
Introduce learners to adversary emulation by simulating a fintech startup breach, covering active and passive information gathering, gaining a foothold, privilege escalation, and persistence via command-and-control software.
Compare red teaming with adversary emulation to show how offensive security assessments reveal weaknesses, test defenses, and simulate incident response with scenarios like ransomware and data theft.
Explore a fictional startup Tax Labs and its investors' security concerns through an adversary evolution exercise that uses a replica environment with test data to probe the platform.
Explore an adversary attack methodology based on the red team operation cycle, starting with zero-knowledge reconnaissance, then initial compromise, persistence, internal recon, and exfiltration.
Compare reteaming and adversary in relation as red engagements focused on a single scenario; That First Labs, a fintech startup, hires a red team to run a zero-knowledge adversary emulation.
Set up the attack machine with essential tools and discuss making those tools accessible via a web server to the target network, and establish a centralized note-taking environment with CherryTree.
Set up a kali linux attack machine by downloading a 64-bit vmware image, installing sublime text, and creating scripted logs and folders to record commands during the exercise.
Install and download a suite of adversary emulation tools—mentalist, begats, bloodhound, jawboned, ganon, porche c2—via an automated script, then configure bloodhound and new 4g.
Set up a web server to host tools by copying them to the webroot, adjust ownership and permissions, start the server when needed, and verify access via localhost.
Set up a note taking environment using Cherry Tree, a free, hierarchical note taking application, to store phase information from red team operations and organize subnodes for each site.
Set up an attack environment by configuring a Linux machine, creating folders, and enabling scripting. Install tools for the exercise and create a node picking environment to centralize collected data.
Learn to self-host the red team lab for adversary emulation by completing eligibility forms, joining the Discord server, provisioning an AWS IAM account with minimal permissions, and understanding hosting costs.
Learn how to fetch your account ID from the IWC management console, copy or paste it into lab prerequisites, and handle hyphenated formats.
Create an AWS IAM user to host Tax First Labs red team network, attach full access, CloudWatch, and EC2 full access policies, and generate an access key and secret key.
Subscribe to the Apache Guacamole AMI from the AMA page, using the account you will use to self-host the from network, and set the prerequisite form answer to yes.
learn to manage a self-hosted ex-First Labs 30-minute network using the action Discord bot, deploying, configuring credentials, starting and stopping machines, and monitoring lab status.
Analyze a website to identify its technology stack with red dot com, use tech-specific tools to prepare a report, and inspect the web server for accessible files.
Perform OSINT recon on a target organization by examining the website, social profiles, and technology stack, identifying potential exploits from outdated WordPress plugins and exposed contact details.
Perform a DirBuster reconnaissance to enumerate server files using a default wordlist, reveal exposed resources such as Outlook Web Access, and assess foothold potential.
Perform open-source intelligence on a target organization using tools like moved with dot com, WP scan, and eye buster to uncover Lingnan data, three users, and exposed outlook web access.
Utilize recon insights to identify a vulnerability in the taxpayers lab's website and establish an initial foothold, returning to the attacker machine for the next phase.
Identify vulnerable WordPress plugins via scan and exploit unauthenticated file upload to gain remote code execution; demonstrate uploading a reverse shell to compromise a web server.
Analyze how an unauthenticated vulnerability yielded a foothold and limited shell on a target website, then use an uploaded file to gain remote shell access in a simulated breach.
Build on the initial foothold in the target network by compromising S01 01 Ripsaw One, which hosts the first lab's website, and escalate from the compromised machine to root.
Perform basic information gathering on the attack machine, identifying hostname, current user, IP address, and operating system details, then assess kernel vulnerabilities for privilege escalation via available exploits.
Examine the dirty cow exploit and how a malicious binary, run by any user, can override NATO protections and escalate privileges on a compromised machine.
Explore how an attacker escalates privileges by deploying a 64-bit exploit, replacing the user password, compiling and running as root, and disabling cache write-backs to seize control of a server.
Explore a web server breach on the first labs network, perform recon insight attacks and privilege escalation using an old Linux kernel, and practice automation with a Linux machine script.
