
Explore how adversaries think and how they hack to take the offensive side of security, study red, blue, and purple team dynamics, indicators of compromise, and cyber kill chain.
Start at the top of this course and work down through topics to optimize learning. Use demos, activities, and discussions to boost retention with Edgar Dale's cone of experience.
Explore the adversary's tactics, techniques, and procedures through the cyber kill chain and Mitre attack, and map reconnaissance, weaponization, delivery, exploitation, and indicators of compromise to defense.
Explore the adversary mindset by defining threat and risk terms, distinguishing black hat, white hat, and gray hat hackers, and examining motivations, targets, resources, and capabilities that threaten organizations.
Identify assets and threats, such as data that can be stolen, altered, or deleted, and apply CIA triad: confidentiality, integrity, availability, to assess probability, impact, and guide defense in depth.
Know the adversary by analyzing threat actors' motivations, targets, and capabilities through threat modeling to identify risks and defend your organization against attacks.
Explore hacker ethics by contrasting white hat, gray hat, and black hat hackers, including legal bounds, ethical hacking, and the role of permission and penetration testing.
Explore adversaries’ characteristics, including hacker types, motivations, sponsorship, relationships, and resources, to anticipate attacks and strengthen defenses in depth and perimeter security.
Identify attacker motivations to predict attack approaches and resource investment. Explore drivers like curiosity, notoriety, revenge, financial gain, power, and hacktivist aims to enact change, plus internal threats shaping defenses.
Identify adversaries and their targets to design a defense in depth that balances cost with protecting assets, data, and people, considering attacker motivation and low hanging fruit.
Define adversary objectives and action on objectives using the Mitre ATT&CK framework, contrasting data exfiltration and impact, with examples from espionage, blackmail, and ransomware.
Explore how hackers shift from lone operators to sponsored teams funded by corporations, organized crime, nation-states, and terrorist groups, expanding cybercrime for competitive and political aims.
Learn how adversary capabilities depend on tools, knowledge, skills, and resources attackers bring. Cover script kiddies, advanced persistent threats, and access routes via supply chains and brokers.
Explore insider threats, distinguish internal and external threats, and mitigate shadow it to protect networks from misconfigurations and social engineering.
Explore how attackers systematically evaluate organizations, identify entry points, establish presence, and pursue objectives. Examine attack methodologies, tactics, techniques, procedures, mitre attack, kill chain, diamond model, and adversary signatures.
Analyze attack methodologies and the flow attackers follow, using tactics, techniques and procedures, mitre attack, the cyber kill chain, and the diamond model of intrusion analysis to defend networks.
Explore how attackers use tactics, techniques, and procedures to gain initial access and progress through a network, with examples like spear phishing, firewall bypass, and data exfiltration.
Discover MITRE ATT&CK, a comprehensive database of adversary tactics and techniques organized into enterprise, mobile, and ICS matrices, with subtechniques, descriptions, and examples of groups.
Explore Mitre attack tactics and the attack flow from reconnaissance to data exfiltration, including initial access, execution, persistence, privilege escalation, defense evasion, discovery, and lateral movement.
Explore the cyber kill chain from reconnaissance to data exfiltration, including weaponization, delivery, exploitation, installation, persistence, and command and control; compare it to the mitre attack.
Discover how the cyber kill chain guides defense from recon through delivery and exploitation, using phishing awareness, intrusion detection, firewalls, and traffic analysis to disrupt attacks.
Explore the diamond model of intrusion analysis to map single events, link adversaries, victims, capabilities, and infrastructure, and trace them along the cyber kill chain to uncover compromised data.
Identify adversary signatures by analyzing attack patterns and fingerprints, using the diamond model and the CPIC database to trace groups and techniques.
Explore reconnaissance and attack planning from an attacker's perspective, covering open source intelligence, DNS reconnaissance, website reconnaissance, social media scraping, dumpster diving, eavesdropping, and mapping attack surfaces and vectors ethically.
Learn how reconnaissance collects target data, from open source intelligence to enumeration. Explore passive and active reconnaissance, external and internal assets, and tools used to map networks and avoid detection.
Explore open source intelligence (osint) to gather, analyze, and disseminate publicly available information about a target company, using tools, Google searches, and websites for reconnaissance.
Explore how DNS reconnaissance uncovers a target's owned domains, IPs, A and MX records, and reverse DNS to map services and identify vulnerabilities.
Explore website reconnaissance to map company assets, enumerate urls, and scrape data from web pages, while examining dns lookups, server directories, and plugin vulnerabilities.
