In this section

Offensive Security for Defenders: Course Orientation

Module 0
An attacker running a campaign through compromised hosts on the left, and a defender on the right turning each move into a detection that lights up, the same campaign read from both sides
OFFENSIVE SECURITY FOR DEFENDERS · MODULE 00
Think like an attacker. Detect like an expert.
An alert is one moment; the attacker ran a whole campaign around it, and most of that campaign is invisible because nobody built detection for it. This course teaches you the attacker's operation from the inside, planning, infrastructure, payloads, access, credentials, lateral movement, evasion, and objectives, so you can see where it touches your environment and build the detection there. You leave with campaign-level detection thinking and real TTPs translated into production Sentinel and Defender XDR detections. This module shows you what you'll learn to read, what you'll build, and how the course gets you there.
12 modules
plus an operations cheatsheet
Campaign-level
detection thinking
Production
Sentinel + Defender detections
No prerequisites
every concept built up

Why this course exists

Defenders see alerts. Attackers run campaigns. The difference is the whole problem. An alert is a single event torn out of context, a flagged sign-in, a blocked attachment, while the operation around it, the recon that picked the target, the infrastructure that was built and burned, the payload engineered to slip the controls, the credentials taken, the quiet movement between hosts, the evasion that kept it off the radar, mostly never surfaces, because no detection was ever written for it. You cannot detect what you do not understand, and you cannot understand the attacker by reading defensive documentation.

So this course teaches the campaign from the attacker's side. You follow how operations are planned, how infrastructure and payloads are built, how initial access decisions are made, what happens in the first thirty minutes, how credentials and lateral movement actually work, and how skilled adversaries evade defenses, using the same offensive tooling that generates the real telemetry. Then you do the defender's job with that understanding: read where the campaign touches the estate and build detection at each stage. That is the point of thinking like an attacker, it is the only way to detect like an expert, and it is what turns a stream of disconnected alerts into a campaign you can see and stop.

Detect where it hurts the attacker most TTPs Tools Host and network artifacts Domain names IP addresses Hash values hardest to change trivial to change The Pyramid of Pain: detect an attacker's behavior, not their disposable artifacts. This course aims at the top.

What you will be able to do

This course is built around the campaign you can read and detect at the end, not the techniques you can name. Every module works one stage of the operation and turns it into detection.

Read the campaign, not the alert
Connect isolated events into the operation behind them, and think at the level of the attacker's whole plan.
Understand how operations are built
Follow how attackers plan, stand up and burn infrastructure, and engineer payloads and delivery to beat your controls.
Map the intrusion from access onward
Work the initial-access decision tree and the first thirty minutes of post-compromise activity as the attacker experiences them.
Follow credentials and movement
Trace credential operations and lateral movement as the operational maneuver they are, and detect each step.
See through defense evasion
Understand operational-level evasion and the objectives, data theft, ransomware, espionage, sabotage, it serves.
Turn TTPs into detections
Reconstruct a full campaign and build threat-informed, production Sentinel and Defender XDR detections from real TTPs.

You also leave with things you keep: production Sentinel and Defender XDR detections built from real attacker TTPs, a full campaign reconstruction, and the offensive-operations cheatsheet.

From where you start to where you finish You see alerts, not the campaign behind them How attackers plan and build Access, credentials, movement Evasion, objectives, reconstruction You read the whole campaign and detect it at every stage

The campaign you will learn to read

Every campaign moves through the same arc: reconnaissance, initial access, execution, credential operations, lateral movement, defense evasion, and the objective the attacker came for. Seen from the defender's chair those are scattered alerts; seen as one operation they are a chain, and a chain can be detected link by link. This course walks that arc from the attacker's side using the tooling that produces the real telemetry, then builds detection at each stage, so you finish able to recognize the operation while it is still running, not after the objective is met.

The attacker campaign lifecycle, recon, initial access, execution, credentials, lateral movement, evasion, and objectives, with detection built at each stage

You work this against Northgate Engineering, 810 users on Defender XDR and Sentinel, using offensive tooling like Sliver and Evilginx to generate the telemetry you then learn to detect, with AI-assisted analysis to accelerate the reconstruction. The discipline is what carries: the attacker's perspective, campaign-level thinking, and threat-informed detection work against any adversary on any platform, so what you learn here applies well beyond one stack. Sentinel and Defender XDR are where you build the detections; reading the campaign is the skill.

How the course is built

Twelve modules move through two phases, then the cheatsheet. You ground offensive thinking and how attackers plan, then walk the entire campaign lifecycle from infrastructure to objectives and on to reconstruction and threat-informed defense, building detection as you go.

PHASE 1 Offensive Foundations Modules 0 to 1: why defenders need offensive thinking, and how attackers plan operations PHASE 2 The Campaign Lifecycle Modules 2 to 11: infrastructure, payloads, initial access, post-compromise, credentials, lateral movement, evasion, objectives, campaign reconstruction, and threat-informed defense RESOURCES Offensive operations cheatsheet

What you need and who this is for

There are no prerequisites, and every concept is explained the first time it appears. This course is for defenders who want to stop guessing at what attackers do: SOC analysts and detection engineers who need to close the gaps, threat hunters chasing campaigns rather than indicators, incident responders reconstructing what happened, and anyone curious about the offensive side who wants that understanding to make them a better defender.

