Search Courses

Quickly search courses, categories, and downloadable labs

Courses Catalog

(585 courses)

Explore our complete collection of technical courses, hands-on lab environments, and downloadable assets.

Showing 445456 of 585 coursesPage 38 of 49

SEC467: Social Engineering for Security Professionals

SEC467 equips security professionals with the knowledge and skills to recognize, prevent, and respond to social engineering attacks. This course delves into the psychological tactics used by attackers to manipulate individuals into divulging confidential information or compromising security systems. Through real-world scenarios and practical exercises, participants will learn to identify phishing, pretexting, baiting, and tailgating attacks, and develop effective countermeasures. SEC467 also covers ethical considerations and legal implications, providing a comprehensive understanding of social engineering threats in both organizational and personal contexts, helping professionals safeguard against these subtle yet highly effective attack methods.

2 modules213 MB

SEC587: Advanced Open-Source Intelligence (OSINT) Gathering and Analysis

SEC587 provides an in-depth exploration of advanced techniques for gathering and analyzing open-source intelligence (OSINT) in cybersecurity. The course teaches participants how to effectively leverage publicly available data—from social media and websites to government databases and deep web sources—to uncover potential security threats and vulnerabilities. Students will learn how to use OSINT tools for real-time threat intelligence, competitor analysis, and threat actor profiling. Emphasizing practical, hands-on exercises, SEC587 enhances the ability to conduct in-depth investigations, identify attack vectors, and anticipate cyber threats, all while adhering to legal and ethical standards.

6 modules10.6 GB
PDFZIP

SEC554: Blockchain and Smart Contract Security

SEC554 explores the rapidly evolving world of blockchain technology and its security implications, focusing on securing decentralized applications (dApps) and smart contracts. Participants will gain an understanding of blockchain architectures, consensus mechanisms, and cryptographic principles, along with the vulnerabilities that can exist within blockchain networks and smart contracts. Through practical labs, students will learn to identify and mitigate risks such as reentrancy attacks, transaction malleability, and gas limit vulnerabilities. SEC554 prepares professionals to secure blockchain ecosystems, ensuring the integrity of decentralized applications and protecting against emerging threats in blockchain-based environments.

5 modules10.3 GB

SEC530: Defensible Security Architecture and Engineering: Implementing Zero Trust for the Hybrid Enterprise

SEC530 offers a comprehensive approach to designing and implementing a Zero Trust security model within hybrid enterprise environments. This course emphasizes the importance of security architecture in mitigating modern threats by assuming that every user, device, and application could be compromised. Participants will explore Zero Trust principles, including identity and access management, micro-segmentation, continuous monitoring, and least-privilege access. Through hands-on labs and case studies, students will learn to implement these concepts across hybrid infrastructures, ensuring robust defenses and minimizing the attack surface. SEC530 prepares security professionals to create and maintain resilient, adaptive security architectures aligned with the latest industry standards and best practices.

6 modules47 GB
ZIPPDFISO

SEC510: Cloud Security Controls and Mitigations

SEC510 provides a deep dive into securing public cloud infrastructures, focusing on the top three platforms: Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). The course covers key security challenges unique to the cloud, such as identity and access management (IAM), data protection, network security, and compliance across these environments. Participants will learn to assess and mitigate risks, implement best practices, and leverage native cloud security tools for threat detection and incident response. Through hands-on exercises and real-world case studies, SEC510 equips security professionals with the skills to protect and secure critical cloud-based resources in multi-cloud and hybrid cloud environments.

5 modules14.1 GB
PDFZIPZ01+2

SEC505: Securing Windows and PowerShell Automation

SEC505 teaches security professionals how to secure Windows environments and automate security tasks using PowerShell while maintaining robust protection against internal and external threats. The course explores techniques for hardening Windows systems, securing PowerShell scripts, and detecting malicious automation. Participants will gain practical experience in securing automation workflows, managing administrative privileges, and mitigating common attack vectors like PowerShell-based exploits. With hands-on labs and real-world examples, SEC505 enables attendees to effectively secure Windows environments, automate incident response, and safeguard against advanced threats that target Windows systems and PowerShell automation.