Use social media scraping to uncover company information and contacts, revealing security holes and opportunities for targeted research and social engineering through LinkedIn, blogs, and other sites.
Explore how dumpster diving reveals discarded documents and exposed data, and highlight legal considerations of reconnaissance as a prelude to researching a company.
Discover how eavesdropping and snooping evolve from informal overhearing to digital listening on networks, including attacks and the use of network sniffers.
Identify the attack surface as the full set of entry points into a network, from perimeter to internal layers, and explore physical, digital, and social avenues, including supply chain risks.
Map the attack surface to identify attack vectors and vulnerabilities across hardware, software, networks, and human factors, then develop an attack plan.
Explore the weaponization phase of the cyber kill chain, examining malware types and how brokers may supply access in ethical hacking education.
Arm teams for cyber attacks by weaponization: acquire or create malware, infrastructure, and access—domains, dns, web services, compromised accounts, and malvertising—ready to support operations in the cyber kill chain.
Explore how brokers enable cybercrime by buying, selling, and trading access, identities, vulnerabilities, exploits, and malware on the dark web, and how an access broker intermediates attacks.
Learn how malware, malicious software designed to disrupt or exfiltrate data, appears as ransomware, viruses, trojans, and more; explore vectors, payloads, and stealthy delivery in the cyber kill chain.
Differentiate between virus and malware, noting a virus is a type of malware. Describe how a virus replicates itself and inserts into code or files, spreading from host to host.
Explore boot sector viruses and how they reside in the drive's initial boot sector, gaining control as the first code to run, potentially bypassing the operating system and security measures.
Explore how a computer worm replicates itself as a standalone file, spreading across networks, consuming resources, and potentially delivering ransomware, data exfiltration, or command-and-control payloads.
Identify how a Trojan disguises itself as legitimate software to collect credentials and compromise a system, illustrating the Trojan horse deception.
Explore how ransomware encrypts data and holds it for ransom, requiring victims to pay attackers for a decryption key.
Explore command and control, a phase in the cyber kill chain and a MITRE attack tactic, involving malware or software that remotely controls a target computer on a network.
Learn how a remote access trojan provides covert remote control, masquerading as legitimate software, often running in the background, and acting as a C2 malware to control machines and networks.
Explore how a botnet, a network of bots, gives command and control over many machines to launch attacks like distributed denial of service and spam email campaigns.
Explore how spyware secretly collects information during an attack, from screen monitoring and webcam access to keyloggers that capture keystrokes and send data to the attacker.
Learn how keyloggers log keystrokes, whether software or hardware, and where data is stored. Compare local storage, file storage, and network transmission, along with the trade-offs of physical access.
Explore fileless malware that runs in RAM to evade disk scans, gaining stealth at the cost of persistence after reboot, and weighing its advantages and drawbacks.
Show how a logic bomb embeds in malware, delaying activation until a time-based condition triggers, enabling wide propagation before the attack launches.
Explore rootkits as a kit of software that grants root access and escalated privileges, not always malware, with legitimate uses and security risks.
Explore cryptojacking by examining how attackers misuse unconsenting devices to mine cryptocurrency for profit, draining resources and slowing systems.
Adware is software that shows ads, which can cause distracting pop-ups and degrade enterprise networks. It may deliver other malware, making adware a security concern for users and IT teams.
Explore scareware, a tactic that uses alarming popups claiming viruses to prompt users to download software, which instead installs malware and harms the computer.
Learn how bloatware consists of unnecessary software that fills hard drive space, drains bandwidth and processing power, and slows devices, with pre-installed programs and excessive features people don’t really use.
Identify enterprise level concerns from legitimate software, such as crypto mining draining resources, and recognize shadow IT and cowboying that disrupt unified communication and productivity.
Explore how attackers deliver malware into networks through social engineering, from high-level concepts to specific methods and tools, including artificial intelligence, all within an ethical hacking perspective.
Deliver weaponized malware into a network by exploiting attack surfaces through social engineering, attachments, and third-party vectors.
Explore how social engineering exploits human psychology to manipulate behavior and bypass security, using phishing emails, voice calls, in-person visits, and no-contact schemes.
Explore overt and covert social engineering methods, analyze emotional manipulation and urgency cues, and train users to slow down and think logically to prevent manipulation.
Explore how adversaries build trust through empathy, flattery, social proof, similarities, and partial truths to enable social engineering, including impersonation and Curly Spider's phishing tactics.
Learn how impersonation fuels social engineering by quickly gaining trust through authority figures, IT support, brands, or typosquatting sites, including vishing examples and real-world tactics.
