Reconnaissance and Perimeter Compromise
- Advanced OSINT and organisation footprinting
- Attack surface mapping and asset identification
- Exploiting vulnerable VPN appliances
- Configuration extraction and credential recovery
- Credential stuffing and external service abuse
- IPv4/IPv6 service discovery and enumeration
Internal Network Pivoting (Linux)
- Linux attack surface enumeration and misconfigurations
- Kerberos authentication
- Restricted shells breakouts
- SSH-based access and lateral escalation
- Breaking hardened web servers
- Local privilege escalation (SUID/SGID, PAM, sudo, kernel)
- Persistence techniques (Linux Capabilities)
- Pivoting via SSH tunnelling and internal service access
Container Breakout
- Breaking and abusing Docker
- Breaking out of Kubernetes containers
Lateral Movement and Pivoting
- Persistence techniques and credential harvesting
- Pivoting via SSH tunnelling and internal service access
Cross-Network Pivoting
- VLAN segmentation bypass and VLAN hopping techniques
- Switch spoofing and double tagging attacks
- Network reconnaissance (CDP/LLDP, routing visibility)
- CI/CD pipeline compromise and pipeline poisoning
- Supply chain and dependency confusion attacks
- Database exploitation (MSSQL/PostgreSQL)
- Observability platform compromise and credential extraction
Identity Compromise (Windows)
- Windows enumeration and policy/restriction analysis
- RDP-based access and desktop/kiosk breakouts
- AppLocker bypass and proxied execution
- Offensive PowerShell and Offsec development
- AMSI bypass techniques
- AV evasion techniques
- OPSEC and defence evasion
- Post-exploitation and persistence techniques
Enterprise Pivot and Active Directory Exploitation
- Active Directory delegation reviews and exploitation (Windows 2022 Server)
- Resource-based constrained delegation
- ACL/ACE misconfigurations and shadow credentials
- Kerberos attacks (Kerberoasting, AS-REP, Pass-the-Ticket)
- Ticket forgery (Golden, Silver, Diamond)
- OPSEC and defence evasion under detection constraints
- Active Directory Certificate Services (AD CS) abuse
- Cross domain and forest attacks
- Pivoting and port forwarding across enterprise environments
- Persistence and backdooring techniques (Golden and Diamond Ticket)
Cloud Hacking
- AWS, Microsoft Azure, and GCP specific attacks
- Storage misconfigurations
- Credentials, APIs, and token abuse
- Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), Container as a Service (CaaS), and serverless exploitation
- Azure AD attacks
Exams and assessments
There is no formal exam for this course.
Hands-on learning
- Extensive lab-based exercises, making up approximately 80% of the course
- Individual access to virtual lab environments for practical hacking experience
- Scenario-led, research-based learning reflecting real-world threat actor behaviour
- 30 days of lab access post-course completion for continued practice