理網卡
│ │
│ ┌─────┴─────┐
│ │ │
│ Win10 Win11
│ VM VM
│ │ │
│ Agent Agent
│
└──────────────┐
│
Analysis Data
│
JSON / PCAP / IOC
│
▼
AI / LLM Host
│
MCP
而你的:
Docker Desktop / Ubuntu
繼續負責:
LLM
MCP
API
開發環境
Knowledge Base
ERP 開發
不要讓 Docker 成為 malware execution layer。
[ ] 1. 準備 Ubuntu 24.04 LTS
[ ] 2. 確認 CPU VT-x / AMD-V
[ ] 3. 確認 /dev/kvm
[ ] 4. 安裝 git / tmux
[ ] 5. clone CAPEv2
[ ] 6. 閱讀 installer/kvm-qemu.sh
[ ] 7. 處理 <WOOT>
[ ] 8. 執行 kvm-qemu.sh
[ ] 9. reboot
[ ] 10. 驗證 KVM/libvirt
[ ] 11. 安裝 virt-manager
[ ] 12. 建立 Windows 10 / Win11 23H2 VM
[ ] 13. 使用 QCOW2
[ ] 14. 安裝 Python x86
[ ] 15. 安裝 Pillow
[ ] 16. 複製 agent.py
[ ] 17. Task Scheduler 啟動 Agent
[ ] 18. 測試 VM_IP:8000
[ ] 19. 建立隔離網路
[ ] 20. 配置 static IP
[ ] 21. 配置 CAPE routing
[ ] 22. 建立 clean snapshot
[ ] 23. 安裝 cape2.sh
[ ] 24. 驗證 Poetry / UV
[ ] 25. 驗證 cape.service
[ ] 26. 驗證 cape-processor.service
[ ] 27. 驗證 cape-web.service
[ ] 28. 驗證 cape-rooter.service
[ ] 29. 設定 custom/conf
[ ] 30. 設定 kvm.conf
[ ] 31. 測試 CAPE
[ ] 32. 測試 Web UI
[ ] 33. 測試第一個安全樣本
[ ] 34. 再進行 Malware Analysis
如果你是要「真的架一套」而不是只研究 GitHub,我會建議第一版直接採:
Ubuntu 24.04 LTS
+
KVM/QEMU
+
virt-manager
+
Windows 10 x64 Guest
+
Python 3.12 x86
+
CAPE Agent
+
QCOW2 Snapshot
+
隔離分析網路
+
CAPEv2
先把單 VM、無 Internet、可成功分析、可正常回復 Snapshot這條路跑通,再增加第二台 Windows 11、Internet Routing、InetSim、Suricata、MongoDB、Distributed CAPE、AI/MCP。
這樣排錯成本最低,也符合 CAPE 官方目前的部署方向。([CAPE Sandbox][17])
官方主要文件:
## 1. Host Installation
- [CAPEv2 GitHub Repository](https://github.com/kevoreilly/CAPEv2)
- [Host Installation](https://github.com/kevoreilly/CAPEv2/blob/master/docs/book/src/installation/host/installation.rst)
- [KVM/QEMU Installation Script](https://github.com/kevoreilly/CAPEv2/blob/master/installer/kvm-qemu.sh)
- [CAPE Installation Script](https://github.com/kevoreilly/CAPEv2/blob/master/installer/cape2.sh)
- [Host Configuration](https://capev2.readthedocs.io/en/latest/installation/host/configuration.html)
## 2. Guest VM
- [Guest Requirements](https://capev2.readthedocs.io/en/latest/installation/guest/requirements.html)
- [Create Virtual Machine](https://capev2.readthedocs.io/en/latest/installation/guest/creation.html)
- [Guest Agent](https://github.com/kevoreilly/CAPEv2/blob/master/docs/book/src/installation/guest/agent.rst)
- [Save / Snapshot Virtual Machine](https://capev2.readthedocs.io/en/latest/installation/guest/saving.html)
## 3. Network
- [Host Routing Configuration](https://github.com/kevoreilly/CAPEv2/blob/master/docs/book/src/installation/host/routing.rst)
- [Per-Analysis Network Routing](https://capev2.readthedocs.io/en/latest/installation/host/routing.html)
- [Guest Network Configuration](https://capev2.readthedocs.io/en/latest/installation/guest_physical/network.html)
- [KVM Configuration](https://github.com/kevoreilly/CAPEv2/blob/master/conf/default/kvm.conf.default)
## 4. Operation
- [Web Interface](https://capev2.readthedocs.io/en/latest/usage/web.html)
- [Starting CAPE](https://capev2.readthedocs.io/en/latest/usage/start.html)
## 5. Documentation
- [CAPE Sandbox Installation](https://capev2.readthedocs.io/en/latest/installation/)
- [CAPE Sandbox Documentation](https://capev2.readthedocs.io/en/latest/)