Typosquatting is an impersonation attack using misspelled domains to mimic legitimate websites, with names like URL hijacking, sting site, cousin domain, fake URL, cybersquatting, and Brandjacking.
Learn how url obfuscation hides the true destination by manipulating uri components, such as the scheme, host, and encodings, to redirect users to a malicious site.
Discover domain shadowing, using a legitimate DNS server to covertly insert records that point to attacker resources and enable phishing, malware delivery, or data exfiltration while evading detection.
Explore how a 302 cushioning attack redirects users from a legitimate site to a malicious page that hosts malicious software, exploiting http 3xx responses like 301 and 302.
Explore business email compromise (BEC) and impersonation via email, as attackers spoof Susan from finance to deceive colleagues like Jane, sometimes using fake reply-to addresses.
Pretexting uses a fictitious plausible story to gain trust and extract money or information, often paired with impersonation to manipulate victims into divulging information or doing something.
Discover how watering hole attacks compromise websites that specific groups frequently visit, enabling attackers to gain access into the organization through users' visits.
Explore baiting as a social engineering tactic that entices users with offers, such as a free e-book, to lure them into scams and phishing emails.
Explore how spam constitutes unsolicited or unwanted emails, why it floods inboxes, and how it causes productivity loss by making legitimate messages harder to find.
Recognize phishing as a social engineering tactic that tricks victims into disclosing sensitive information via email or messages, including attachments, and use phishing buttons to identify phishing emails.
Learn how spearfishing targets a specific individual with a tailored email to exploit information disclosure, making phishing attacks more effective than broad, mass emails.
Target high-level executives through whaling, a form of spearfishing that aims at the CEO and other C-suite leaders to access critical information.
Explore smishing, the technique of using text messages to deceive victims into disclosing sensitive data or visiting a site, and learn how attackers leverage SMS to carry out targeted attacks.
Explore vishing, the voice phishing tactic that uses phone calls and voice messages to trick victims into disclosing sensitive data. See how attackers use voice services across phone lines.
Learn how shoulder surfing lets an adversary glimpse credentials by watching victims type at ATMs, point-of-sale terminals, or during IT support.
Tailgating follows an authorized person into a locked entry point without consent, while piggybacking uses consent to enter. Both exploit door practices in buildings and elevators to gain access.
Explore how a USB drop exploits curiosity by leaving infected drives in public spaces, prompting users to plug in and attackers to gain network access.
Learn to identify false information across misinformation, disinformation, and deepfakes, distinguishing unintentional errors from deliberate manipulation and understanding the potential harms.
Explore the quid pro quo concept in cybersecurity, from bribes and deals to social engineering that trades access or credentials for entry.
Blackmail involves an adversary threatening to leak compromising information unless the victim complies. It is an overt, illegal tactic demanding cash or access to systems.
Explore how social engineering relies on a range of tools, including the social engineering toolkit and AI, used by attackers and security professionals to test defenses within organizations.
Explore how artificial intelligence powers social engineering, from AI-generated phishing and deepfake videos to AI-facilitated interviews and fake LinkedIn profiles, and why defenders must counter with AI-driven defenses.
Explore the exploitation phase by examining vulnerabilities across networks, protocols, hardware, software, cloud virtualization, cryptographic, human, password, process, and physical weaknesses, and how attackers deliver weaponized malware.
Explore how vulnerabilities enable exploitation by malware during execution, and how the vulnerability lifecycle—from zero days to patches—is tracked and cataloged in CVS and the exploit database.
Identify common network vulnerabilities such as insecure wireless and wired networks, Bluetooth on devices, eavesdropping on traffic, open service ports, and misconfigurations, and understand how outdated firewall settings expose systems.
Examine protocol vulnerabilities across the OSI model, comparing IPv4 and IPv6 while noting insecure protocols like HTTP and FTP and risks such as spoofing and denial of service.
Explore common hardware vulnerabilities, such as insecure default credentials, open ports, and misconfigurations, and learn why firmware updates and patching matter for switches, IoT, and industrial control systems.
Explore common software vulnerabilities in business apps and in-house development, including misconfigurations, default credentials, patching, and zero-days. Note in-house risks like buffer overflows and injections.
Explore common vulnerabilities in virtualization and cloud environments, including misconfigurations, poor access controls, insecure APIs, VM escape, and risky memory reuse across shared resources.
Explore cryptographic vulnerabilities, including weak ciphers, insecure implementations, weak or default keys, poor key management, weak random number generation, hard coded keys or secrets, certificate errors, and cipher suite risks.
