Courses Catalog
(62 courses)Explore our complete collection of technical courses, hands-on lab environments, and downloadable assets.
MGT514: Security Strategic Planning, Policy, and Leadership
MGT514 is a professional training course designed to help cybersecurity and IT leaders develop the skills and strategies necessary for managing and leading security programs. The course focuses on aligning security initiatives with business objectives, building a strong governance framework, and driving organizational resilience against modern threats.
FOR608: Enterprise-Class Incident Response & Threat Hunting
FOR608 is an advanced course designed for cybersecurity professionals responsible for detecting, responding to, and mitigating sophisticated cyber threats within enterprise environments. The course emphasizes proactive threat hunting, effective incident response strategies, and the use of cutting-edge tools and techniques to combat advanced persistent threats (APTs) and complex attacks.
SEC564: Red Team Operations and Threat Emulation
SEC564 course is designed to immerse students in the tactics, techniques, and procedures (TTPs) used by modern adversaries. By understanding the mindset and strategies of attackers, participants will learn how to conduct sophisticated penetration tests, simulate real-world attacks, and assess the security posture of organizations from a threat actor’s perspective. This course covers advanced topics in threat emulation, including attack simulations, red team engagements, and developing countermeasures to thwart malicious activities. By the end of the course, students will be adept at identifying vulnerabilities, exploiting weaknesses, and enhancing overall security resilience.
Antisyphon: Windows Post Exploitation w/ Kyle Avery
So you popped a shell, now what? Windows Post Exploitation focuses on four major components of any adversary simulation or red team exercise: enumeration, persistence, privilege escalation, and lateral movement. Each of these steps will be covered in detail with hands-on labs in a custom Active Directory environment. In addition, students will learn several modern techniques to minimize opportunities for detection. This course goes beyond teaching popular tactics, techniques, and procedures. Instead, students will learn how to covertly gather and leverage information about a target environment to achieve their objectives efficiently. A review of each post-ex capability will include discussion on the OPSEC implications and publicly documented detection recommendations. Open-source SIEM rules from Sigma and Elastic will be used as a starting point for avoiding alert generation. No technique is undetectable; the key is understanding an environment’s detection capabilities and choosing the best course of action. Antisyphon: Windows Post Exploitation w/ Kyle Avery
PEN-300: Advanced Evasion Techniques and Breaching Defenses
Evasion Techniques and Breaching Defenses (PEN-300) is an advanced penetration testing course. Learners who complete the course and pass the exam will earn the OffSec Experienced Pentester (OSEP) certification. This course builds on the knowledge and techniques taught in Penetration Testing with Kali Linux, teaching learners to perform advanced penetration tests against mature organizations with an established security function and focuses on bypassing security mechanisms that are designed to block attacks. The OSEP is one of three certifications making up the OSCE certification along with the OSWE for advanced web attacks and OSED for exploit development.
FOR585: Smartphone Forensic Analysis In-Depth
This course is designed to provide forensic professionals with specialized techniques to analyze and investigate smartphones thoroughly. With mobile devices playing a significant role in daily communications, they often become key evidence sources in criminal, civil, or corporate investigations.
SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking
This course is designed for seasoned penetration testers and cybersecurity professionals looking to elevate their skills in offensive security. It focuses on advanced exploitation techniques and complex attack vectors, enabling participants to uncover and exploit vulnerabilities in a wide range of systems and networks.
SEC588: Cloud Penetration Testing
This course provides an in-depth exploration of penetration testing techniques tailored to modern cloud environments. Participants will gain hands-on experience identifying vulnerabilities, exploiting weaknesses, and understanding the unique attack vectors that cloud infrastructures introduce. Covering leading platforms such as AWS, Azure, and Google Cloud, SEC588 emphasizes real-world scenarios, enabling students to assess and secure cloud systems effectively. With a focus on both offensive and defensive strategies, the course equips cybersecurity professionals with the tools to stay ahead in a rapidly evolving threat landscape.
SEC573: Automating Information Security with Python
This course empowers security professionals to leverage Python for automating complex information security tasks. SEC573 provides a hands-on approach to writing custom scripts for vulnerability scanning, data analysis, log parsing, and intrusion detection. Participants will learn to develop tools that streamline repetitive workflows, enhance threat hunting, and integrate seamlessly into existing security operations. With a focus on practical problem-solving, SEC573 equips attendees with the skills to create scalable, efficient, and adaptable solutions, ensuring organizations stay ahead in a fast-paced security landscape.
SEC560: Enterprise Penetration Testing
SEC560 focuses on advanced techniques for conducting thorough penetration tests in large-scale enterprise environments. Participants will learn to assess complex networks, web applications, and systems for vulnerabilities using real-world attack strategies. The course covers both external and internal penetration testing, emphasizing effective exploitation, post-exploitation, and lateral movement techniques. With a strong hands-on approach, students will gain experience in identifying, exploiting, and mitigating risks within enterprise infrastructures. SEC560 prepares professionals to tackle the growing security challenges faced by large organizations and helps them develop comprehensive strategies for improving overall cybersecurity resilience.
SEC587: Advanced Open-Source Intelligence (OSINT) Gathering and Analysis
SEC587 provides an in-depth exploration of advanced techniques for gathering and analyzing open-source intelligence (OSINT) in cybersecurity. The course teaches participants how to effectively leverage publicly available data—from social media and websites to government databases and deep web sources—to uncover potential security threats and vulnerabilities. Students will learn how to use OSINT tools for real-time threat intelligence, competitor analysis, and threat actor profiling. Emphasizing practical, hands-on exercises, SEC587 enhances the ability to conduct in-depth investigations, identify attack vectors, and anticipate cyber threats, all while adhering to legal and ethical standards.
SEC530: Defensible Security Architecture and Engineering: Implementing Zero Trust for the Hybrid Enterprise
SEC530 offers a comprehensive approach to designing and implementing a Zero Trust security model within hybrid enterprise environments. This course emphasizes the importance of security architecture in mitigating modern threats by assuming that every user, device, and application could be compromised. Participants will explore Zero Trust principles, including identity and access management, micro-segmentation, continuous monitoring, and least-privilege access. Through hands-on labs and case studies, students will learn to implement these concepts across hybrid infrastructures, ensuring robust defenses and minimizing the attack surface. SEC530 prepares security professionals to create and maintain resilient, adaptive security architectures aligned with the latest industry standards and best practices.