Offense in service of defense
Every offensive technique is taught to be detected, not deployed. The goal throughout is a better detection, never an attack.
Transferable adversary thinking
Campaign-level, threat-informed detection works against any adversary on any SIEM and EDR. Sentinel and Defender are the implementation; reading the campaign is the skill.
How to get the most
For each stage, ask what telemetry it leaves and write the detection before moving on. Keep the detections that fire cleanly, that is how your production rule set gets built.

Do I already know this material?

Six quick scenarios across the full range of this course, from why defenders study offense to threat-informed defense. Answer them to find out where you sit, and whether this course fits or it will sharpen knowledge you already have.

Why does a defender study offensive tradecraft?

To carry out attacks against other organisations.
To anticipate how a real attacker thinks and moves, so detections and defenses target the choices and chokepoints attackers actually rely on.
You defend what you understand. Knowing how an operator plans, moves, and decides lets you put controls and detections where the attacker has to pass, rather than spreading effort evenly across everything.
Because offense is simply more interesting than defense.
It has no real defensive value.

Attackers build, stage, and burn infrastructure across a campaign. What is the key defensive implication?

Indicators like a single IP or domain are disposable; durable defense targets the behaviours and techniques that persist across the campaign, not the throwaway infrastructure.
If the attacker can swap infrastructure at will, blocking one address buys hours. The techniques they must use to achieve their objective are far harder to change, so that is where lasting detection and defense belong.
Blocking one IP or domain ends the threat.
Attackers never reuse infrastructure, so logging is pointless.
You should buy the same tools the attackers use.

Understanding how attackers choose an initial-access method, what does that tell a defender about where to focus?

Focus only on the most sophisticated zero-day exploits.
Attackers take the path of least resistance, phishing, exposed services, valid accounts, so hardening the common, easy entry points removes the options they reach for first.
Operators are economical: they use the cheapest reliable way in. Most intrusions start with phishing, an exposed service, or valid credentials, so closing those common doors denies the attacker their default move before exotic techniques ever come up.
Nothing; the entry point is essentially unpredictable.
Focus only on physical security.

The course calls credentials "the keys to the kingdom." From the attacker's post-compromise view, why, and what should defenders watch?

Credentials are unimportant once an attacker is inside.
Attackers only ever use exploits, never credentials.
Stolen credentials let an attacker move and act as a legitimate user, evading many controls, so defenders watch for credential access and the abnormal use of valid accounts, not just malware.
Once an attacker holds valid credentials they stop looking like an attacker and start looking like a user, which defeats malware-centric controls. That is why credential access and anomalous valid-account behaviour are central to detecting post-compromise activity.
Watch only for failed logins.

An attacker runs almost their entire operation with built-in system tools and signed binaries. Why is this effective, and what does it demand of defenders?

It is not effective; signed and built-in tools are always safe.
Defenders should simply block all built-in tools.
Antivirus alone handles it.
Living off the land blends with legitimate activity and evades signature and allowlist controls, so defense has to shift to behaviour and context, what the tool is doing and why, not whether the binary is known.
A signed, built-in tool passes every check that asks "is this binary trusted?" The attacker hides in the gap between trusted and benign, so detection must move to behaviour: this trusted tool, doing this, in this context, is wrong.

You have reconstructed a real campaign end to end. How does that most improve your defense?

It proves the attack already happened, so nothing changes.
It is only useful for the incident report.
It lets you prioritise defenses against the specific techniques and chokepoints that campaign relied on, a threat-informed defense grounded in real adversary behaviour rather than a generic checklist.
A reconstructed campaign is a map of exactly how a real adversary operated against an environment like yours. Defending against those concrete techniques and chokepoints is far higher-yield than a generic best-practice list that ignores who actually attacks you.
It tells you which security vendor to buy from.
This course is for you.
You will learn how attackers plan and run operations, from infrastructure and payloads through initial access, credential operations, lateral movement, and evasion, and turn that into stronger detection and defense.
Start Offensive Security for Defenders
You have the fundamentals. The value here is the harder half.
You grasp why offense informs defense, so the payoff is the back half: post-compromise operations, credential and lateral-movement tradecraft, operational defense evasion, campaign reconstruction, and threat-informed defense.
Start with the advanced modules
You clearly think like an operator already.
You handled disposable infrastructure, path-of-least-resistance access, living-off-the-land evasion, and threat-informed defense, the senior end of offensive thinking. Take the course to sharpen what you have, close the gaps you did not expect, and turn an attacker's mindset into sharper defense.
Start Offensive Security for Defenders

Start here

You are a student of this course now, so start by deciding what you want from it. Are you here to close the detection gaps an attacker would walk through, to build campaign-level thinking instead of indicator-chasing, or to learn the adversary's playbook so your detections finally match how intrusions really run? Name that outcome, then turn it into a study plan: which stages of the campaign matter most to your environment, how much time you will give it each week, and what you want to have built by the time you finish.

The rest of Module 0 sets you up to do exactly that. Work through it to see the gap between alerts and campaigns, how attackers think differently from defenders, the Pyramid of Pain and why behavior beats indicators, what this course teaches, and the roadmap ahead. Then begin Module 1.