Highlight common human vulnerabilities in cybersecurity, examining social engineering, trust, emotions, knowledge gaps, and accident-prone or lazy behaviors that attackers exploit and organizations must guard against.
Identify common password vulnerabilities and attacker methods, including social engineering, phishing, shoulder surfing, eavesdropping, keyloggers, data breaches, rainbow tables, brute force, password spraying, credential stuffing, mask attacks, and password reuse.
Identify common process vulnerabilities and implement well-defined, documented security processes, including change management, encryption, logging, and monitoring, to minimize risks during staffing changes and shifts like mergers and acquisitions.
Identify physical vulnerabilities in servers, switches, routers, and firewalls, including access risks, environmental failures, and misconfigurations. See how these threats impact confidentiality, integrity, and especially availability.
Explore exploit chaining that combines multiple vulnerabilities to compromise a system, and distinguish vulnerability from exploitation with examples like proxy shell and service now attack chains.
Explore attacks, such as denial of service, eavesdropping, spoofing, and adversary in the middle, and map them to apex domains: software, hardware, communication, supply chain, social engineering, and physical security.
Explore how adversaries install and persist inside a network, then perform internal discovery, network reconnaissance, sniffing, wiretapping, Nmap scanning, credential harvesting and dumping, and vulnerability enumeration.
Explore network discovery and enumeration by detailing reconnaissance, staging component delivery, and installation to gain persistence, footholds, backdoors, and access to Active Directory environments.
Learn to map a network through discovery and enumeration, identify devices, services, shares, users, credentials, tokens, and vulnerabilities, and pivot across systems using tools like nmap and wireshark.
Explore network discovery and reconnaissance for wiretapping, balancing passive monitoring with active scanning to observe ARP traffic, hosts, services, and banner grabbing.
Explore wiretapping concepts by examining how unauthorized monitoring of electronic communications occurs, from traditional phone lines to modern network sniffing with Wireshark.
Explore how sniffing attacks listen to network traffic with Wireshark, revealing passive data like TCP, DHCP, IPv6, and spanning tree messages on a demo Cisco network, with ethical hacking emphasis.
Explore how attackers use nmap and zenmap to scan for live hosts, ip ranges, ports, and services in a 10.1.10.0/24 demo, revealing Cisco devices, a raspberry pi, and proxmox.
Explore wireless reconnaissance for wardriving and enumerate wireless networks, devices, users, and traffic to understand what attackers can observe across wireless links.
Drive around to locate insecure wireless networks by wardriving, using a laptop and software to scan networks and identify open wifi hotspots as easy targets.
Port scanning with nmap and zenmap demonstrates protocol, service, and port discovery, showing open ports 21, 80, 443, 3389 and running web services on Apache and Raspbian.
Explore operating system fingerprinting through network discovery: analyze port responses, TCP/IP stack details, and TLS service data to identify Windows or Linux targets, using nmap ethically.
Credential harvesting targets large-scale theft of usernames and passwords across networks, enabling credential dumping; attackers deploy malware, phishing, domain spoofing, or adversary in the middle tactics to collect information.
Identify network vulnerabilities through operating system fingerprinting and active scans, using tools like nmap and Nessus, and prioritize risks with CWE, CVE, CVSS, and EPS scoring.
Explore denial of service attacks and how attackers overwhelm targets with flooding techniques, including icmp floods, tcp syn floods, udp floods, and dns amplification in distributed scenarios.
Explore denial of service attacks that target availability within the CIA triad, examining volumetric floods, protocol weaknesses, application vulnerabilities, and even physical disruption across DNS, DHCP, web servers, and websites.
Jamming disrupts wireless signals by transmitting interference that degrades or disconnects connections between devices, turning any wave-based network—Wi-Fi, Bluetooth, cellular, GPS—into a denial of service attack.
Shows how a rogue DHCP server can cause a denial of service by spoofing DHCP and distributing incorrect IP configurations, disrupting network connectivity.
Explore how a DHCP starvation attack exhausts a scope by repeatedly requesting IPs for different MAC addresses, using Kali Linux and dhcp pig to deny service to legitimate users.
Explore how a buffer overflow exploits memory and RAM layouts, causing denial of service or arbitrary code execution, with heap and stack overflows, memory addressing, and return addresses.
Explore how ping of death uses oversized IP packets and fragmentation on legacy systems like Windows 95. Understand MTU limits, IP header values, and buffer overflow risks.
Learn how a tcp reset attack disconnects two devices by spoofing a switch and sending a reset flag, ending a session and potentially a denial of service.
