TRAINING COURSES

Adversary Tactics: Red Team Operations

iAPM-HeroImage-RedTeam@2x_f12236
APM-MainImage-RedTeam@2x

WHAT TO EXPECT

Go beyond Domain Admin and sharpen your offense-in-depth skills

Leveraging experience from hundreds of adversary simulation exercises, we built this course to teach effective red team operations. Most organizations have adopted an “assume breach” mentality, understanding that sophisticated adversaries will breach their defenses.

The best way to test enterprise security operations is through red team exercises that leverage the same tactics, techniques, and procedures (TTPs) as real attackers. Students learn offensive tradecraft post-initial access, from resilient command and control to advanced Active Directory exploitation, by operating against live incident responders in simulated enterprise environments. Real-time defender feedback reveals what artifacts attackers leave behind and how to minimize detection footprints.

key takeaways

Course summary

Upgrade your red team tradecraft with tactics, techniques, and procedures (TTPs) commonly used by attackers in real-world breaches.

This course teaches students how to design resilient command and control infrastructure and covertly operate in target networks to simulate advanced adversaries. Students learn to apply data-driven approaches to tradecraft decisions, execute advanced Active Directory attacks, perform sophisticated post-exploitation actions beyond “Domain Admin,” and practice “offense-in-depth” by adapting techniques in response to defenders. Participants will use the skillsets taught in this course to go up against live defenders in an elaborate lab environment mimicking an enterprise network, learning to adapt and overcome active response operations through collaborative feedback.

Participants will learn

Icons-Connect

How to plan red team engagements and design effective attack infrastructure and payloads

Icons-Check

How to apply a data-driven approach to making educated, risk-based tradecraft decisions that reduce detection likelihood

Cards-Learn3@2x

How to identify and traverse attack paths in Active Directory and Windows environments

A CLOSER LOOK AT THE COURSE

Adversary Tactics: Red Team Operations

To avoid becoming the next breach headline, organizations are testing their defenses by simulating the same sophisticated adversaries targeting them in the wild. Organizations with an “assume breach” mentality understand that it’s not a matter of if these adversaries compromise them but when. Red team exercises using real attacker tactics, techniques, and procedures (TTPs) provide the most effective validation. If you want to learn the tradecraft of adversary simulation operations in enterprise environments, sharpen your offensive technical skillset, and understand how to detect modern advanced threat actor tradecraft, this course is for you.

Dig into Red Team Operations

This intense course immerses students in a single simulated enterprise environment, with multiple networks, hardened endpoints, modern defenses, and active network defenders responding to red team activities. The course focuses on in-depth attacker tradecraft post-initial access, breaking out of the beachhead, establishing resilient command and control (C2) infrastructure, gaining situational awareness through OPSEC-aware host and network enumerations, performing advanced lateral movement and sophisticated Active Directory escalation, establishing persistence (userland, elevated, and domain flavors), and executing advanced Kerberos attacks, data mining, and exfiltration.

A focus is on “offense-in-depth”—the ability to rapidly adapt to defensive mitigations and responses with various offensive tactics and techniques. To drive this concept home, students will go against live incident responders who actively hunt for and block malicious activity in the environment. The responders provide real-time feedback to students demonstrating what artifacts attackers can leave behind and how students can adapt their tradecraft to minimize their footprint. Students learn to use some of the most well-known offensive tools from the co-creators and developers of Mythic, Merlin, Rubeus, GhostPack, HardHatC2, SharpSCCM, and BloodHound.

Carousel1-RedTeam@2x_7a3979

Here’s what we’ll cover:

  • Red Team Operations Overview
  • Attack Infrastructure
  • Windows Internals
  • Payloads
  • Host Situational Awareness
  • Local Privilege Escalation
Red-Day1@2x_f9ebd2

Here’s what we’ll cover:

  • Detection Considerations
  • Host Persistence
  • Credential Abuse
  • Introduction to AD
  • BloodHound — Visualizing Attack Paths
  • Lateral Movement
Red-Day2@2x_a5de2a

Here’s what we’ll cover:

  • SQL Abuse
  • Data Hunting
  • Kerberos Fundamentals and Abuse
  • Active Directory Domain Trusts
Red-Day3@2x_9f56a8

Here’s what we’ll cover:

  • Domain Persistence
  • DPAPI
  • Cookie Abuse
  • Lab Debrief
  • Defensive Debrief*
Red-Day4@2x_8c2125

Overview

Dig into Red Team Operations

This intense course immerses students in a single simulated enterprise environment, with multiple networks, hardened endpoints, modern defenses, and active network defenders responding to red team activities. The course focuses on in-depth attacker tradecraft post-initial access, breaking out of the beachhead, establishing resilient command and control (C2) infrastructure, gaining situational awareness through OPSEC-aware host and network enumerations, performing advanced lateral movement and sophisticated Active Directory escalation, establishing persistence (userland, elevated, and domain flavors), and executing advanced Kerberos attacks, data mining, and exfiltration.

