TRAINING COURSES
Adversary Tactics: Red Team Operations
WHAT TO EXPECT
Go beyond Domain Admin and sharpen your offense-in-depth skills
Leveraging experience from hundreds of adversary simulation exercises, we built this course to teach effective red team operations. Most organizations have adopted an “assume breach” mentality, understanding that sophisticated adversaries will breach their defenses.
The best way to test enterprise security operations is through red team exercises that leverage the same tactics, techniques, and procedures (TTPs) as real attackers. Students learn offensive tradecraft post-initial access, from resilient command and control to advanced Active Directory exploitation, by operating against live incident responders in simulated enterprise environments. Real-time defender feedback reveals what artifacts attackers leave behind and how to minimize detection footprints.
key takeaways
Course summary
Upgrade your red team tradecraft with tactics, techniques, and procedures (TTPs) commonly used by attackers in real-world breaches.
This course teaches students how to design resilient command and control infrastructure and covertly operate in target networks to simulate advanced adversaries. Students learn to apply data-driven approaches to tradecraft decisions, execute advanced Active Directory attacks, perform sophisticated post-exploitation actions beyond “Domain Admin,” and practice “offense-in-depth” by adapting techniques in response to defenders. Participants will use the skillsets taught in this course to go up against live defenders in an elaborate lab environment mimicking an enterprise network, learning to adapt and overcome active response operations through collaborative feedback.
Participants will learn
How to plan red team engagements and design effective attack infrastructure and payloads
How to apply a data-driven approach to making educated, risk-based tradecraft decisions that reduce detection likelihood
How to identify and traverse attack paths in Active Directory and Windows environments
A CLOSER LOOK AT THE COURSE
Adversary Tactics: Red Team Operations
To avoid becoming the next breach headline, organizations are testing their defenses by simulating the same sophisticated adversaries targeting them in the wild. Organizations with an “assume breach” mentality understand that it’s not a matter of if these adversaries compromise them but when. Red team exercises using real attacker tactics, techniques, and procedures (TTPs) provide the most effective validation. If you want to learn the tradecraft of adversary simulation operations in enterprise environments, sharpen your offensive technical skillset, and understand how to detect modern advanced threat actor tradecraft, this course is for you.
Dig into Red Team Operations
This intense course immerses students in a single simulated enterprise environment, with multiple networks, hardened endpoints, modern defenses, and active network defenders responding to red team activities. The course focuses on in-depth attacker tradecraft post-initial access, breaking out of the beachhead, establishing resilient command and control (C2) infrastructure, gaining situational awareness through OPSEC-aware host and network enumerations, performing advanced lateral movement and sophisticated Active Directory escalation, establishing persistence (userland, elevated, and domain flavors), and executing advanced Kerberos attacks, data mining, and exfiltration.
A focus is on “offense-in-depth”—the ability to rapidly adapt to defensive mitigations and responses with various offensive tactics and techniques. To drive this concept home, students will go against live incident responders who actively hunt for and block malicious activity in the environment. The responders provide real-time feedback to students demonstrating what artifacts attackers can leave behind and how students can adapt their tradecraft to minimize their footprint. Students learn to use some of the most well-known offensive tools from the co-creators and developers of Mythic, Merlin, Rubeus, GhostPack, HardHatC2, SharpSCCM, and BloodHound.
Here’s what we’ll cover:
- Red Team Operations Overview
- Attack Infrastructure
- Windows Internals
- Payloads
- Host Situational Awareness
- Local Privilege Escalation
Here’s what we’ll cover:
- Detection Considerations
- Host Persistence
- Credential Abuse
- Introduction to AD
- BloodHound — Visualizing Attack Paths
- Lateral Movement
Here’s what we’ll cover:
- SQL Abuse
- Data Hunting
- Kerberos Fundamentals and Abuse
- Active Directory Domain Trusts
Here’s what we’ll cover:
- Domain Persistence
- DPAPI
- Cookie Abuse
- Lab Debrief
- Defensive Debrief*
Before you attend
Who should attend
- Red team operators seeking to solidify their understanding of red teaming concepts and tradecraft and become “enlightened actors” who understand the impact of each action performed and make risk-based decisions.
- Penetration testers seeking to utilize their offensive security skills to transition to covert red team operator roles.
- Blue teamers and general security practitioners seeking to gain an insight into adversary tactics and the offensive side.
Prerequisites
Participants should be comfortable with penetration testing concepts and tools, Active Directory, and attacking Microsoft Windows environments.
What to bring
Participants of Red Team Operations must provide their own computer with a modern web browser installed to access training materials and complete the course’s labs. The SpecterOps training platform URL (https://specterops.training) must be accessible from the participant’s computer throughout the duration of the course.
There are no local virtual machines or special software required to fully participate in the Red Team training course or labs.
What you receive
During the course, participants receive access to a hands-on training range where they complete labs and work through course objectives.
Upon completion of the course, participants receive:
- A copy of the course slides
- A certificate of completion
- A course challenge coin
- A digital badge
Accepting your digital badge confirms your SpecterOps Training alumni status, which conveys exclusive discounts to future SpecterOps hosted training.
MORE WAYS TO TRAIN
Private and custom training
SpecterOps courses, delivered exclusively for your team. Need something beyond our current offerings? We develop custom curriculum, labs, and CTFs designed around your team’s specific goals and threat landscape. Our training is taught by the same front-line practitioners who conduct our engagements, bringing real-world experience into every course.
DEEPEN YOUR TRADECRAFT
Explore additional training courses
Adversary Perspectives: Active Directory
Learn Active Directory’s architecture and security implications, and identify misconfigurations before an attacker does.
Adversary Perspectives: Azure
Discover how adversaries view, target, and exploit Azure and Entra ID environments.
Adversary Tactics: Identity-Driven Offensive Tradecraft
What turns a path into an attack path? Learn how to find and abuse them.
Adversary Tactics: Detection
Stop chasing indicators. Build detections that focus on how attackers operate.
Adversary Tactics: Tradecraft Analysis
Deconstruct how attack techniques really work, then build detections or learn how to evade them.
SpecterOps Tradecraft Academy
Hands-on offensive and defensive security training built by SpecterOps practitioners, available on demand and designed to be completed at your own pace.