Explore how a Wi-Fi deauthentication attack disrupts client and access point communication, exposing MAC addresses and enabling denial of service and evil twin and adversary-in-the-middle scenarios.
Demonstrates how flooding attacks overwhelm a device’s resources—memory, CPU, bandwidth, and storage—to deny service, using stress testing tools like Jmeter, Load Ninja, and Web load neo load.
Demonstrates an ICMP flood, or ping flood, overwhelming a target's resources with flood mode and random source addresses, while emphasizing ethical hacking and testing only on authorized equipment.
Explore how a tcp syn flood overwhelms a server by sending syn, syn-ack, and ack during the three-way handshake, tested ethically on kali linux within authorized networks.
Explore how a UDP flood attack overwhelms a server by flooding it with UDP packets that trigger ICMP destination unreachable replies, consuming bandwidth and resources.
Demonstrates how a DNS flood attack overwhelms a target by sending UDP packets to port 53, for ethical hacking on Kali Linux with varying source addresses.
Explore amplification attacks, where small requests produce large replies to exhaust the victim's resources. See how DNS and SNMP exemplify this effect, often with reflective amplification driving denial-of-service.
Learn how distributed denial of service attacks weaponize multiple machines to overwhelm a server, using botnets, command and control, and reflected ICMP requests to flood resources.
Demonstrates a reflected distributed denial of service attack, using address spoofing and ICMP to bounce traffic through multiple machines toward a victim, often with amplification, while emphasizing ethical testing.
Beneath the hood of a local area network, learn broadcasts, directed broadcasts like 192.168.1.255, and how spoofed directed broadcasts enable reflected attacks, plus how broadcast storms cripple networks.
Explore the Smurf attack, an ICMP flood and DDoS method that uses spoofed victim address and directed broadcasts to overwhelm a target with reflected ICMP replies.
Explore adversary in the middle and spoofing attacks, and learn how DHCP spoofing, ARP cache poisoning, DNS cache poisoning, evil twin, and replay attacks enable these techniques.
Explore the adversary-in-the-middle attack, also called man-in-the-middle or on-path attacks, where an attacker sits between client and server to relay, eavesdrop, alter, or delay messages, breaking confidentiality, integrity, and availability.
Explore replay attacks, where an adversary overhears and replays traffic or credentials, including hashed or encrypted data, to gain unauthorized access and threaten authentication.
Learn how spoofing imitates network identities to mislead devices, enabling ARP, MAC, IP, DHCP and DNS spoofing, evil-twin access points, and leading to DoS or MITM attacks.
Explore how DHCP spoofing tricks clients into accepting fake IP addresses, gateways, and DNS settings, enabling an adversary in the middle and traffic manipulation, demonstrated with Ettercap on Kali Linux.
Explore ARP cache poisoning in this demo, showing how an attacker poisons ARP cache entries to perform a man-in-the-middle attack, sometimes via gratuitous ARP, impersonating the gateway or DNS.
Explain how dns cache poisoning redirects users to spoofed sites by corrupting dns caches and explore vectors like arp cache poisoning and dhcp spoofing.
Learn how an evil twin spoofs a wireless access point to place an adversary in the middle between a victim and the network.
This course provides a comprehensive overview of cybersecurity threats, vulnerabilities, and attack methodologies, equipping learners with the knowledge to identify, analyze, and respond to adversarial tactics. We begin by exploring key concepts like threat terminology, attacker motivations, and reconnaissance techniques used to gather critical information. From there, we dive into attack methodologies, including the use of Tactics, Techniques, and Procedures (TTPs), frameworks like MITRE ATT&CK, and models such as the Cyber Kill Chain and Diamond Model of Intrusion Analysis. Through hands-on demos and exercises, learners will understand how adversaries weaponize malware, deliver attacks via social engineering, and exploit system weaknesses to gain access and maintain persistence.
The course further examines advanced attack vectors such as denial of service, spoofing, software vulnerabilities, authentication attacks, and stealth techniques used to evade detection. Learners will develop skills to recognize indicators of compromise (IoCs), analyze unusual system behaviors, and understand attack patterns and signatures. Emphasizing practical tools and demonstrations—including network scanning, password cracking, and intrusion detection—this course prepares participants to anticipate, detect, and defend against evolving cyber threats effectively.
Key components of the course include:
Define key threat and risk-related terms
Identify and describe the primary categories of hackers (white hat, gray hat, black hat) and explain their ethical boundaries
Recognize the different characteristics that define adversaries in the cybersecurity landscape, such as motivations, resources, sponsorship, and levels of sophistications
Explain the risks posed by insider threats and shadow IT and how these internal risks differ from external threats
Explain how cyber attacks are planned and carried out.
