Table of Contents

This course follows a red-team mission from an approved question to a reviewable result. Each module connects a technique to identity, scope, evidence, and recovery. The sequence develops from definitions and explanations into bounded actions, comparisons, decisions, and reader-created records.

Use the material only in an environment you are authorized to test. Treat every example as a lab exercise unless the engagement rules say otherwise.

What You Will Learn

The course is a loop of objective, preparation, observation, access, analysis, cleanup, backout, and reporting. New evidence can change the objective or next action, so the modules teach records that survive a change in plan.

StageReader outcome
PrepareScope, roles, infrastructure, and stopping conditions
UnderstandNetwork, Windows, identity, and protocol behavior
ObserveOSINT, scanning, host state, and service evidence
AccessDelivery, execution, persistence, and privilege boundaries
Expand carefullyKerberos, movement, trusts, and LDAP scope
Clean up and back outRemove owned artifacts, restore changes, and verify the baseline
ReportObjective, evidence, impact, remediation, and retest

Course Modules

#ModuleReader artifact
1Red Team MethodologyObjective and evidence review loop
2Mission Preparation and InfrastructureReadiness and responsibility register
3Networking and Active DirectoryDependency and access map
4Windows Internals and AuthenticationIdentity, token, and registry context record
5Command and Control OperationsTask delivery and result ledger
6Beacon Execution and BOFsCompatibility and failure record
7Malleable C2 and Communication EvasionControlled traffic comparison
8Open-Source IntelligenceProvenance and research brief
9Active Reconnaissance and ScanningScan manifest and response interpretation
10Initial Access: Phishing and DeliveryDelivery and interaction test specification
11Situational Awareness and Host OperationsHost-state snapshot
12User PersistenceStartup lifecycle record
13Local Privilege EscalationPermission-boundary evidence chain
14Privileged Persistence and Process MigrationService and process lifecycle record
15Persistence Cleanup and Defense EvasionRestoration and backout ledger
16Domain Privilege Escalation and Kerberos AbuseTicket and privilege review
17Lateral Movement and Expanding AccessMovement path ledger
18Cross-Domain Pivoting and LDAP EnumerationTrust and query decision record
19Fortifying Access and Operator DisciplineAccess and failover plan
20Mission Objectives and ReportingMission finding package

How To Use It

Start with Module 1: Red Team Methodology . Read each module’s terms and explanation before attempting its lab action. The worked example then shows how to apply the idea, while the comparison and self-check sections ask you to judge evidence and limits.

Keep the reader artifact from each module. The next module uses it as an input, so the course becomes a connected assessment record instead of twenty unrelated command lists. When a module describes an expected result, label it as expected until your authorized lab produces an observation.

Prerequisites

Use a disposable lab with a Windows domain controller, Windows workstations, and a Linux analysis host. Keep an engagement document that names the assets, identities, time window, data handling rules, owner contacts, and stop conditions. Several commands are Windows-specific and are documented rather than executed on the macOS authoring system.

The course does not grant permission to test a real system. Obtain written authorization and use the smallest scope that answers the mission question.

After Module 20

Review the CompTIA PenTest+ Course and Certified Ethical Hacker Course for related study. Reuse the mission finding package when you design a new approved exercise, then update the evidence and retest fields with observed results.