Adversary Ops: Infrastructure Edition

This is our 4-day Advanced-level infrastructure hacking course.

Our Advanced Infrastructure Edition course is designed for those who wish to push their knowledge. Whether you are Pen Testing, Red Teaming or trying to get a better understanding of managing vulnerabilities in your environment, understanding advanced hacking techniques is critical.


Fast track available


4 day practical class


Available by Partners


Live, online available


Hack-Lab for 30 days


Advanced

Course Overview

Adversary Ops: Infrastructure Edition is a 4-day advanced training course designed for penetration testers, red teamers, and security professionals who want to develop their infrastructure security testing capabilities.

The course builds on our established Advanced Infrastructure Hacking training and incorporates significant updates to reflect modern enterprise environments and offensive security techniques. Delegates will gain practical experience across Windows, Linux, Active Directory, network infrastructure, CI/CD, cloud, and container technologies, with an increased emphasis on combining techniques to understand realistic attack paths.

Through hands-on exercises in our enterprise Hacklab, participants will explore advanced exploitation, privilege escalation, lateral movement, and post-exploitation techniques. The updated training also introduces AI-assisted reconnaissance and attack-path analysis, alongside operational security and defence-evasion considerations where relevant.

The course is designed to help delegates strengthen their technical skills, understand how weaknesses can be chained across infrastructure, and apply that knowledge to more effective security testing and remediation.

Interested

Interested?

1. Our courses are available directly from us; through our training partners or at worldwide technical conferences.

2. You can find course dates and prices on the Courses and Webinars page.
Click here for course dates, prices and content

3. Take a look below at a few of the upcoming courses for this specific training.

4. For more information including private course requests, complete the short form below.

Courses and webinars

Sorry, there are no specific public courses for this module in the immediate future. Please come back later as we are adding them all the time, view all our courses or check with one of our partners.

All upcoming courses

Booking enquiries

Select the course from the Courses and Webinars Page.

Click here for course dates and prices

For private course delivery enquiries or other information, please use the form alongside.

The course is also available from our partners listed below.


QA training

For security and IT decision makers

What’s the real impact of training your team through NotSoSecure?

Harden your organisation’s infrastructure and make it a less attractive target for attackers by building a team that can identify, test, and recommend remediations for vulnerabilities and misconfigurations throughout your environments. Trained delegates can:

  • Perform security testing that uses complex attack chaining across Windows (local), Active Directory, Linux, and common cloud environments.
  • Design this testing around real-world attacker behaviour and tooling to ensure its relevance to the threats facing your organisation.
  • Identify misconfigurations from network level to system level.
  • Understand the business impact of misconfigurations and vulnerabilities and articulate this to key stakeholders.
  • Implement logging and monitoring processes to detect live attacks.
  • Take on greater responsibility in the team and become an advocate of security in the wider business.

Course Details

Who is it for?

  • Penetration testers and red teamers
  • Security consultants and architects
  • Network admins with security experience
  • CSIRT/SOC teams/blue teamers
  • Security/IT managers and team leads
  • This course is suitable for in-house security teams from intermediate to pro-level. It’s also relevant to other security and IT practitioners and managers who want to understand the current threat landscape and defend their organization.

    Delegates must have the following to make the most of the course:

    • Intermediate knowledge of infrastructure application security (at least 2 years’ experience)
    • Common command line syntax competency
    • Experience using virtual labs for pentesting and/or offensive research

    Top 3 Takeaways

    • Many of the latest and most complex infrastructure testing techniques
    • Hacks to use against your organization’s own products
    • Knowledge of how to remediate as well as attack weaknesses in infrastructure

    What You Will Learn

    This course uses a Defence by Offence methodology based on real world engagements and offensive research (not theory). That means everything we teach has been tried and tested on live environments and in our labs, so you can put it into practice as soon as the training is over. By the end of the course, you’ll know:

    • How to think and behave like an advanced, real world threat actor
    • How to identify commonly used vulnerabilities known to have recently caused damage and disruption
    • How to deploy the latest and most common network infrastructure and cloud hacks, (including many novel techniques that can’t be detected by scanners)
    • How to analyze vulnerabilities within your own organization and customize your hacking techniques in response
    • A huge menu of hacks for Windows, Linux, Microsoft Azure, AWS, Google Cloud Platform (GCP), software development systems, and more...