Describe Tactics, Techniques, and Procedures (TTPs) and how they reveal attacker behavior
Understand the MITRE ATT&CK framework and how it organizes attack tactics and techniques
List the steps of the Cyber Kill Chain and how it helps defend against attacks
Describe the Diamond Model of Intrusion Analysis and how it helps analyze attacks
Define what attack patterns and signatures are and how they are used to identify adversaries
Explain the purpose of reconnaissance and how attackers gather information
Describe OSINT techniques, including DNS and website reconnaissance, social media scraping, eavesdropping, and dumpster diving
Define an attack surface and how it’s analyzed to find an attack vector and vulnerabilities that will be used during an attack
Explain the concept of weaponization in cyber attacks and the role of brokers in malware distribution
Identify common types of malware, including viruses, worms, trojans, ransomware, spyware, Command and Control (C2), Remote Access Trojans (RATs), botnets, and fileless malware
Discuss enterprise-level concerns related to malware and strategies for mitigation
Explain the role of social engineering in cyber attack delivery and how trust is developed with targets
Identify and describe common social engineering methods and tactics, including impersonation, phishing variants, and physical techniques like tailgating
Recognize advanced delivery techniques such as typosquatting, domain shadowing, and business email compromise (BEC)
Understand the impact of emerging tools, including AI, on social engineering attacks
Identify common vulnerabilities across networks, protocols, hardware, software, virtualization, cloud, cryptography, humans, passwords, processes, and physical security
Explain how different vulnerabilities can be exploited individually or combined through exploit chaining
Describe techniques for network discovery, reconnaissance, and enumeration, including both wired and wireless methods
Perform basic network scanning and fingerprinting using tools like Nmap and Wireshark
Explain wiretapping and sniffing attacks and how they are used to capture network data
Understand credential harvesting and vulnerability scanning as part of the attack lifecycle
Explain the concepts of Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks and their impact on network availability
Identify various types of DoS attacks, including jamming, buffer overflow, ping of death, and TCP reset attacks.
Describe network flooding attacks such as ping flood, TCP SYN flood, UDP flood, DNS flood, amplification, and reflected attacks.
Demonstrate understanding of Wi-Fi deauthentication, DHCP starvation, and rogue DHCP attacks
Understand the mechanics behind broadcast storms, directed broadcasts, and smurf attacks
Explain what Adversary-in-the-Middle (AitM) and replay attacks are, including their impact on communications
Identify various spoofing attacks, including DHCP spoofing, ARP cache poisoning, DNS cache poisoning, and evil twin attacks
Understand how these attacks manipulate network traffic and deceive systems or users
Identify common software vulnerabilities using frameworks like Common Weakness Enumeration (CWE) and OWASP Top 10.
Explain different types of software attacks, including race conditions, deserialization, buffer overflow, path traversal, injection attacks, and cross-site scripting (XSS)
Identify common authentication and credential-based attacks such as password attacks, credential replay, and MFA fatigue.
Explain advanced access attacks including pass-the-hash, session hijacking, privilege escalation, and compromised key attacks
Describe exploitation techniques like jailbreaking, sideloading, trust exploits, and request forgery attacks (CSRF, SSRF)
Recognize physical attack vectors related to authentication and access control
Explain password hashing and the importance of salting to protect stored passwords
Demonstrate various password cracking methods, including brute-force, dictionary, mask attacks, and password spraying
Understand advanced cracking tools like hashcat and hydra used for account compromise
Recognize attacks such as rainbow tables, credential stuffing, and their impact on security
Explain common stealth techniques used by attackers, including encryption, tunneling, and obfuscation
Describe traffic manipulation methods such as traffic fragmentation and DNS tunneling
Identify network evasion tools like proxies, fast-flux, double-flux, and domain-flux
Understand how Domain Generation Algorithms (DGA) enable persistent and evasive communications
Identify common indicators of compromise (IoCs), including alerts, logs, and signs of removed evidence or disabled defenses
Recognize behavioral signs such as resource consumption issues, system crashes, and strange communications
Detect suspicious activities like data exfiltration, rogue devices, scans, beaconing, and unauthorized changes
Understand account anomalies including lockouts, new accounts, concurrent sessions, and impossible travel
Analyze other unusual system behaviors that may indicate a security breach
Who Should Take this Course:
Those getting into IT
Those wanting to advance their ethical hacking skills
Those going after a certification in
CompTIA Security+
CompTIA CySA+
CompTIA Pentest+
CompTIA SecurityX
ISC2 CISSP
Cisco CBROPS
Why take the course from me?
