Offensive Security for Defenders

Master Offensive Security for Defenders

Think like an attacker to defend like an expert. Learn offensive security techniques to understand real attacker campaigns, uncover detection gaps, and build resilient defenses that go far beyond alerts, so you can detect, disrupt, and stop sophisticated adversaries in your environment.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Download Lab Pack Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Simulate real-world attacker techniques and campaigns using red team tactics and living-off-the-land methods
✓Think like an attacker to identify blind spots and detection gaps in your current security controls
✓Translate offensive techniques into stronger, more effective detections and hunting hypotheses
✓Proactively hunt and detect sophisticated attacker campaigns that evade traditional alerts
✓Assess and improve your organization's defenses by understanding how real breaches actually happen
✓Build campaign-focused detection strategies instead of isolated alert-based rules
SEC403 | Premium tier | 12 modules + cheatsheet | 30–40 hours at your own pace | 40 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Offensive Foundations

Module 0Course OrientationCourse Preview

What Offensive Security for Defenders teaches: learn the attacker's full campaign from the inside, recon, infrastructure, access, credentials, lateral movement, evasion, objectives, so you can build detection at every stage and turn real TTPs into production Sentinel and Defender XDR detections. The campaign you'll learn to read, the detections you walk away with, and how the course is structured. Start here.

Show 6 lessonsHide lessons
  1. 0.1OD0.1 The Gap Between Alerts and CampaignsPreview
  2. 0.2OD0.2 How Attackers Think Differently from DefendersPreview
  3. 0.3OD0.3 The Pyramid of Pain. Why Operational Patterns MatterPreview
  4. 0.4OD0.4 What This Course Teaches and What It Doesn'tPreview
  5. 0.5OD0.5 Course Roadmap, 12 Modules in ContextPreview
  6. 0.6Module SummaryPreview

Phase 2: The Campaign Lifecycle

Module 6Credential Operations, The Keys to the Kingdom

How attackers think about credentials as operational resources, not individual passwords to steal, but an inventory of keys with different values, lifespans, and reuse potential. Which credentials to harvest depends on the objective. How to use them depends on the environment. When to use them depends on the campaign timing. The credential inventory is the campaign's fuel, it determines how far the attacker can move, how long they can stay, and what they can access.

Show 14 lessonsHide lessons
  1. 6.1OD6.1 Credentials as Operational Resources
  2. 6.2OD6.2 Password and Hash Operations
  3. 6.3OD6.3 Kerberos Abuse as an Operational System
  4. 6.4OD6.4 Token and Session Operations
  5. 6.5OD6.5 Certificate-Based Credential Abuse
  6. 6.6OD6.6 Cloud Credential Operations
  7. 6.7OD6.7 Credential Reuse Chains
  8. 6.8OD6.8 Credential Tiering Failures
  9. 6.9OD6.9 Credential Operation Detection at Campaign Scale
  10. 6.10OD6.10 Defending the Credential Lifecycle
  11. 6.11OD6.11 Campaign Telemetry Exercise. Credential Operations
  12. 6.12OD6.12 Interactive Lab: Credential Chain Mapper
  13. 6.13Module Summary
  14. 6.14Check My Knowledge
Module 7Lateral Movement as Operational Maneuver

Not just 'T1021', how attackers decide WHERE to move, WHAT credentials to use, WHEN to move, and HOW FAST to move. The operational logic: high-value target identification, trust relationship mapping, movement timing relative to business hours and monitoring cadence, and protocol selection based on the detection surface. The credential inventory from M6 is the fuel. The movement decisions from this module are the route. Together, they form the campaign's movement narrative.

