TRAINING COURSES
Adversary Tactics: Tradecraft Analysis
WHAT TO EXPECT
Deconstruct attack techniques, then build detections or learn to evade them
Your organization has invested in leading detection and response products. This course helps you get the most out of them — building the confidence and methodology to detect sophisticated attacks.
This course teaches the importance of understanding attack techniques and telemetry availability to develop robust detection analytics and data-driven evasion decisions. Focusing on Windows components and attacker tactics, techniques, and procedures (TTPs), participants dive deep into how software abstracts underlying capabilities and how attackers interact with deeper layers to bypass detection. Whether you’re a detection engineer validating coverage or a red teamer understanding evasion, this tradecraft analysis methodology provides the foundation for both disciplines.
key takeaways
Course summary
Knowledgeable detection engineers and red team operators understand that while there are many effective security products, all have gaps that sophisticated adversaries can exploit.
This course provides a tradecraft analysis methodology to deconstruct how Windows attack techniques work underneath the hood, identify telemetry sources and detection choke points, and develop robust detection coverage and informed evasion strategies. Participants learn to analyze attack paths in depth to understand not just what techniques do, but how they work at multiple abstraction layers and what artifacts they generate. Whether building detections or planning red team operations, this analytical approach ensures informed, data-driven decisions about coverage and evasion.
Participants will learn
How various Windows component attack TTPs work and what detection telemetry they generate
How to develop robust detection analytics and data-driven evasion decisions using a practical approach and methodology
How to analyze which tools trip detection logic, and a better understanding of how to utilize and select techniques that evade detection
A CLOSER LOOK AT THE COURSE
Adversary Tactics: Tradecraft Analysis
Knowledgeable detection engineers and red team operators know that while there are many effective products, all have gaps that can be exploited by sophisticated adversaries. A mature security program must continuously test and enhance product detection configurations to maintain effective response capabilities. Unfortunately, organizations often run into limitations, primarily due to insufficient understanding of: the attack technique itself; telemetry used for each detection; and effectiveness of the detection. The result leads to blind spots within detection and response capabilities, ineffective detection strategies, and a false sense of security in the organization’s ability to respond to advanced threat actors.
Dig into Tradecraft Analysis
In Adversary Tactics: Tradecraft Analysis, we’ll present and apply a general tradecraft analysis methodology for offensive TTPs, focused on Windows components. The course discusses Windows attack techniques and deconstructs how they work underneath the hood. For various techniques, participants will identify the layers of telemetry sources and potential detection choke points. Finally, the course culminates with students creating their own technique evasion and detection strategies. Participants will be able to use the knowledge gained to leverage telemetry to create robust detection coverage across their organization and assess coverage efficacy.
Whether you are a red team operator or detection engineer, you will gain a comprehensive understanding of several attack chains. Red team operators learn how to analyze their own tools, which techniques to select to evade detection, and how to better describe to defenders why their evasion is successful. Detection engineers will understand how to craft strategies for robust detections and detect families of attacks.
Understanding Abstraction
- Attack and Detection Strategies
- Naive PSExec Overview
- Tradecraft Analysis Process
- Capability Identification
- Capability Deconstruction
- Introduction to Decompilers
Operationalizing Detection and Evasion Concepts
- Understanding Inter-Process Communication
- RPC Deep Dive
- Introduction to NtObjectManager
- Utilizing Decompilers for Windows Internals Analysis
- Understanding Shared and Divergent Behavior of Offensive Tools
Understanding Telemetry
- Securable Objects
- Identifying Choke Points
- Telemetry Source Identification
- How EDRs Work
- Organic Logging
- SACLs
- Function Hooking
- Kernel Callback Functions
- ETW
Capstone
- Defensive Capstone
- Offensive Capstone
Before you attend
Who should attend
The Tradecraft Analysis course is intended for expert blue teamers, detection engineers, and red team operators. Participants should be familiar with detection engineering and/or red team operations, and be generally comfortable with Windows internals, adversarial attack technique analysis, offensive security tools and techniques.
Prerequisites
This course is intended for expert blue teamers, detection engineers, and red team operators. Participants should be familiar with detection engineering and/or red team operations, and be generally comfortable with Windows internals, attack technique analysis, offensive tools and techniques.
What to bring
Tradecraft Analysis participants will need a laptop with a modern web browser. All labs are completed through a training portal that contains a range with simulated enterprise networks under attack and defensive workstations from which participants will operate. There are no local virtual machines or special software required to fully participate in the course or labs.
What you receive
During the course, participants receive access to a hands-on training range where they complete labs and work through course objectives.
Upon completion of the course, participants receive:
- A copy of the course slides
- A certificate of completion
- A course challenge coin
- A digital badge
Accepting your digital badge confirms your SpecterOps Training alumni status, which conveys exclusive discounts to future SpecterOps hosted training.
MORE WAYS TO TRAIN
Private and custom training
SpecterOps courses, delivered exclusively for your team. Need something beyond our current offerings? We develop custom curriculum, labs, and CTFs designed around your team’s specific goals and threat landscape. Our training is taught by the same front-line practitioners who conduct our engagements, bringing real-world experience into every course.
DEEPEN YOUR TRADECRAFT
Explore additional training courses
Adversary Perspectives: Active Directory
Learn Active Directory’s architecture and security implications, and identify misconfigurations before an attacker does.
Adversary Perspectives: Azure
Discover how adversaries view, target, and exploit Azure and Entra ID environments.
Adversary Tactics: Red Team Operations
Go beyond Domain Admin and sharpen your offense-in-depth skills.
Adversary Tactics: Identity-Driven Offensive Tradecraft
What turns a path into an attack path? Learn how to find and abuse them.
Adversary Tactics: Detection
Stop chasing indicators. Build detections that focus on how attackers operate.
SpecterOps Tradecraft Academy
Hands-on offensive and defensive security training built by SpecterOps practitioners, available on demand and designed to be completed at your own pace.