
All TCG Security Academy courses that aren't on this platform are on their domain, which has a lot of benefits and other cybersecurity courses. Just visit the platform - www.tcg-sec.org
Course Resources
Download and install Terabox on your mobile or PC and get loged in, then visit the link below to download the resources.
I offer resources on Terabox because it offers 1TB of cloud storage, file managing on the application, faster uploads and downloads than other hosting platforms, that's why this is my only option.
If the zipped file has a password, it's going to be: www.tcg-sec.org
Terabox: https://1024terabox.com/s/1IQW6C-9L7DbjUaCqakMZ3Q
Set up two virtual machines, Kali Linux and Windows 11, using VMware Workstation, and apply system updates to beef up security as the lab starts.
Download and extract Kali Linux and Windows 11 pre-installed virtual machines for VMware, inspect their contents, and prepare to set up these machines in the next video.
Set up Kali Linux and Windows 11 virtual machines in VMware, importing VMs, adjusting RAM and processors, and configuring bridged and NAT networks with custom IPs.
Boot and configure a Windows 11 virtual machine, optimize performance by adjusting settings for best performance, remove unnecessary software, and ensure updates are current for a ready, up-to-date environment.
Explore low-level persistence in Windows, its challenges for a low-level user, and tactics to maintain access while evading antivirus and endpoint detection systems.
Create and manage a scheduled task to persist access by regular user or medium integrity, daily at 9 a.m., running a malicious binary, then verify and remove it.
All TCG Security Academy courses that aren't on this platform are on their domain, which has a lot of benefits and other cybersecurity courses. Just visit the platform - www.tcg-sec.org
Examine logon scripts as a persistence technique for regular or medium integrity users, highlighting Apt28 Group, Cobalt Group, and Zebra's Groups, including registry persistence and logging to monitor activity.
Explore admin level persistence in Windows, examining techniques to maintain access across reboots while operating as an administrator, and learn how persistence targets low and high privilege scenarios.
Explore initial access and elevation to persist as an administrator on Windows, demonstrated via a Kali Linux shell, elevated privileges, and a plan to deploy persistence techniques.
Demonstrates creating a scheduled task with admin privileges and high integrity level to achieve persistence, configure task XML, and maintain an interactive shell.
Demonstrates creating a multi-action scheduled task with admin privileges, exporting to task XML, backing up, modifying it to run a payload on user logon, and restoring the original task.
Learn the winlogon registry shell technique for admin persistence, starting from a regular user and using system32 binaries, testing with sign out and sign in, and cleanup.
Explore how the Winlogon registry userinit key enables persistence by injecting a malicious binary into system32, using admin privileges, and aligning with login events to gain a shell.
All TCG Security Academy courses that aren't on this platform are on their domain, which has a lot of benefits and other cybersecurity courses. Just visit the platform - www.tcg-sec.org
explores WMI event subscription as a persistence technique, detailing event filter, event consumer, and binding, to trigger a payload when Microsoft Edge launches and grant system-level access.
explore Windows persistence techniques by creating a hidden privileged user and enabling remote desktop access, including logon concealment and registry tweaks.
All TCG Security Academy courses that aren't on this platform are on their domain, which has a lot of benefits and other cybersecurity courses. Just visit the platform - www.tcg-sec.org
This course explores advanced techniques for maintaining persistent access in Windows-based systems, a critical skill for both cybersecurity professionals and ethical hackers. As attackers often aim to establish long-term control over compromised systems, understanding Windows persistence mechanisms is essential for effective detection, defense, and incident response.
Participants will delve into various persistence techniques, including registry modifications, scheduled tasks, and leveraging Windows services to maintain undetected access. The course covers the use of malware, backdoors, and rootkits to ensure ongoing access, as well as methods to evade detection by antivirus software and security monitoring tools.
The course will also address the implications of persistence in penetration testing, where ethical hackers simulate real-world attacks to evaluate system defenses. Hands-on labs will give students the opportunity to practice setting up and detecting persistence mechanisms in a controlled environment, equipping them with the skills needed for proactive system defense and response to advanced persistent threats (APTs).
By the end of the course, participants will be able to:
Understand various Windows persistence techniques and how attackers use them.
Identify common methods for establishing persistence on Windows systems.
Implement strategies for detecting, mitigating, and removing persistence mechanisms.
Apply learned techniques in ethical hacking scenarios and penetration tests.
Designed for security professionals, penetration testers, and incident responders, this course enhances your ability to protect against advanced cyber threats and improves your capability to secure Windows environments.