TRAINING COURSES
Adversary Tactics: Identity-Driven Offensive Tradecraft
WHAT TO EXPECT
Learn how to find and abuse attack paths
Identity has become the connective thread across modern hybrid environments, making identity-driven attacks one of the most critical threat vectors organizations face today. Traditional network-based security approaches fail when attackers abuse authentication and authorization mechanisms to move laterally across on-premises and cloud boundaries.
This advanced course equips red teamers and offensive security professionals with techniques to discover and exploit identity attack paths in complex environments—from familiar Active Directory weaknesses to cutting-edge cloud and supply chain attacks. Developed by practitioners who execute real-world identity assessments, this course teaches the methodology for identifying both known attack paths and discovering new primitives across diverse technology stacks.
key takeaways
Course summary
Modern ecosystems rely on Identity Providers (IdP) and Identity and Access Management (IAM) systems to authenticate users and govern access. Threat actors and red teams increasingly use “identity-driven” tradecraft to navigate modern environments and attack paths.
But what turns a path into an attack path? How do attackers discover new paths, abuse IAM platforms, and execute high-impact attacks? This immersive course equips students with methods to discover attack paths in complex environments, including both known techniques and new attack primitives in common technology stacks and bespoke systems. Students will learn to identify and execute elaborate attacks against on-premises and cloud technologies. They’ll practice through hands-on labs that simulate real-world environments and a variety of technologies and attack paths, including cross-tenant and supply chain attacks.
Participants will learn
How to use Clean Source Principle (CSP) analysis to methodically identify violations and discover both known and new attack paths
How to abuse on-premises and hybrid identity architectures for lateral movement and privilege escalation in complex enterprise environments
How to master various authentication and authorization mechanisms and execute elaborate attacks abusing them and their security dependencies for privilege escalation and system access to achieve red team objectives
A CLOSER LOOK AT THE COURSE
Adversary Tactics: Identity-Driven Offensive Tradecraft
As modern architecture increasingly shifts services and data from on-premises infrastructure to the cloud, identity becomes the thread that ties everything together. Adversary Tactics: Identity-driven Offensive Tradecraft is a follow-on to our Adversary Tactics: Red Team Operations course and offers an in-depth look at identity-driven attacks, targeting both on-premises and hybrid identities. Participants learn how to abuse the intricacies of different authentication and authorization mechanisms to traverse on-premises and cloud environments, gain access to integrated systems, and even cross tenants. Participants are equipped with a practical approach to identifying known attack paths and forging new ones within complex operational environments and across people, processes, and technology. Technologies covered include Kerberos, NTLM, ADCS, ADFS, SAML, Okta, Entra ID, OAuth, Azure, and hybrid identities.
Dig into Identity-Driven Offensive Tradecraft
Participants learn how to abuse the intricacies of different authentication and authorization mechanisms to traverse on-premises and cloud environments, gain access to integrated systems, and even cross tenants. Participants are equipped with a practical approach to identifying known attack paths and forging new ones within complex operational environments and across people, processes, and technology. Technologies covered include Kerberos, NTLM, ADCS, ADFS, SAML, Okta, Entra ID, OAuth, Azure, and hybrid identities.
In typical SpecterOps fashion, “Red vs. Blue” discussions are incorporated into lectures to provide students with the defender’s perspective and detection logic, as well as OPSEC considerations to counter them. A defender will also actively “hunt” students in the lab to push them to improve their tradecraft by making educated decisions.
Here’s what we’ll cover:
- Introduction
- Attack Path Theory and The Clean Source Principle
- Kerberos Delegation Abuse
- Computer Authentication Coercion
Here’s what we’ll cover:
- NTLM Attacks
- User Authentication Coercion
- ADIDNS Tradecraft
- ADCS Introduction
- ADCS Abuse
- Shadow Credentials
Here’s what we’ll cover:
- SAML Attacks
- ADFS Tradecraft
- Configuration Manager (SCCM) Attacks
- Introduction to Okta
- Okta Abuse
Here’s what we’ll cover:
- OAuth Introduction and Abuse
- Entra ID and Hybrid Identities
- Devices Identities and PRTs
- Azure RM
- Microsoft Graph
- Cross-Tenant Attacks
Before you attend
Who should attend
- Red teamers and penetration testers seeking to learn advanced tradecraft that works in mature environments.
- Blue teamers seeking to gain insight into advanced tradecraft commonly used by advanced threat actors.
- Security practitioners seeking to learn a methodic approach for identifying attack paths in complex systems or environments.
Prerequisites
Proficiency in the following:
- Windows and Active Directory fundamentals
- Operating through a C2 agent
- Payload generation
- Lateral movement techniques
- Credential abuse on Windows systems
Completion of the Adversary Tactics: Red Team Operations course is highly recommended but not strictly required. We recommend participants have at least two (2) years of practical experience.
What to bring
Participants must provide their own computer with a modern web browser installed to access training materials and complete the course’s labs. The SpecterOps training platform URL (specterops.training) must be accessible from the participant’s computer throughout the duration of the course. The participant’s computer must also support joining a Zoom call and a Slack Workspace.
There are no local virtual machines or special software required to fully participate in the course or labs.
What you receive
During the course, participants receive access to a hands-on training range where they complete labs and work through course objectives.
Upon completion of the course, participants receive:
- A copy of the course slides
- A certificate of completion
- A course challenge coin
- A digital badge
Accepting your digital badge confirms your SpecterOps Training alumni status, which conveys exclusive discounts to future SpecterOps hosted training.
MORE WAYS TO TRAIN
Private and custom training
SpecterOps courses, delivered exclusively for your team. Need something beyond our current offerings? We develop custom curriculum, labs, and CTFs designed around your team’s specific goals and threat landscape. Our training is taught by the same front-line practitioners who conduct our engagements, bringing real-world experience into every course.
DEEPEN YOUR TRADECRAFT
Explore additional training courses
Adversary Perspectives: Active Directory
Learn Active Directory’s architecture and security implications, and identify misconfigurations before an attacker does.
Adversary Perspectives: Azure
Discover how adversaries view, target, and exploit Azure and Entra ID environments.
Adversary Tactics: Red Team Operations
Go beyond Domain Admin and sharpen your offense-in-depth skills.
Adversary Tactics: Detection
Stop chasing indicators. Build detections that focus on how attackers operate.
Adversary Tactics: Tradecraft Analysis
Deconstruct how attack techniques really work, then build detections or learn how to evade them.
SpecterOps Tradecraft Academy
Hands-on offensive and defensive security training built by SpecterOps practitioners, available on demand and designed to be completed at your own pace.