
Understand red teaming: a hacker-like testing method that simulates cyber attacks to reveal weaknesses, improve incident response, and strengthen defenses through red and blue team dynamics.
Configure the external network in a two-vlan VMware lab, assign static IPs for vlan one and vlan two, and verify Kali on vlan one can reach the metasploitable web server.
Set up the internal network in VMware by configuring VLAN two on the domain controller, employee machine, and application server; assign static IP and DNS, and enable remote access.
Set up Active Directory on a domain controller, promote to a new forest with a root domain, join employee machines and application server to the domain, and create domain users.
Reconnaissance gathers information about a target system, network, or organization to understand its structure and identify vulnerabilities, using publicly available data to map risks and strengthen defenses.
Distinguish passive and active recon: passive uses public data to stay undetected with no direct interaction, while active engages targets with ping and port scans for deeper insights.
Identify live hosts on a network using ARP and ICMP, then verify with ping, by scanning a /24 subnet with Net Discover.
Use nmap to scan a target for open ports and services, reveal ftp on port 21 with Vsftpd 2.3.4, and run scripts to detect the backdoor vulnerability.
Explore attacking a web server by exploiting a Vsftpd backdoor on port 21 using Metasploit, gaining a root shell and escalating to interactive command execution.
Learn how attackers exploit WebDAV on vulnerable servers to upload a reversal script. Set up a netcat listener to catch the reversal and verify access from the target Metasploitable machine.
Learn how pivoting enables ethical hackers to move from an external network to an internal one using a compromised system, routing traffic with proxy chains to access internal machines.
Learn to enumerate an internal network with Powerview in a Windows environment, listing users, groups, and computers, and identify risks from passwords stored in descriptions.
Download : https://learn.microsoft.com/en-us/sysinternals/downloads/psexec
https://github.com/gentilkiwi/mimikatz
Are you ready to master advanced offensive security? This course is designed to take you through the complete red teaming process, from setting up a lab to carrying out real-world attacks.
You’ll learn how to:
Set up a virtual lab environment with internal and external networks.
Conduct effective reconnaissance and gather valuable information about your targets.
Exploit vulnerabilities in networks, systems, and web servers.
Use advanced tools and techniques for post-exploitation and lateral movement.
Understand how Active Directory works and how attackers exploit it.
The course includes detailed explanations of red team tactics, methods to bypass security defenses, and approaches for stealth operations. Through hands-on labs and step-by-step guides, you’ll gain the ability to think critically, solve problems, and adapt to new challenges.
This course is for beginners and professionals who want to improve their skills in ethical hacking and red teaming. No prior experience in red teaming is required. Just bring your passion for cybersecurity and a computer capable of running virtual machines!
With step-by-step instructions, practical labs, and hands-on exercises, you’ll gain the knowledge and skills to think like an attacker and protect against real-world threats. Enroll now and start your journey toward becoming a red team expert!