TRAINING COURSES

Adversary Tactics: Tradecraft Analysis

iAPM-HeroImage@2x-3_402c80
APM-MainImage-ATTA@2x

WHAT TO EXPECT

Deconstruct attack techniques, then build detections or learn to evade them

Your organization has invested in leading detection and response products. This course helps you get the most out of them — building the confidence and methodology to detect sophisticated attacks.

This course teaches the importance of understanding attack techniques and telemetry availability to develop robust detection analytics and data-driven evasion decisions. Focusing on Windows components and attacker tactics, techniques, and procedures (TTPs), participants dive deep into how software abstracts underlying capabilities and how attackers interact with deeper layers to bypass detection. Whether you’re a detection engineer validating coverage or a red teamer understanding evasion, this tradecraft analysis methodology provides the foundation for both disciplines.

key takeaways

Course summary

Knowledgeable detection engineers and red team operators understand that while there are many effective security products, all have gaps that sophisticated adversaries can exploit.

This course provides a tradecraft analysis methodology to deconstruct how Windows attack techniques work underneath the hood, identify telemetry sources and detection choke points, and develop robust detection coverage and informed evasion strategies. Participants learn to analyze attack paths in depth to understand not just what techniques do, but how they work at multiple abstraction layers and what artifacts they generate. Whether building detections or planning red team operations, this analytical approach ensures informed, data-driven decisions about coverage and evasion.

 

Participants will learn

Icons-Connect

How various Windows component attack TTPs work and what detection telemetry they generate

Icons-Control

How to develop robust detection analytics and data-driven evasion decisions using a practical approach and methodology

Cards-Learn3@2x

How to analyze which tools trip detection logic, and a better understanding of how to utilize and select techniques that evade detection

A CLOSER LOOK AT THE COURSE

Adversary Tactics: Tradecraft Analysis

Knowledgeable detection engineers and red team operators know that while there are many effective products, all have gaps that can be exploited by sophisticated adversaries. A mature security program must continuously test and enhance product detection configurations to maintain effective response capabilities. Unfortunately, organizations often run into limitations, primarily due to insufficient understanding of: the attack technique itself; telemetry used for each detection; and effectiveness of the detection. The result leads to blind spots within detection and response capabilities, ineffective detection strategies, and a false sense of security in the organization’s ability to respond to advanced threat actors.

Dig into Tradecraft Analysis

In Adversary Tactics: Tradecraft Analysis, we’ll present and apply a general tradecraft analysis methodology for offensive TTPs, focused on Windows components. The course discusses Windows attack techniques and deconstructs how they work underneath the hood. For various techniques, participants will identify the layers of telemetry sources and potential detection choke points. Finally, the course culminates with students creating their own technique evasion and detection strategies. Participants will be able to use the knowledge gained to leverage telemetry to create robust detection coverage across their organization and assess coverage efficacy.

Whether you are a red team operator or detection engineer, you will gain a comprehensive understanding of several attack chains. Red team operators learn how to analyze their own tools, which techniques to select to evade detection, and how to better describe to defenders why their evasion is successful. Detection engineers will understand how to craft strategies for robust detections and detect families of attacks.

Carousel1-TradecraftAnalysis@2x_ef703d

Understanding Abstraction

  • Attack and Detection Strategies
  • Naive PSExec Overview
  • Tradecraft Analysis Process
  • Capability Identification
  • Capability Deconstruction
  • Introduction to Decompilers
ATTA-Day1@2x_e9762f

Operationalizing Detection and Evasion Concepts

  • Understanding Inter-Process Communication
  • RPC Deep Dive
  • Introduction to NtObjectManager
  • Utilizing Decompilers for Windows Internals Analysis
  • Understanding Shared and Divergent Behavior of Offensive Tools
ATTA-Day2@2x_e72e37

Understanding Telemetry

  • Securable Objects
  • Identifying Choke Points
  • Telemetry Source Identification
  • How EDRs Work
  • Organic Logging
  • SACLs
  • Function Hooking
  • Kernel Callback Functions
  • ETW
ATTA-Day3@2x_aaab63

Capstone

  • Defensive Capstone
  • Offensive Capstone
ATTA-Day4@2x_0452f6

Overview

Dig into Tradecraft Analysis

In Adversary Tactics: Tradecraft Analysis, we’ll present and apply a general tradecraft analysis methodology for offensive TTPs, focused on Windows components. The course discusses Windows attack techniques and deconstructs how they work underneath the hood. For various techniques, participants will identify the layers of telemetry sources and potential detection choke points. Finally, the course culminates with students creating their own technique evasion and detection strategies. Participants will be able to use the knowledge gained to leverage telemetry to create robust detection coverage across their organization and assess coverage efficacy.

