Red Team Operations

  • Course Duration18 HRS
  • Course LanguageEnglish

What you'll learn

  • Understand red teaming, adversary emulation, and the attack lifecycle
  • Map operations to the MITRE ATT&CK framework
  • Design and deploy resilient command-and-control (C2) infrastructure
  • Develop, obfuscate, and deliver payloads that evade antivirus and EDR
  • Plan and execute phishing campaigns for initial access
  • Escalate privileges on Windows and Linux systems
  • Attack Active Directory and achieve domain dominance
  • Move laterally and pivot through internal networks
  • Establish stealthy persistence and maintain access
  • Exfiltrate data while evading detection and logging
  • Collaborate with blue teams through purple teaming and reporting

Red teaming goes beyond traditional penetration testing — it emulates the tactics, techniques, and procedures of real-world adversaries to test not just an organisation's technology, but its people, processes, and ability to detect and respond. This advanced course takes you through the complete red team lifecycle, from building resilient attack infrastructure to achieving objectives while evading detection.

Across hands-on modules mapped to the MITRE ATT&CK framework, you will learn to design command-and-control infrastructure, develop and obfuscate payloads that bypass modern EDR, run phishing campaigns for initial access, escalate privileges, move laterally through Active Directory, establish stealthy persistence, and exfiltrate data over covert channels. Throughout, the focus is on operational security (OPSEC) and thinking like a real adversary.

By the end of this course, you will be able to plan and execute a full red team engagement, emulate advanced threat actors, collaborate with defenders through purple teaming, and deliver a professional report that improves an organisation's detection and response capabilities — making you effective on both sides of the fight.

Disclaimer: This course is intended strictly for educational and authorised security testing purposes. All techniques are performed within isolated lab environments or under explicit written authorisation. Unauthorised use of any technique taught in this course is illegal and strictly prohibited.

Course content

01Welcome to the Course2 lectures
  • Important Before You Start
  • Course Roadmap & Objectives
02Introduction to Red Teaming5 lectures
  • What Is Red Teaming?
  • Red Team vs Penetration Testing vs Purple Teaming
  • The Attack Lifecycle & Cyber Kill Chain
  • Introduction to MITRE ATT&CK
  • Rules of Engagement & Legal Considerations
03Red Team Infrastructure6 lectures
  • Designing Resilient C2 Infrastructure
  • Setting Up Command & Control Servers
  • Redirectors & Domain Fronting
  • Introduction to Cobalt Strike
  • Open-Source C2 Frameworks (Sliver, Mythic, Havoc)
  • Operational Security (OPSEC) Fundamentals
04Reconnaissance & OSINT5 lectures
  • Passive Reconnaissance
  • Open-Source Intelligence (OSINT) Gathering
  • Identifying the Attack Surface
  • Employee & Email Enumeration
  • Infrastructure & Domain Mapping
05Initial Access & Weaponization5 lectures
  • Phishing Campaign Development
  • Crafting Malicious Documents & Payloads
  • Payload Delivery Techniques
  • Exploiting External-Facing Services
  • Password Spraying & Credential Attacks
06Payload Development & Evasion5 lectures
  • Understanding Antivirus & EDR
  • Payload Obfuscation Techniques
  • Bypassing AMSI & Windows Defender
  • Process Injection Fundamentals
  • Shellcode Loaders & Packers
07Command & Control (C2)5 lectures
  • C2 Communication Channels
  • Beaconing & Sleep Obfuscation
  • Malleable C2 Profiles
  • Encrypted & Covert Channels
  • Managing Multiple Sessions
08Host Enumeration & Situational Awareness4 lectures
  • Enumerating the Compromised Host
  • Local Reconnaissance
  • Identifying Security Products
  • Credential Harvesting
09Privilege Escalation4 lectures
  • Windows Privilege Escalation
  • Linux Privilege Escalation
  • Abusing Misconfigurations
  • Token Impersonation & UAC Bypass
10Active Directory Attacks5 lectures
  • Domain Enumeration with BloodHound
  • Kerberoasting & AS-REP Roasting
  • Pass-the-Hash & Pass-the-Ticket
  • Delegation Abuse
  • Domain Dominance & DCSync
11Lateral Movement4 lectures
  • Lateral Movement Techniques
  • Remote Execution (WMI, WinRM, PsExec)
  • Pivoting & Tunneling
  • SOCKS Proxies & Port Forwarding
12Persistence4 lectures
  • Establishing Persistence Mechanisms
  • Registry & Scheduled Task Persistence
  • Service & WMI Persistence
  • Golden & Silver Tickets
13Defense Evasion & OPSEC4 lectures
  • Evading Detection & Logging
  • Bypassing EDR & Behavioral Analysis
  • Living-off-the-Land (LOLBins)
  • Anti-Forensics Techniques
14Data Exfiltration & Impact4 lectures
  • Identifying High-Value Targets
  • Data Collection & Staging
  • Exfiltration Over Covert Channels
  • Simulating Ransomware & Impact
15Purple Teaming & Detection4 lectures
  • Collaborating with the Blue Team
  • Mapping Attacks to MITRE ATT&CK
  • Detection Engineering Basics
  • Improving Defensive Coverage
16Reporting & Debrief4 lectures
  • Writing a Red Team Report
  • Attack Narrative & Storytelling
  • Actionable Recommendations
  • The Red Team Debrief

Requirements

  • A computer with at least 16GB RAM and virtualization support (32GB recommended)
  • Solid understanding of networking, Windows, and Linux fundamentals
  • Prior experience with penetration testing or ethical hacking is strongly recommended
  • A stable internet connection to download tools and lab resources

Who this course is for

  • Penetration testers looking to advance into red team operations
  • Red team operators who want to sharpen their tradecraft and OPSEC
  • SOC analysts and blue teamers who want to understand adversary tactics
  • Security professionals preparing for red team certifications
$250ENROLL NOW