
Advanced Practical Initial Access ( Social Engineering ) 2 - https://www.tcg-sec.org/courses/advanced-practical-initial-access-2/
All TCG Security Academy courses that aren't on this platform are on their domain, which has a lot of benefits and other cybersecurity courses. Just visit the platform - www.tcg-sec.org
All TCG Security Academy courses that aren't on this platform are on their domain, which has a lot of benefits and other cybersecurity courses. Just visit the platform - www.tcg-sec.org
Course Resources
Download and install Terabox on your mobile or PC and get loged in, then visit the link below to download the resources.
I offer resources on Terabox because it offers 1TB of cloud storage, file managing on the application, faster uploads and downloads than other hosting platforms, that's why this is my only option.
If the zipped file has a password, it's going to be: www.tcg-sec.org
Terabox: https://1024terabox.com/s/1J0pmDB8qH-v_UvSVkXzAfA
set up a lab environment by downloading and installing vmware workstation pro, walk through the setup wizard, restart, and activate with a pro license key after the 30-day trial.
Download Windows 10 and Kali Linux ISOs by navigating browser links, selecting edition and language, and using a Linux Firefox user agent to enable 64-bit or 32-bit options.
Set up Kali Linux and Windows 10 VMs in VMware workstation, configuring RAM and storage while isolating them on a host-only network to prevent updates.
Install the Kali Linux virtual machine named Joker, configure language, network, and a user, then partition the disk, install the base system, and update with apt update and apt upgrade.
Learn to install Windows machines via VMware Workstation, automating setup with autopilot, user creation, and automatic login while Kali Linux manages virtualization and networked updates.
Install Microsoft Office Pro Plus 2019 on two Windows machines by mounting the ISO, selecting Word and Excel, and preparing for activation after temporarily disabling real-time protection.
Set up and configure the c2 frameworks villain framework and metasploit framework to kick off this section of the course on initial access via social engineering.
Set up the metasploit framework, initialize the database, configure a Windows x64 Meterpreter reverse TCP payload, set LHOST and port 443, and enable stage encoding for covert traffic.
Explore effective note taking in cyber security by reviewing types of note keeping tools and the software I use to organize daily work.
Compare note keeping tools for cybersecurity work—keep note, one note, obsidian, and cherry tree—covering cloud sync, backups, and code syntax support; plus green shot for screenshots.
All TCG Security Academy courses that aren't on this platform are on their domain, which has a lot of benefits and other cybersecurity courses. Just visit the platform - www.tcg-sec.org
Explore how to modify villain payloads, obfuscate code, and test undetected versus detected payloads to establish background sessions with a listener in a Windows lab.
All TCG Security Academy courses that aren't on this platform are on their domain, which has a lot of benefits and other cybersecurity courses. Just visit the platform - www.tcg-sec.org
Shows a proof-of-concept that you don't need villain C2 frameworks to achieve initial access, by demonstrating how PowerShell payloads can be modified to evade antivirus and establish a reverse shell.
All TCG Security Academy courses that aren't on this platform are on their domain, which has a lot of benefits and other cybersecurity courses. Just visit the platform - www.tcg-sec.org
Learn to obfuscate payloads and code and sign them to appear unsuspicious and legitimate to antivirus software in this section on advanced practical initial access.
Learn how a binary payload can be made to look unsuspicious to antivirus software by modifying metadata and icons with tools like Resource Hacker, while noting ethical and detection considerations.
Learn how code signing certificates and digital signatures validate software, assess revocation and expiration scenarios, and understand how certificate choices affect payload authenticity.
Explore fishing with HTA files and prepare three machines—Kali Linux development box and Windows 10 target machines—ensuring all are up to date before proceeding.
Explores image attacks technique 2 golden attack, demonstrating a download, save and run payload delivery with metasploit and a hidden powershell execution to establish a meterpreter session.
Wrap up this section reinforces phishing using image files, warns against harm, and notes undetected payloads and antivirus bypass, and previews phishing with other techniques in the next section.
this lecture demonstrates image-based initial access via a decoy image that secretly executes a payload and gains a remote shell, using Kali Linux and a Windows 10 target.
Explore the image attack technique, leveraging WinRAR to conceal a payload and establish a Meterpreter session through Metasploit on a target Windows machine.
Wrap up this section on phishing with image files, emphasizing ethical use. It warns about dangerous payloads and viruses from GitHub, bypassing antivirus, and encourages responsible, non-harmful practice.
Phish using Microsoft Office documents to trigger macros, gaining a shell on target machines, within a clean, controlled lab setup to practice social engineering and evading defenses.
Office Word attack technique uses macro-enabled documents to deliver encoded PowerShell payloads, bypass defenses, and establish a backdoor session.
Explore obfuscation techniques for malicious documents and concealment of macros to evade detection, including base64 encoding and the use of tools to modify a document’s macro payload.
Ethical Hacking - Social Engineering
This immersive, 250-word course description is for our course about Cyber Security titled "Advanced Tactics in Practical Initial Access and Network Penetration." This rigorous program is fabricated for information security experts seeking to master the art of initial access, a foundational and critical step in the cyber breach process.
Dive into the challenging world of digital infiltration with our expertly crafted, scenario-based curriculum. This comprehensive course zeros in on advanced tactics that are used by cyber adversaries to establish a covert presence within target networks. Participants will dissect and reconstruct real-world attack vectors, understanding the intricate mechanisms behind successful initial access operations.
Throughout the duration of the course, we place a significant emphasis on practical, hands-on learning. Pupils will engage with cutting-edge technology, going beyond theoretical knowledge to apply what they discover in realistic penetration testing environments. They will study under the guidiance of industry veterans, exploring key components such as social engineering mastery, exploitation of public-facing applications, sophisticated phishing techniques, and the art of circumventing modern security measures.
We will delve into the nuances of attack methodologies such as weaponized document delivery, living-off-the-land tactics, and exploitation of zero-day vulnerabilities. Learning to recognize, exploit, and remediate such vulnerabilities provides our students with the capability to not only conduct advanced threat simulations but to also significantly bolster their own organizations’ defenses.
On completing this course, you’ll emerge with the acumen to navigate the evolving threat landscape, equipped with the expertise to detect, respond to, and mitigate against sophisticated initial access threats—positioning you at the vanguard of cybersecurity defense.