Whether you are a red team operator or detection engineer, you will gain a comprehensive understanding of several attack chains. Red team operators learn how to analyze their own tools, which techniques to select to evade detection, and how to better describe to defenders why their evasion is successful. Detection engineers will understand how to craft strategies for robust detections and detect families of attacks.

Carousel1-TradecraftAnalysis@2x_ef703d

Day 1

Understanding Abstraction

  • Attack and Detection Strategies
  • Naive PSExec Overview
  • Tradecraft Analysis Process
  • Capability Identification
  • Capability Deconstruction
  • Introduction to Decompilers
ATTA-Day1@2x_e9762f

Day 2

Operationalizing Detection and Evasion Concepts

  • Understanding Inter-Process Communication
  • RPC Deep Dive
  • Introduction to NtObjectManager
  • Utilizing Decompilers for Windows Internals Analysis
  • Understanding Shared and Divergent Behavior of Offensive Tools
ATTA-Day2@2x_e72e37

Day 3

Understanding Telemetry

  • Securable Objects
  • Identifying Choke Points
  • Telemetry Source Identification
  • How EDRs Work
  • Organic Logging
  • SACLs
  • Function Hooking
  • Kernel Callback Functions
  • ETW
ATTA-Day3@2x_aaab63

Day 4

Capstone

  • Defensive Capstone
  • Offensive Capstone
ATTA-Day4@2x_0452f6

Before you attend

Who should attend

The Tradecraft Analysis course is intended for expert blue teamers, detection engineers, and red team operators. Participants should be familiar with detection engineering and/or red team operations, and be generally comfortable with Windows internals, adversarial attack technique analysis, offensive security tools and techniques.

Prerequisites

This course is intended for expert blue teamers, detection engineers, and red team operators. Participants should be familiar with detection engineering and/or red team operations, and be generally comfortable with Windows internals, attack technique analysis, offensive tools and techniques.

What to bring

Tradecraft Analysis participants will need a laptop with a modern web browser. All labs are completed through a training portal that contains a range with simulated enterprise networks under attack and defensive workstations from which participants will operate. There are no local virtual machines or special software required to fully participate in the course or labs.

What you receive

During the course, participants receive access to a hands-on training range where they complete labs and work through course objectives.

Upon completion of the course, participants receive:

  • A copy of the course slides
  • A certificate of completion
  • A course challenge coin
  • A digital badge

Accepting your digital badge confirms your SpecterOps Training alumni status, which conveys exclusive discounts to future SpecterOps hosted training.

MORE WAYS TO TRAIN

Private and custom training

SpecterOps courses, delivered exclusively for your team. Need something beyond our current offerings? We develop custom curriculum, labs, and CTFs designed around your team’s specific goals and threat landscape. Our training is taught by the same front-line practitioners who conduct our engagements, bringing real-world experience into every course.

5050-1-AttackPaths_b167b9

 DEEPEN YOUR TRADECRAFT

Explore additional training courses

TrainingPage-ActiveDirectory_9494c3

Adversary Perspectives: Active Directory

Learn Active Directory’s architecture and security implications, and identify misconfigurations before an attacker does.

Learn More
TrainingPage-Azure

Adversary Perspectives: Azure

Discover how adversaries view, target, and exploit Azure and Entra ID environments.

Learn More
TrainingPage-RedTeam

Adversary Tactics: Red Team Operations

Go beyond Domain Admin and sharpen your offense-in-depth skills.

Learn More
TrainingPage-OffensiveTradecraft

Adversary Tactics: Identity-Driven Offensive Tradecraft

What turns a path into an attack path? Learn how to find and abuse them.

Learn More
TrainingPage-Detection

Adversary Tactics: Detection

Stop chasing indicators. Build detections that focus on how attackers operate.

Learn More

SpecterOps Tradecraft Academy

Hands-on offensive and defensive security training built by SpecterOps practitioners, available on demand and designed to be completed at your own pace.

TradeCraftAcademyLogo@2x_3266ac