6 modules4.7 GB

SEC501: Advanced Security Essentials – Enterprise Defender

SEC501 is designed for experienced security professionals who protect enterprise environments from advanced threats. This course provides in-depth training on defending against sophisticated attacks using modern security tools and techniques. Participants will explore topics such as advanced intrusion detection, threat hunting, malware analysis, and effective use of security information and event management (SIEM) systems. The curriculum emphasizes real-world scenarios, including defending against ransomware, lateral movement, and insider threats. Through hands-on labs and exercises, SEC501 equips defenders with the expertise to strengthen an organization’s security posture, respond to incidents effectively, and build a resilient enterprise defense strategy.

6 modules8.4 GB
ZIPISO

SEC488: Cloud Security Essentials

SEC488 provides foundational knowledge for securing cloud environments across various platforms, including AWS, Azure, and Google Cloud. This course is designed for security professionals seeking to understand cloud-specific risks, security controls, and compliance requirements. Participants will explore core topics such as identity and access management (IAM), secure configuration, data protection, and monitoring in cloud-native environments. With hands-on labs and practical exercises, students will gain the skills needed to identify vulnerabilities, implement security best practices, and safeguard cloud infrastructure. SEC488 is the ideal starting point for building a strong cloud security strategy and ensuring a secure adoption of cloud technologies.

6 modules3 GB

SEC575: iOS and Android Application Security Analysis and Penetration Testing

SEC575 provides a comprehensive approach to identifying, analyzing, and exploiting vulnerabilities in mobile applications on iOS and Android platforms. This course equips security professionals with the skills to perform advanced penetration testing and reverse engineering of mobile apps. Topics include secure coding practices, mobile app architecture, API security, and common vulnerabilities such as insecure data storage, improper authentication, and cryptographic flaws. Through hands-on labs and real-world scenarios, participants will learn to evaluate the security of mobile applications, uncover weaknesses, and provide actionable recommendations for remediation. SEC575 prepares attendees to tackle the unique challenges of securing mobile ecosystems effectively.

6 modules4.6 GB

Antisyphon: Security Leadership and Management w/ Chris Brenton

“Security” is arguably one of the most challenging disciplines to move from being an individual contributor (IC) to being a manager. While security ICs can perform most tasks in isolation, a manager needs to regularly interact with people both inside and outside of the team. Further, “security” has its own language which can be completely foreign to people outside of the discipline. How do you take security concerns and convert them into a language that senior leaders and “C” levels can understand? Honing these skills will be the primary objective of this course. In this course, we will cover all of the steps needed to stand up and lead a security team within an organization. We start with a clean slate so that every aspect gets covered. If you are in an environment that already has a security team, this can help fill in the gaps. This course will have a heavy focus on how to integrate the security team with the rest of the business units. We’ll look at strategies for increasing funding, as well as converting “security risks” into “business risks” so they are better understood by the organization’s leadership. The course includes a lot of collateral like a full set of pre-written security policies. The goal is to help you build an effective security team in as little time as possible. Antisyphon: Security Leadership and Management w/ Chris Brenton

Overview6.6 GB

Antisyphon: Security Defense and Detection TTX w/ Amanda Berlin and Jeremy Mio

Security Defense and Detection TTX is a comprehensive four-day tabletop exercise that involves the introduction to completion of security TTXs (tabletop exercises), IR playbooks, and after-action reports. The exercises are paired with video and lab demonstrations that reinforce their purpose. The training as a whole is compatible with the world’s most popular RPG rules. The preparation phase will walk students through the creation of specific IR playbooks that can be utilized in any environment as well as during later parts of the class. The next phase introduces the gamification of the TTXs. The students split up into separate “corporations” with assigned verticals, hit points, armor class, budgets, strengths, and weaknesses. Selection of departments and skills allow the players to further their modifiers. Throughout the exercise, each company will take turns rolling their way through decisions such as large purchases, attack severity, defense capability, and incident response decisions. Antisyphon: Security Defense and Detection TTX w/ Amanda Berlin and Jeremy Mio

Overview2.8 GB

Antisyphon: Introduction to PCI (PCI 101)

This will be a high level exploration of the Payment Card Industry Security Standards Council. Students will receive a strong understanding of the organization’s history, structure, the standards they maintain, qualified professional certifications, and the lists of validated solutions. This course is a great starting off point for IT or security professionals who reference “PCI” but don’t fully understand everything that entails. Antisyphon: Introduction to PCI (PCI 101)

Overview697 MB