دوره Applied Purple Teaming w/ Kent Ickler and Jordan Drysdale

You’ve heard this story before. Bad actor walks into a network and pillages the place in swift action. CIO asks: “Where did we go wrong?” SysAdmin replies “our password, remote access, workstation restriction, and lack of application safelisting policies. Oh, and our SIEM didn’t notify us. We just weren’t ready for that attack.”

In a significant change from the original course, students will be introduced to Microsoft Azure and Sentinel. Each student will be responsible for deploying a cloud lab that includes an Active Directory domain, a C2 server, and integration with AZ Sentinel’s detection platform. All of this will be taught through a proven framework for purple team operations that results in better business outcomes.

Syllabus

  1. Organizational reconnaissance
  2. Bloodhound, Sharphound and Neo4j
  3. Plumhound
  4. Group policy preferences
  5. Command and control operations
  6. Canary accounts for detecting password sprays and Kerberoasting
  7. File share poisoning via URL and LNK files
  8. Pass the hash attacks
  9. DCSync operations
  10. Password cracking with John the Ripper
  11. Kerberoasting attacks
  12. Atomic Red Team

Applied Purple Teaming w/ Kent Ickler and Jordan Drysdale