Antisyphon Courses
(19 courses)Explore all courses, labs, and learning resources from Antisyphon.
Antisyphon: Active Defense & Cyber Deception w/ John Strand
Active Defenses have been capturing a large amount of attention in the media lately. There are those who thirst for vengeance and want to directly attack the attackers. There are those who believe that any sort of active response directed at an attacker is wrong. We believe the answer is somewhere in between. In this class, you will learn how to force an attacker to take more moves to attack your network. These moves may increase your ability to detect them. You will learn how to gain better attribution as to who is attacking you and why. You will also find out how to get access to a bad guy’s system. And most importantly, you will find out how to do the above legally. Active Defense & Cyber Deception w/ John Strand
Antisyphon: Enterprise Forensics and Response
The Enterprise Forensics and Response course is designed to provide students with both an investigative construct and techniques that allow them to scale incident response activities in an enterprise environment. The focus of the lecture portion of the course work is understanding the incident investigation process, objective oriented analysis and response, intrusion analysis and an exploration of attacker Tactics and Techniques. The technical portion of the course will focus on how to conduct incident investigations at enterprise scale using the remote evidence acquisition and analysis tool Velociraptor along with other free and open-source tools. The focus of the technical portion will be on extracting usable Indicators of Compromise (IOCs) related to specific MITRE ATT&CK tactics. For example, students will be instructed on extracting and analyzing evidence related to the Execution TA0002 of malicious code or LOLBAS. From here, they will be tasked with addressing containment and eradication measures. This course will combine technical elements along with lecture that provides students with both an investigative construct and techniques that allows them to analyze evidence and provide stakeholders with data necessary to limit the damage of modern cyber-attacks. Antisyphon: Enterprise Forensics and Response
Antisyphon: Enterprise Attacker Emulation and C2 Implant Development w/ Joff Thyer
As penetration testers, we all have a need to establish command and control channels in our customer environments. This can be done under the guise of an “assumed compromise” context or in a more adversarial Red Team context. The age of endpoint detection and response (EDR) solutions and application whitelisting has created significant barriers to commodity/well known malware deployment for adversarial exercises. This class focuses on the demonstration of an Open Command Channel framework called “OpenC2RAT”, and then developing, enhancing, and deploying the “OpenC2RAT” command channel software into a target environment. Students will learn about the internal details of a command channel architecture and methods to deploy in an application-whitelisted context. The class will introduce students to blocks of code written in C#, GoLang, and Python to achieve these goals. In addition, the class will introduce some ideas to deploy existing shellcode such as Cobalt Strike Beacon or Meterpreter within a programmed wrapper to enhance success in the age of modern endpoint defense. Many of the techniques introduced in this class can be used to evade modern defensive technologies. Antisyphon: Enterprise Attacker Emulation and C2 Implant Development w/ Joff Thyer
Antisyphon: Defending the Enterprise w/ Kent Ickler and Jordan Drysdale
For the luckiest of enterprises, the awareness of an insecure environment is proven not in public discord after a breach but instead by effective security penetration tests. Time and time again Jordan and Kent have witnessed organizations struggle with network management, Active Directory, organizational change, and an increasingly experienced adversary. For new and legacy enterprises alike, Defending the Enterprise explores the configuration practices and opportunities that secure networks, Windows, and Active Directory from the most common and effective adversarial techniques. Have the confidence that your organization is prepared for tomorrow’s security threats by learning how to defend against network poisoning, credential abuse, exploitable vulnerabilities, lateral movement, and privilege escalation. Learn cost-effective mitigations to contemporary adversarial attacks. The best defended networks are those which have matured from countless penetration tests and security incidents. Learn from Kent and Jordan, two seasoned offensive and defensive security experts, to shortcut your organization’s security posture into a well-fortified fortress. Antisyphon: Defending the Enterprise w/ Kent Ickler and Jordan Drysdale
Antisyphon: Advanced Red Team Operations
This is an advanced course that focuses on setting up secure and resilient C2 infrastructure using Azure/AWS, creating custom Cobalt Strike profiles, hunting for Active Directory Certificate Services misconfigurations in mature enterprise environments. Learn current post-exploitation techniques that White Knight Labs (WKL) has used during real-life engagements to dump credentials, move laterally, escalate to Domain Admin, and capture the client’s crown jewels. We will cover EDR bypass briefly, but AV/EDR bypass will be assumed knowledge for this course. Although this course is designed to be a deep dive into hunting for ADCS misconfigurations and setting up C2 infrastructure, an apex attacker must also know their own indicators of compromise (IOCs) they’re creating and the artifacts they’re leaving behind. On the second day, students will be led through a real-life red team operation. Syllabus Day 1: Red Team Fundamentals Cobalt Strike/Guacamole walkthrough Terraform for infrastructure automation Redirectors and CDNs Custom malleable C2 profile Protecting your C2 server (mod rewrite and proxy pass) Touch and go AV/EDR Bypasses Day 2: Red Team Operation Attack Paths Advanced payload creation Windows lateral movement SOCKS proxies Service controller WMI COM/DCOM Abusing AD misconfigurations via C2 channels (ADCS) Advanced credential dumping techniques SQL misconfigurations for lateral movement and code execution Antisyphon: Advanced Red Team Operations
Antisyphon – SOC Core Skills
This 16-hour information security training course will cover the core security skills all Security Operation Center (SOC) analysts need to have. These are the skills that all Black Hills Information Security (BHIS) SOC team members need to have. Syllabus Core networking skills Live Windows Forensics Live Linux Forensics Memory Forensics Active Directory Analysis Network Threat Hunting Basics of Vulnerability Management The Incident Response Process SOC Core Skills
Getting Started in Security With BHIS and MITRE Att&CK
The Getting Started in Security with BHIS and MITER ATT&CK course from Wild West Hackin Fest is designed for those who want to enter the world of cyber security. This course does not require prerequisites and its purpose is to understand and learn how to defend against attacks that happen on a daily basis by hackers. In this course, you will learn about 11 of the most important attacks that every organization must protect itself against. The instructor of this course is John Strand. Getting Started in Security With BHIS and MITRE Att&CK






