Visão Geral
Este curso apresenta os fundamentos de operações de Red Team, com foco em simulação controlada de adversários, planejamento de campanhas, reconhecimento, obtenção de acesso, movimentação, persistência, evasão, objetivos de missão e avaliação da capacidade defensiva.
Conteúdo Programatico
Module 1: Red Team Fundamentals
- Red Team concepts
- Adversary simulation
- Threat emulation
- Objectives and mission planning
- Rules of engagement
- Operational security
- Attack lifecycle
- Adversary behavior
- Detection-aware operations
- Red Team governance
Module 2: Reconnaissance and Target Discovery
- Passive reconnaissance
- Active reconnaissance
- OSINT
- Attack surface discovery
- Network mapping
- Identity discovery
- Technology fingerprinting
- External attack surface
- Internal reconnaissance
- Target prioritization
Module 3: Initial Access
- Initial Access concepts
- Phishing simulation
- Public-facing applications
- Valid account abuse
- External attack paths
- Credential-based access
- Initial foothold assessment
- Access validation
- Detection opportunities
- Initial access documentation
Module 4: Active Directory Operations
- Active Directory reconnaissance
- Identity enumeration
- Privileged account discovery
- Credential Access
- Kerberos attack concepts
- NTLM attack concepts
- Privilege escalation
- Lateral Movement
- Domain compromise paths
- Active Directory threat emulation
Module 5: Command and Control
- Command and Control concepts
- C2 architecture
- Communication channels
- Network-based detection
- Endpoint-based detection
- C2 infrastructure security
- Operational security
- Beaconing concepts
- Detection-aware C2
- C2 monitoring
Module 6: Defense Evasion and Persistence
- Defense Evasion concepts
- Detection surface
- Security control analysis
- Persistence concepts
- Privileged persistence
- Authentication persistence
- Endpoint security controls
- EDR considerations
- Detection engineering
- Defensive validation
Module 7: Lateral Movement and Objectives
- Lateral Movement
- Credential reuse
- Remote administration
- Privilege escalation
- Internal reconnaissance
- Target identification
- Mission objectives
- Data access simulation
- Objective completion
- Attack path documentation
Module 8: Red Team Campaign Execution
- Campaign planning
- Attack chain development
- Operational coordination
- Detection monitoring
- Blue Team interaction
- Evidence collection
- Attack timeline
- Defensive control assessment
- Lessons learned
- Red Team campaign case study