Courses Catalog
(480 courses)Explore our complete collection of technical courses, hands-on lab environments, and downloadable assets.
Antisyphon: Enterprise Attacker Emulation and C2 Implant Development w/ Joff Thyer
As penetration testers, we all have a need to establish command and control channels in our customer environments. This can be done under the guise of an “assumed compromise” context or in a more adversarial Red Team context. The age of endpoint detection and response (EDR) solutions and application whitelisting has created significant barriers to commodity/well known malware deployment for adversarial exercises. This class focuses on the demonstration of an Open Command Channel framework called “OpenC2RAT”, and then developing, enhancing, and deploying the “OpenC2RAT” command channel software into a target environment. Students will learn about the internal details of a command channel architecture and methods to deploy in an application-whitelisted context. The class will introduce students to blocks of code written in C#, GoLang, and Python to achieve these goals. In addition, the class will introduce some ideas to deploy existing shellcode such as Cobalt Strike Beacon or Meterpreter within a programmed wrapper to enhance success in the age of modern endpoint defense. Many of the techniques introduced in this class can be used to evade modern defensive technologies. Antisyphon: Enterprise Attacker Emulation and C2 Implant Development w/ Joff Thyer
Antisyphon: Defending the Enterprise w/ Kent Ickler and Jordan Drysdale
For the luckiest of enterprises, the awareness of an insecure environment is proven not in public discord after a breach but instead by effective security penetration tests. Time and time again Jordan and Kent have witnessed organizations struggle with network management, Active Directory, organizational change, and an increasingly experienced adversary. For new and legacy enterprises alike, Defending the Enterprise explores the configuration practices and opportunities that secure networks, Windows, and Active Directory from the most common and effective adversarial techniques. Have the confidence that your organization is prepared for tomorrow’s security threats by learning how to defend against network poisoning, credential abuse, exploitable vulnerabilities, lateral movement, and privilege escalation. Learn cost-effective mitigations to contemporary adversarial attacks. The best defended networks are those which have matured from countless penetration tests and security incidents. Learn from Kent and Jordan, two seasoned offensive and defensive security experts, to shortcut your organization’s security posture into a well-fortified fortress. Antisyphon: Defending the Enterprise w/ Kent Ickler and Jordan Drysdale
Antisyphon: Advanced Red Team Operations
This is an advanced course that focuses on setting up secure and resilient C2 infrastructure using Azure/AWS, creating custom Cobalt Strike profiles, hunting for Active Directory Certificate Services misconfigurations in mature enterprise environments. Learn current post-exploitation techniques that White Knight Labs (WKL) has used during real-life engagements to dump credentials, move laterally, escalate to Domain Admin, and capture the client’s crown jewels. We will cover EDR bypass briefly, but AV/EDR bypass will be assumed knowledge for this course. Although this course is designed to be a deep dive into hunting for ADCS misconfigurations and setting up C2 infrastructure, an apex attacker must also know their own indicators of compromise (IOCs) they’re creating and the artifacts they’re leaving behind. On the second day, students will be led through a real-life red team operation. Syllabus Day 1: Red Team Fundamentals Cobalt Strike/Guacamole walkthrough Terraform for infrastructure automation Redirectors and CDNs Custom malleable C2 profile Protecting your C2 server (mod rewrite and proxy pass) Touch and go AV/EDR Bypasses Day 2: Red Team Operation Attack Paths Advanced payload creation Windows lateral movement SOCKS proxies Service controller WMI COM/DCOM Abusing AD misconfigurations via C2 channels (ADCS) Advanced credential dumping techniques SQL misconfigurations for lateral movement and code execution Antisyphon: Advanced Red Team Operations
Hackademy: Red Team Wi-Fi
