Search Courses

Quickly search courses, categories, and downloadable labs

Courses Catalog

(585 courses)

Explore our complete collection of technical courses, hands-on lab environments, and downloadable assets.

Showing 457468 of 585 coursesPage 39 of 49

Antisyphon: Offensive Development w/ Greg Hatcher & John Stigerwalt

In the Intro to Offensive Tooling class, you will learn about many of the tools used by attackers to identify vulnerabilities and exploit them. This hands-on course covers a variety of offensive tools, such as Nmap, Recon-ng, Metasploit, Proxychains, Responder, and many more. Through a series of practical labs, you will gain experience in using these tools to assess the security of systems and networks. In addition to learning how to use these tools effectively, you will also explore the ethical considerations surrounding offensive tooling, how to responsibly use these tools to protect sensitive information, and prevent cyber attacks. By the end of this course, you will have a strong foundation in offensive tooling and be well-equipped to apply your knowledge to a wide range of security challenges. Antisyphon: Offensive Development w/ Greg Hatcher & John Stigerwalt

Overview5 GB

Antisyphon: Linux Forensics w/ Hal Pomeranz

Linux is everywhere– running in the cloud, on cell phones, and in embedded devices that make up the “Internet of Things”. Often neglected by their owners, vulnerable Linux systems are low-hanging fruit for attackers wishing to create powerful botnets or mine cryptocurrencies. Ransomware type attacks may target Linux-based database systems and other important infrastructure. As attacks against Linux become more and more common, there is an increasing demand for skilled Linux investigators. But even experienced forensics professionals may lack sufficient background to properly conduct Linux investigations. Linux is its own particular religion and requires dedicated study and practice to become comfortable. Antisyphon: Linux Forensics w/ Hal Pomeranz

Overview42.4 GB

Antisyphon: Enterprise Forensics and Response

The Enterprise Forensics and Response course is designed to provide students with both an investigative construct and techniques that allow them to scale incident response activities in an enterprise environment. The focus of the lecture portion of the course work is understanding the incident investigation process, objective oriented analysis and response, intrusion analysis and an exploration of attacker Tactics and Techniques. The technical portion of the course will focus on how to conduct incident investigations at enterprise scale using the remote evidence acquisition and analysis tool Velociraptor along with other free and open-source tools. The focus of the technical portion will be on extracting usable Indicators of Compromise (IOCs) related to specific MITRE ATT&CK tactics. For example, students will be instructed on extracting and analyzing evidence related to the Execution TA0002 of malicious code or LOLBAS. From here, they will be tasked with addressing containment and eradication measures. This course will combine technical elements along with lecture that provides students with both an investigative construct and techniques that allows them to analyze evidence and provide stakeholders with data necessary to limit the damage of modern cyber-attacks. Antisyphon: Enterprise Forensics and Response

Overview24 GB

Antisyphon: Enterprise Attacker Emulation and C2 Implant Development w/ Joff Thyer

As penetration testers, we all have a need to establish command and control channels in our customer environments. This can be done under the guise of an “assumed compromise” context or in a more adversarial Red Team context. The age of endpoint detection and response (EDR) solutions and application whitelisting has created significant barriers to commodity/well known malware deployment for adversarial exercises. This class focuses on the demonstration of an Open Command Channel framework called “OpenC2RAT”, and then developing, enhancing, and deploying the “OpenC2RAT” command channel software into a target environment. Students will learn about the internal details of a command channel architecture and methods to deploy in an application-whitelisted context. The class will introduce students to blocks of code written in C#, GoLang, and Python to achieve these goals. In addition, the class will introduce some ideas to deploy existing shellcode such as Cobalt Strike Beacon or Meterpreter within a programmed wrapper to enhance success in the age of modern endpoint defense. Many of the techniques introduced in this class can be used to evade modern defensive technologies. Antisyphon: Enterprise Attacker Emulation and C2 Implant Development w/ Joff Thyer

Overview3.2 GB

Antisyphon: Defending the Enterprise w/ Kent Ickler and Jordan Drysdale

For the luckiest of enterprises, the awareness of an insecure environment is proven not in public discord after a breach but instead by effective security penetration tests. Time and time again Jordan and Kent have witnessed organizations struggle with network management, Active Directory, organizational change, and an increasingly experienced adversary. For new and legacy enterprises alike, Defending the Enterprise explores the configuration practices and opportunities that secure networks, Windows, and Active Directory from the most common and effective adversarial techniques. Have the confidence that your organization is prepared for tomorrow’s security threats by learning how to defend against network poisoning, credential abuse, exploitable vulnerabilities, lateral movement, and privilege escalation. Learn cost-effective mitigations to contemporary adversarial attacks. The best defended networks are those which have matured from countless penetration tests and security incidents. Learn from Kent and Jordan, two seasoned offensive and defensive security experts, to shortcut your organization’s security posture into a well-fortified fortress. Antisyphon: Defending the Enterprise w/ Kent Ickler and Jordan Drysdale

Overview21.3 GB

Antisyphon: Attack Emulation Tools: Atomic Red Team, CALDERA and More w/ Carrie Roberts

Attack Emulation tools help you measure, monitor, and improve your security controls by executing scripted attacks. Atomic Red Team is a community developed open-source library of these scripted attacks that are mapped directly to the MITRE ATT&CK Framework. There are several frameworks available for executing these scripted attacks including MITRE CALDERA and VECTR.