Experience: I’ve been in the IT world since 2000, have a masters in computers, and over 20 industry standard certifications
Know how to Teach: I was trained as an instructor by the USAF, have a bachelors in education, teaching since 1997, and well over 6,000 hours of classroom instruction time.
I’ve been a hiring manager since 2010, I know what skill sets employers are looking for.
TechKnowSurge’s Unique Approach
Your instructor has training and years of experience as an educator, as a technician, and as a leader. The course implements the following features:
Microstep lectures and segmented videos that meters learning into bite size chunks. It also makes it easy to go back and review concepts when needed.
Staged-Based Educational Model where information is covered multiple times in increasing amounts of complexity. The approach helps reinforce learning and creates a knowledge and skill set less likely to fade with time.
Extensive coverage of topics to make sure topics are explained fully
Well-organized content. A tremendous amount of effort has been placed on what order content should be delivered to maximize learning and minimizing confusion.
A focus on pedagogy. A funny name, but your instructor has a deep understanding of educational theory and what drives learning.
Module overviews explaining what to expect for each module and sets a mindset for why the information is important to learn.
Video intros, overviews, and summaries to explain the intention of each video, reinforce learning, and prepare you for success.
High quality and engaging videos that use graphics, great explanations, and analogies to explain complex topics in an easy to understand way.
Real world application. Step beyond just the theory. Your instructor has real world experience and will share that with you throughout the course.
Employer insight, know what employers are looking for. Your instructor runs IT Departments and hires individuals just like you.
This well organized course will has the following modules:
Welcome and Getting Started: Prepare yourself for efficiently and successfully completing the course. You’ll get an overview of what the course is all about and what you should expect out of it.
Knowing the Adversary: This module introduces key cybersecurity concepts related to threats and adversaries. We explore essential terminology, understand attacker motivations, and examine the characteristics, resources, and objectives of various adversaries. Topics include inside threats and shadow IT, helping learners grasp the landscape of cyber threats and the factors driving attacker behavior.
Attack Methodologies: This module covers how adversaries plan and execute cyber attacks using various tactics, techniques, and procedures (TTPs). Learners explore frameworks such as MITRE ATT&CK and models like the Cyber Kill Chain and Diamond Model of Intrusion Analysis. Through practical exercises, students learn to identify attack patterns and adversary signatures, enhancing their ability to anticipate and respond to threats.
Reconnaissance and Attack Planning: Focusing on the information-gathering phase of attacks, this module covers open-source intelligence (OSINT), DNS and website reconnaissance, social media scraping, and physical tactics such as dumpster diving and eavesdropping. Learners will understand attack surfaces and how vulnerabilities are discovered through various vectors.
Weaponization and Malware: This module examines how attackers create and deploy malware as weapons in cyber attacks. It covers a wide range of malware types, including viruses, worms, trojans, ransomware, spyware, and advanced threats like fileless malware and botnets. The role of brokers in malware distribution and enterprise-level concerns are also explored.
Delivery and Social Engineering: In this module, learners study how attackers deliver malicious payloads using social engineering techniques. Topics include phishing, impersonation, business email compromise, and physical attack vectors such as tailgating and USB drops. The impact of emerging technologies like AI on social engineering tactics is also examined.
Exploitation and Vulnerabilities: This module identifies common vulnerabilities across networks, protocols, hardware, software, virtualization, cloud environments, cryptography, humans, passwords, processes, and physical security. It explains how attackers exploit these vulnerabilities—often chaining exploits to maximize impact—and covers typical attacks used to compromise systems.
Persistence and Discovery: Learners will explore techniques for network discovery, enumeration, and reconnaissance on both wired and wireless networks. This module includes hands-on demonstrations with tools such as Nmap and Wireshark, and covers attacks like wiretapping, sniffing, credential harvesting, and vulnerability scanning.
Denial of Service (DoS) Attacks: This module explains the concepts and impact of DoS and DDoS attacks. Students learn about various attack types, including jamming, buffer overflow, ping of death, and flooding attacks like TCP SYN flood and amplification. Demonstrations highlight attacks such as Wi-Fi deauthentication and DHCP starvation.
AitM and Spoofing Attacks: Focusing on interception and deception techniques, this module covers AitM, replay attacks, and spoofing attacks such as DHCP spoofing, ARP cache poisoning, DNS cache poisoning, and evil twin attacks. Learners gain insight into how these attacks manipulate network traffic to breach security.