    What You Will be Doing

    You’ll be learning hands on:

    • Spending most of the session (~80%) on lab-based exercises
    • Using lab-based flows to explore and hack lifelike web application environments
    • Discussing the impact of the hacks covered with your course trainer

    Why it is Relevant

    As different on-premises and cloud environments shapeshift and converge, the practice of infrastructure security is becoming more complex. Organisations and their security teams can no longer afford to understand the overarching attack surface at a high level. Nor can they rely on the same security practices that worked in the past. What’s needed is a thorough, contextual understanding of how and why your architecture and systems get targeted by threat actors, which are at risk, and what happens when those attacks succeed. Our Adversary Ops: Infrastructure Edition course provides delegates with this knowledge and more, by giving them an up-to-date arsenal of advanced offensive testing and remediation skills.

    Our syllabuses are revised regularly to reflect the latest in-the-wild hacks and whatever proof of concepts we’ve been developing through our own research. Because they remain so up to date with the threat landscape and security industry standard, many delegates return every 1-2 years to update their skills and get a refresh.

    Details of the course content:

    Note: Our syllabuses are subject to change based on new vulnerabilities found and exploits released.

    RECONNAISSANCE & PERIMETER COMPROMISE

    • Advanced OSINT and organization foot printing
    • Attack surface mapping and asset identification
    • Exploiting vulnerable VPN appliances
    • Configuration extraction and credential recovery
    • Credential stuffing and external service abuse
    • IPv4/IPv6 service discovery and enumeration
    • AI-Assisted Reconnaissance & Attack-Path Analysis

    INTERNAL NETWORK PIVOTING (LINUX)

    • Linux attack surface enumeration and misconfigurations
    • Kerberos authentication
    • Restricted shells breakouts
    • SSH-based access and lateral escalation
    • Breaking hardened web servers
    • Local privilege escalation (SUID/SGID, PAM, sudo, kernel)
    • Persistence techniques (Linux Capabilities)
    • Pivoting via SSH tunneling and internal service access

    CONTAINER BREAKOUT

    • Breaking and abusing Docker
    • Breaking out of Kubernetes containers

    LATERAL MOVEMENT AND PIVOTING

    • Persistence techniques and credential harvesting
    • Pivoting via SSH tunneling and internal service access

    CROSS-NETWORK PIVOTING

    • VLAN segmentation bypass and VLAN hopping techniques
    • Switch spoofing and double tagging attacks
    • Network reconnaissance (CDP/LLDP, routing visibility)
    • CI/CD pipeline compromise and pipeline poisoning
    • Supply chain and dependency confusion attacks
    • Database exploitation (MSSQL/PostgreSQL)
    • Observability platform compromise and credential extraction

    IDENTITY COMPROMISE (WINDOWS)

    • Windows enumeration and policy/restriction analysis
    • RDP-based access and desktop/kiosk breakouts
    • AppLocker bypass and proxied execution
    • Offensive PowerShell /Offsec Development
    • AMSI bypass Techniques
    • AV Evasion Techniques
    • OPSEC and defense evasion
    • Post-exploitation and persistence techniques
    • EDR-Aware Tradecraft & Operational Security
    • Adapting attack paths when defensive controls affect the operation
    • Evaluating the visibility and impact of offensive actions

    ENTERPRISE PIVOT & ACTIVE DIRECTORY EXPLOITATION

    • Active Directory delegation reviews and pwnage (Win 2022 Server)
    • Resource-based constrained delegation
    • ACL/ACE misconfigurations and shadow credentials
    • Kerberos attacks (Kerberoasting, AS-REP, Pass-the-Ticket)
    • Ticket forgery (Golden, Silver, Diamond)
    • OPSEC and defense evasion under detection constraints
    • Active Directory Certificate Services (AD CS) abuse
    • Cross domain and forest attacks
    • Pivoting and port forwarding across enterprise environments
    • Persistence and backdooring techniques (Golden and Diamond Ticket)

    CLOUD HACKING

    • AWS, MS Azure, and GCP specific attacks
    • Storage misconfigurations
    • Credentials, APIs, and token abuse
    • Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), Container as a Service (CaaS), and serverless exploitation
    • Azure AD attacks