A focus is on “offense-in-depth”—the ability to rapidly adapt to defensive mitigations and responses with various offensive tactics and techniques. To drive this concept home, students will go against live incident responders who actively hunt for and block malicious activity in the environment. The responders provide real-time feedback to students demonstrating what artifacts attackers can leave behind and how students can adapt their tradecraft to minimize their footprint. Students learn to use some of the most well-known offensive tools from the co-creators and developers of Mythic, Merlin, Rubeus, GhostPack, HardHatC2, SharpSCCM, and BloodHound.

Carousel1-RedTeam@2x_7a3979

Day 1

Here’s what we’ll cover:

  • Red Team Operations Overview
  • Attack Infrastructure
  • Windows Internals
  • Payloads
  • Host Situational Awareness
  • Local Privilege Escalation
Red-Day1@2x_f9ebd2

Day 2

Here’s what we’ll cover:

  • Detection Considerations
  • Host Persistence
  • Credential Abuse
  • Introduction to AD
  • BloodHound — Visualizing Attack Paths
  • Lateral Movement
Red-Day2@2x_a5de2a

Day 3

Here’s what we’ll cover:

  • SQL Abuse
  • Data Hunting
  • Kerberos Fundamentals and Abuse
  • Active Directory Domain Trusts
Red-Day3@2x_9f56a8

Day 4

Here’s what we’ll cover:

  • Domain Persistence
  • DPAPI
  • Cookie Abuse
  • Lab Debrief
  • Defensive Debrief*
Red-Day4@2x_8c2125

Before you attend

Who should attend
  • Red team operators seeking to solidify their understanding of red teaming concepts and tradecraft and become “enlightened actors” who understand the impact of each action performed and make risk-based decisions.
  • Penetration testers seeking to utilize their offensive security skills to transition to covert red team operator roles.
  • Blue teamers and general security practitioners seeking to gain an insight into adversary tactics and the offensive side.
Prerequisites

Participants should be comfortable with penetration testing concepts and tools, Active Directory, and attacking Microsoft Windows environments.

What to bring

Participants of Red Team Operations must provide their own computer with a modern web browser installed to access training materials and complete the course’s labs. The SpecterOps training platform URL (https://specterops.training) must be accessible from the participant’s computer throughout the duration of the course.

There are no local virtual machines or special software required to fully participate in the Red Team training course or labs.

What you receive

During the course, participants receive access to a hands-on training range where they complete labs and work through course objectives.

Upon completion of the course, participants receive:

  • A copy of the course slides
  • A certificate of completion
  • A course challenge coin
  • A digital badge

Accepting your digital badge confirms your SpecterOps Training alumni status, which conveys exclusive discounts to future SpecterOps hosted training.

MORE WAYS TO TRAIN

Private and custom training

SpecterOps courses, delivered exclusively for your team. Need something beyond our current offerings? We develop custom curriculum, labs, and CTFs designed around your team’s specific goals and threat landscape. Our training is taught by the same front-line practitioners who conduct our engagements, bringing real-world experience into every course.

5050-1-AttackPaths_b167b9

 DEEPEN YOUR TRADECRAFT

Explore additional training courses

TrainingPage-ActiveDirectory_9494c3

Adversary Perspectives: Active Directory

Learn Active Directory’s architecture and security implications, and identify misconfigurations before an attacker does.

Learn More
TrainingPage-Azure

Adversary Perspectives: Azure

Discover how adversaries view, target, and exploit Azure and Entra ID environments.

Learn More
TrainingPage-OffensiveTradecraft

Adversary Tactics: Identity-Driven Offensive Tradecraft

What turns a path into an attack path? Learn how to find and abuse them.

Learn More
TrainingPage-Detection

Adversary Tactics: Detection

Stop chasing indicators. Build detections that focus on how attackers operate.

Learn More
TrainingPage-TradecraftAnalysis

Adversary Tactics: Tradecraft Analysis

Deconstruct how attack techniques really work, then build detections or learn how to evade them.

Learn More

SpecterOps Tradecraft Academy

Hands-on offensive and defensive security training built by SpecterOps practitioners, available on demand and designed to be completed at your own pace.

TradeCraftAcademyLogo@2x_3266ac