Explore how adversaries maintain access after losing initial entry by using persistence and command-and-control techniques to re-enter networks and add a local user on a web server.
Execute persistence techniques using posh c2 to deploy a command-and-control agent, create a new user, configure the server, and interact with compromised machines.
Establish persistence on the target server using Poche Command and Control Center software. Add a local user on the target web server to enable future module tools and seamless interaction.
Learn to download a binary on a compromised web server and use it to discover live hosts and what's available on those hosts.
Map the target network to discover live hosts and scan ports through internal reconnaissance, identifying a domain controller, exchange server, and user workstations.
Identify three hosts and a domain controller from internal recon, then download and map the static binary on compromised server with nmap to discover live hosts and their open ports.
Explore how to analyze gathered information from conferences to identify an exploit vector in a vehicle network and move it in the network to compromise another machine.
Generate custom username and password lists to brute-force the Outlook Web App, using patterns like first name plus last name or initials, and month, season, and object-based passwords.
Emulate a real-world cyber attack by brute-forcing the Outlook Web App with an auxiliary scanner to test logins and reveal a credential, then explore a phishing vector for payload delivery.
attackers partially compromise Mukherjee by forcing credentials and phish Pavlin to access the machine, then use password lists and brute-force login to deploy a malicious payload.
This lecture demonstrates privileged escalation on a compromised machine using Ballot Up, a power script to identify Windows services and escalate privileges.
Load power up into the target machine's memory using IEX, then enumerate vulnerable services to identify restart rights and manually generate a malicious binary for exploitation.
Learn how unquoted service path vulnerabilities in Windows enable attackers with service control rights to trigger a malicious executable by writing to the service path.
Explore how an attacker assesses folder permissions using icacls, identifies write access for authenticated users, and backs up a service file before replacing it with a malicious variant.
Explore adversary emulation techniques by using venom to generate payloads, deploy a malicious binary on a target Windows system, and escalate privileges to administrator.
Examine how adversaries establish persistence with poshC2 and escalate privileges to administrator, then deploy a command-and-control agent using a C# drop payload.
Trace the attack path as we escalate privileges on a compromised machine, gaining access to services and domain, then enumerate the network with PowerUp scripts to deploy a malicious binary.
Welcome to a simulated live Red Team Operation.
You aren't just learning isolated tools—you are stepping into a live Adversary Emulation exercise. Hired by a FinTech startup, your objective is strictly defined: assuming zero prior knowledge of the target network, you must mimic a real-world cyber attack and successfully exfiltrate customer data before actual threat actors do.
Forget academic fluff. This is a practical, low-drag engagement that follows the professional Red Team Operations Attack Lifecycle. Instead of a disjointed list of exploits, we build a cohesive attack path step-by-step, executed in a safe, local lab environment so you can practice without expensive cloud overhead.
We will cover the installation and tactical deployment of industry-standard tools like PoshC2, BloodHound, Mimikatz, Metasploit, and PowerUp, mapping our techniques across the attack phases:
Recon & Initial Access: Active and passive information gathering, weaponizing exploits, and executing targeted employee phishing.
Execution & Escalation: Bypassing defenses and escalating privileges across both Linux and Windows systems (utilizing icacls and PowerShell).
Discovery & Lateral Movement: Automated Active Directory domain enumeration, password brute-forcing with custom lists (Mentalist), and executing modern AD attacks.
Command & Control (C2): Establishing covert persistence and managing infrastructure.
Action on Objectives: Completing the mission and preparing an actionable engagement report for the organization's management.
Who this course is for:
Beginners in Offensive Security: If you are just starting your career or preparing for penetration testing exams, this beginner-friendly course provides a clear introduction to real-world attack paths.
Blue Teamers & SOC Analysts: To catch an attacker, you need to understand their methodology. Witnessing a live emulation exercise provides invaluable perspective on how adversaries string techniques together.
Current Pentesters: If you already know individual exploits, this exercise connects the dots, showing how isolated vulnerabilities are chained into a full-scope campaign.
This is a beginner friendly course. If you have just started your career in offensive cybersecurity or are preparing for penetration testing exams then this course is for you. If you are interested in witnessing a live adversary emulation exercise, please feel free to follow along.