Common Application Attacks: This module reviews common software weaknesses using the Common Weakness Enumeration (CWE) and OWASP Top 10 frameworks. Learners explore attacks like race conditions, deserialization, buffer overflows, path traversal, injection attacks, SQL injection, and cross-site scripting (XSS) through demonstrations and practical examples.
Common Access Attacks: Students examine attacks targeting authentication systems, including password and credential attacks, MFA fatigue, pass-the-hash, session hijacking, privilege escalation, jailbreaking, sideloading, and various request forgery attacks. The module also discusses physical attack vectors compromising access controls.
Password Cracking: This module covers how passwords are protected and attacked. Learners will explore password hashing, salting, and cracking methods such as brute-force, dictionary, mask attacks, and password spraying. Tools like hashcat and hydra are demonstrated alongside attacks including rainbow tables and credential stuffing.
Stealth Techniques: Students will learn about stealth techniques attackers use to avoid detection, including encryption, tunneling, obfuscation, traffic fragmentation, and DNS tunneling. The module also covers evasion tools like proxies, fast-flux, double-flux, domain-flux, and domain generation algorithms (DGA) for persistent communications.
Indicators of Compromise (IoC): This module teaches how to recognize indicators of compromise (IoCs), such as alerts, logs, removed evidence, and disabled defenses. It also covers behavioral signs like resource consumption, system crashes, strange communications, rogue devices, unauthorized account activity, and other suspicious behaviors indicating a breach.
Wrap Up: Time to wrap up the course and provide any final thoughts.
Instructor Bio
TechKnowSurge (Andrew Grimes) has been in the tech industry since 2000 and even longer as an Instructor. He started out as a Survival Instructor for the United States Air Force (USAF) in 1997. When he got out of the military, he started teaching computer classes. Wanting to advance his technical skills, he became a contractor working on a wide range of technologies while teaching technology college courses in the evening. Overtime, he became a hiring manager, director, and leader
His background includes:
Building a security program within 2 years to include becoming SOC 2 Type 2 compliant
Leading and maximizing efficiency of IT, Security, and DevOps teams
Managing SaaS company infrastructure with millions of active users
Managing small, medium, and large IT Infrastructures
Migrating technologies to the cloud
Managing multi-million dollar budgets and reducing overall budget spend year over year
Utilizing various project management techniques such as waterfall, scrum and Kanban to maximize efficiency and success
Bachelors in Workforce Education
Masters in Computer Resource and Information Management
Over 6,000 hours of teaching experience
Over 20 industry standard certifications.
Past student reviews:
“Andrew is absolutely the best instructor I've had throughout the course of my education. He is extremely knowledgeable when it comes to all things network and IT-related. Because of the education he provided, I am now working in the network engineering field, and I could not have done it without his expert guidance.” ~Michael B.
“Andrew was hands down my favorite instructor since enrolling” “He has great skills as an instructor, and I've learned a lot from his classes.” ~Jeff S.
“As an instructor, he is thorough, articulate, patient and positive. He genuinely cares that his students fully comprehend the curriculum. I have a great deal of respect for Andrew. I can't recommend him highly enough.” ~Dan H.
“I found Andrew to be one of the best Instructors” “He presents the information with real world applications, which helped to reinforce the concepts presented in the Cisco Certification track.” “I am truely thankful to have had him as my teacher.” ~Dan M.
“Andrew is very knowledgeable and brings his practical business experience with him. He expresses himself very well and treats everyone with respect. He explains very complicated concepts in a manner that is easy to understand.” “It is without reservation that I would recommend Andrew as a business professional and/or teacher.” ~Adam C.
“Andrew is an excellent instructor and more.” “Andrew is the kind of teacher that you never forget.” ~ William C.
“Andrew Grimes is a first rate instructor who genuinely cares about the success of his students. I was fortunate to have Andrew as my instructor.” “I highly recommend Andrew as an instructor and IT professional.” ~Paul C.
“Andrew is a great instructor who really cares whether his students grasp the concepts he teaches. He has a passion for teaching that many couldn't muster.” ~Patrick R.
“He was a great teacher and I would gladly take a class under him again.” ~Joshua R.
“...his style of teaching is accommodating for any level, that a student is starting off at, either beginning or advance in IT world.” ~Paul W.
“He fosters a multidimensional environment of learning in which students of diverse abilities excel.” ~Mark B
“Andrew Grimes was a great Data Networks and Telecommunications Instructor.” “I would highly recommend him to any who desires to further their education.” ~ Tommy S.