Overview8.7 GB

Antisyphon: Advanced Red Team Operations

This is an advanced course that focuses on setting up secure and resilient C2 infrastructure using Azure/AWS, creating custom Cobalt Strike profiles, hunting for Active Directory Certificate Services misconfigurations in mature enterprise environments. Learn current post-exploitation techniques that White Knight Labs (WKL) has used during real-life engagements to dump credentials, move laterally, escalate to Domain Admin, and capture the client’s crown jewels. We will cover EDR bypass briefly, but AV/EDR bypass will be assumed knowledge for this course. Although this course is designed to be a deep dive into hunting for ADCS misconfigurations and setting up C2 infrastructure, an apex attacker must also know their own indicators of compromise (IOCs) they’re creating and the artifacts they’re leaving behind. On the second day, students will be led through a real-life red team operation. Syllabus Day 1: Red Team Fundamentals Cobalt Strike/Guacamole walkthrough Terraform for infrastructure automation Redirectors and CDNs Custom malleable C2 profile Protecting your C2 server (mod rewrite and proxy pass) Touch and go AV/EDR Bypasses Day 2: Red Team Operation Attack Paths Advanced payload creation Windows lateral movement SOCKS proxies Service controller WMI COM/DCOM Abusing AD misconfigurations via C2 channels (ADCS) Advanced credential dumping techniques SQL misconfigurations for lateral movement and code execution Antisyphon: Advanced Red Team Operations

6 modules3.4 GB

SEC201: Computing & Technology Essentials

SEC201 is an entry-level course designed to provide a strong foundation in computing and technology concepts essential for cybersecurity professionals. The course covers fundamental topics such as computer hardware, operating systems, networking, and basic programming principles. Participants will also explore key cybersecurity concepts, including threat identification, basic encryption, and safe computing practices. Through practical exercises and real-world examples, SEC201 equips attendees with the essential technical knowledge and skills needed to succeed in more advanced cybersecurity training and roles, making it an ideal starting point for individuals new to the field.

5 modules46 MB

Hackademy: Red Team Wi-Fi

Many publications exist documenting ways to attack Wi-Fi networks. Still, the gap between old methods that have become obsolete and the current state and outdated tools can be frustrating for someone who wants to learn or even update his knowledge in this field. This course aims to learn the modern ways of assessing the security of Wi-Fi networks and how to apply these attacks against organizations during a Red Team engagement. Indeed, during this course, we will be able to start from the very beginning by talking about old, current, and new attacks and opportunities to allow attendees to fulfill their pentest or Red Team engagements in the future based on our recent experiences. Syllabus Introduction Network introspection Attacks and risks Completion Hackademy: Red Team Wi-Fi

2 modules5.7 GB
ZIPZ01Z02+1

Practical Analysis with Security Onion 2.3

This course is geared for those interested in seeing how Security Onion is used practically to triage alerts, hunt for threats, as well as build new detections. This course consists of three case studies that briefly cover the 3 most common workflows used in Security Onion: Case Study 1: Alert Triage & Case Creation – This case study walks through how to triage alerts within the alerts interface including escalation to TheHive. Case Study 2: Threat Hunting – This case study focuses on threat hunting within Security Onion using the Hunt interface, targeting SSL & Sysmon logs. Case Study 3: Detection Engineering – This case study covers ingesting Google Workspace audit logs into Security Onion and writing Sigma rules within Playbook targeting these new logs. Practical Analysis with Security Onion 2.3

Overview349 MB

Developing Your Detection Playbook with Security Onion 2.3

This course is geared for those wanting to understand how to build a Detection Playbook with Security Onion 2.3. Students will gain both a theoretical and practical understanding of building detections in Security Onion, reinforced with real-life examples from network and host datasources. Syllabus Course Welcome & Introduction to Security Onion Security Onion Installation tDetection Engineering tKey Components of a Play Operationalizing Plays with Sigma Getting Started with Playbook Creating New Plays Developing Your Detection Playbook with Security Onion 2.3

1 modules344 MB

Security Onion 2.3 in Production

This course is geared for administrators of Security Onion 2.3. Students will gain a foundational understanding of the platform – how to architect, deploy, manage and tune their Security Onion 2.3 grid. Syllabus Preview Course Welcome & Introduction to Security Onion Overall Architecture Installation – Manager Node Installation – Search Node Installation – Forward Node Grid Management with Salt Grid User Management Grid Firewall Management Grid Updates Grid Hardening Security Onion 2.3 in Production

1 modules276 MB