Many publications exist documenting ways to attack Wi-Fi networks. Still, the gap between old methods that have become obsolete and the current state and outdated tools can be frustrating for someone who wants to learn or even update his knowledge in this field. This course aims to learn the modern ways of assessing the security of Wi-Fi networks and how to apply these attacks against organizations during a Red Team engagement. Indeed, during this course, we will be able to start from the very beginning by talking about old, current, and new attacks and opportunities to allow attendees to fulfill their pentest or Red Team engagements in the future based on our recent experiences. Syllabus Introduction Network introspection Attacks and risks Completion Hackademy: Red Team Wi-Fi
Complete Hardware Hacking Package
The topic of Hardware Hacking is one of the topics that is rarely addressed and mentioned in official courses, but nevertheless it is one of the most important techniques required for hackers who intend to carry out field and physical attacks. This package includes videos from conferences like DefCon on this topic, hands-on courses, lots of books, YouTube videos and blogs. In this course, you will learn a wide range of topics such as making (Rubber Ducky) BAD USB, FPGA attacks, security testing of switches and routers, Wifi jamming, direct attacks on Memory, attacks on Mouse, etc. This package includes more than 40 hours of educational videos and many books. To know the names of the courses and books in this package, you can watch the video of this article. Complete Hardware Hacking Package
Zero Point Security – C2 Development in C Sharp
Learn how to design, build and maintain your own C2 Framework codebase from scratch. Build a RESTful API-driven Team Server, and a .NET Framework Implant with a variety of post-exploitation capabilities. Design and build Unit Tests to automatically test your code and prevent regression bugs.
Zero Point Security – Red Team Ops
Red Team Ops is an online, self-study course that teaches the basic principles, tools and techniques synonymous with red teaming. Students will first cover the core concepts of adversary simulation, command & control, engagement planning and reporting. They will then go through each stage of the attack lifecycle – from initial compromise to full domain takeover, data hunting and exfiltration. Students will learn how common “OPSEC failures” can lead to detection by defenders, and how to carry out those attacks in a stealthier way. Finally, they will learn how to bypass defences such as Windows Defender, AMSI and AppLocker.
Antisyphon – SOC Core Skills
This 16-hour information security training course will cover the core security skills all Security Operation Center (SOC) analysts need to have. These are the skills that all Black Hills Information Security (BHIS) SOC team members need to have. Syllabus Core networking skills Live Windows Forensics Live Linux Forensics Memory Forensics Active Directory Analysis Network Threat Hunting Basics of Vulnerability Management The Incident Response Process SOC Core Skills
(BTL1) Blue Team Level 1
BTL1 is designed to train technical defenders who can defend networks and respond to real-world cyber incidents. The skills and tools you learn apply directly to security roles and are used by defenders worldwide.
Reversing Hero
Reversing Hero course is a very good course for people who want to learn reverse engineering from beginner to intermediate level. This course consists of 12 hours of video, the degree of difficulty of which increases step by step, and also in the Reversing Hero course, you have to try to solve the given exercises by yourself, and if you are completely stuck, you can watch the video of the solution to the exercise. Reversing Hero
Redteam Blueprint by Redteam Nation
The RedTeam Blueprint course from RedTeam Nation is a very special course for people who want to start Red Team, APT or penetration testing. This course also teaches the basic topics related to hacking and security in the operating system as well as the network, and is completely suitable for people who do not have any background.
Maltego Essentials
Maltego Essentials is the official video tutorial series that guides you through the basics of Maltego to help you kickstart your investigations. Watch these 10 bite-sized tutorials and quickly learn about the most important Maltego features now! Syllabuss 1. Introducing The Official Maltego Video Tutorial Series 2. Editions of Maltego 3. How to Install and Activate Maltego 4. Running Your First Transform 5. How to Navigate your Graph 6. Different Layouts and Views of a Maltego Graph 7. What You Should Know About Entities in an Investigation 8. Notes, Bookmarks & Attachments 9. What Are Collection Nodes 10. How to Import Data into Maltego Maltego Essentials Course