What You Will Get

  • Certificate of completion
  • 30 days lab access post-course completion (with the opportunity to extend)
  • 8 Continuing Professional Education (CPE) credits awarded per day of training fulfilled
  • Learning pack, including Q&A sheets, setup documents, and command cheat sheets

Course Highlights

What Delegates Love:

  • Realistic Enterprise Hacklab: Train in a complex enterprise environment combining multi-domain Active Directory, segmented networks, CI/CD pipelines, and monitoring systems Exercises are designed to encourage attack chaining and operational decision-making rather than isolated exploitation.
  • Individual access: You’ll have your own infrastructure to play with, enabling you to hack at your own speed.
  • Real-world learning: Where many leading cybersecurity training courses are based on theory, our scenario-led, research-based approach ensures you learn how real threat actors think and act.
  • Specialist-led training: You’ll learn from highly skilled and experienced practicing penetration testers and red teamers.
  • Up-to-date content: Our syllabus remains so relevant that delegates come back year afteryear.
  • Remediations included: You’ll learn how to fix as well as find vulnerabilities.
  • Course topics: Defense Evasion, AD Constraint Delegation issues, and Cross-Network Pivoting Techniques often come out on top.

Outcomes for Budget Holders

This course is designed to bring your in-house cloud security testing competency up to industry standard, helping you to:

  • Harden your organisation’s infrastructure and lower the likelihood of security incidents by identifying high impact vulnerabilities across your infrastructure.
  • Improve the organization’s approach to access control management.
  • Create a stronger case for securing software development, cloud deployment, and governance practices.
  • Develop a secure cloud roadmap that balances growth and risk.
  • Implement cloud-based attack detection and response tactics.
  • Build a closer relationship between development and security teams
  • Internally pentest new tools and systems before making an investment.
  • Nurture and retain passionate, highly skilled, and security-conscious employees.
  • Demonstrate commitment to security through training, compliance, and change management.
  • Develop the organization’s competitive advantage for security-conscious customers.

Prerequisites

Who Should Take This Class?

System Administrators, SOC Analysts, Penetration Testers, Network Engineers, security enthusiasts and if you want to take your skills to next level.

While prior pen testing experience is not a strict requirement, familiarity with both Linux and Windows command line syntax will be greatly beneficial and a reasonable technical understanding of computers and networking in general is assumed. Some hands-on experience with tools commonly used by hackers, such as Nmap, NetCat, or Metasploit, will also be beneficial, although if you are a less advanced user, you can work your way up during the 30 days of complimentary lab access provided as part of the course.

The course is ideal if you are preparing for CREST CCT (ICE), CHECK (CTL), TIGER SST or other similar industry certifications, as well as if you perform Penetration Testing on infrastructure as a day job and wish to add to your existing skill set.

You will need:

The only requirement for this course is that you must bring your own laptop and have admin/root access on it. During the course, we will give you VPN access to our state-of-art Hack-lab which is hosted in our data-center in the UK. Once you are connected to the lab, you will find all the relevant tools/VMs there. We also provide a dedicated Kali VM to each attendee on the Hack-Lab, accessed using SSH. So, you don’t need to bring any VMs with you. All you need is admin access to install the VPN client and once connected, you are good to go!

As a delegate, you may optionally come prepared with an OpenVPN client (e.g. OpenVPN Client for Windows, we suggest Tunnelblick for Mac, the OpenVPN client is often included natively for Linux but may need installing/updating) and an SSH client (e.g. PuTTY for Windows, generally included natively for Linux/Mac) installed.

It is recommended that you complete one of the following courses before taking this course:

The Art of Hacking


Infrastructure Hacking

Infrastructure Edition

Course Information

You can download a copy of the course information below.

In addition you will also be provided with a student pack, handouts and cheat-sheets if appropriate.

Available in 4 day versions

4 Days Course

Your Training Roadmap

Offensive Classes

Hacking training for all levels: new to advanced. Ideal for those preparing for certifications such as CREST CCT (ICE), CREST CCT (ACE), CHECK (CTL), TIGER SST as well as infrastructure / web application penetration testers wishing to add to their existing skill set.

Defensive Classes

Giving you the skills needed to get ahead and secure your business by design. We specialise in application security (both secure coding and building security testing into your software development lifecycle) and cloud security. Build security capability into your teams enabling you to move fast and stay secure.