Show 14 lessonsHide lessons
  1. 7.1OD7.1 Movement as a Decision Problem
  2. 7.2OD7.2 Target Prioritization. Where to Move and Why
  3. 7.3OD7.3 Protocol Selection. How to Move
  4. 7.4OD7.4 Movement Timing and Pacing
  5. 7.5OD7.5 Trust Relationships as Movement Highways
  6. 7.6OD7.6 Multi-Hop Movement Analysis
  7. 7.7OD7.7 Cloud Lateral Movement
  8. 7.8OD7.8 Lateral Movement Evasion
  9. 7.9OD7.9 Movement Detection Across Log Sources
  10. 7.10OD7.10 Containing Lateral Movement
  11. 7.11OD7.11 Campaign Telemetry Exercise. Lateral Movement
  12. 7.12OD7.12 Interactive Lab: Movement Path Reconstructor
  13. 7.13Module Summary
  14. 7.14Check My Knowledge
Module 8Defense Evasion at the Operational Level

How attackers think about your defenses, not as impenetrable barriers but as a landscape of controls to navigate. They bypass the controls in their path and accept the ones that merely log. They test whether they've been detected before escalating. They adapt when a tool is blocked. They clear evidence when they think the investigation is getting close. Every evasion action leaves its own trace, the meta-signals of an attacker who knows they're being watched.

Show 14 lessonsHide lessons
  1. 8.1OD8.1 The Evasion Mindset
  2. 8.2OD8.2 EDR Evasion Philosophy
  3. 8.3OD8.3 Log Awareness and Evidence Destruction
  4. 8.4OD8.4 Timestomping and Anti-Forensics
  5. 8.5OD8.5 Living Off the Land. Blending with the Environment
  6. 8.6OD8.6 Detection Testing by the Attacker
  7. 8.7OD8.7 Adapting Mid-Campaign
  8. 8.8OD8.8 Cloud Evasion
  9. 8.9OD8.9 The Meta-Signals of Evasion
  10. 8.10OD8.10 Evasion-Aware Detection Design
  11. 8.11OD8.11 Campaign Telemetry Exercise. Defense Evasion
  12. 8.12OD8.12 Interactive Lab: Evasion Detection Challenge
  13. 8.13Module Summary
  14. 8.14Check My Knowledge
Module 9Objectives: Data Theft, Ransomware, Espionage, Sabotage

The endgame. Modules 4–8 taught the operational journey, initial access, post-compromise, credentials, lateral movement, evasion. Module 9 covers what happens when the attacker reaches the objective. Ransomware deploys through a specific operational sequence: backup destruction, shadow copy deletion, encryption staging, GPO push, ransom note deployment. Data theft follows a pipeline: identification, staging, compression, channel selection, transfer.

Show 14 lessonsHide lessons
  1. 9.1OD9.1 Objective Execution as the Culmination of Operations
  2. 9.2OD9.2 Ransomware as an Operational Sequence
  3. 9.3OD9.3 Data Theft and Exfiltration Operations
  4. 9.4OD9.4 Double Extortion Operations
  5. 9.5OD9.5 Espionage Operations. The Long Game
  6. 9.6OD9.6 Business Email Compromise Operations
  7. 9.7OD9.7 Sabotage and Destructive Operations
  8. 9.8OD9.8 Cloud-Native Objective Execution
  9. 9.9OD9.9 Detecting Objective Staging
  10. 9.10OD9.10 Objective-Informed Containment
  11. 9.11OD9.11 Campaign Telemetry Exercise. Objective Execution
  12. 9.12OD9.12 Interactive Lab: Objective Classifier
  13. 9.13Module Summary
  14. 9.14Check My Knowledge

Phase 0: Course Resources

ResourcesLab Setup

An isolated lab for running attacker techniques safely, and the telemetry to observe them from the defender's side.

Show 5 lessonsHide lessons
  1. 1Isolation and Safety
  2. 2The Domain and Hosts
  3. 3Telemetry
  4. 4Tooling and the First Technique
  5. 5Verify and Limits
ResourcesPlaybooks

Seven events that arrive with an offensive question attached, each with prerequisites, a pre-flight, a numbered sequence and a worked handoff.

Show 7 lessonsHide lessons
  1. 1A Behavioral Detection Fired
  2. 2An Operator Appears to Be Adapting
  3. 3A Technique Fired With No Playbook
  4. 4A Third Party Told Us
  5. 5Somebody Is Testing Our Detections
  6. 6A Red Team Engagement Is Starting
  7. 7A Rule We Rely On Went Silent
ResourcesPlayground

Where to practice reading attacker telemetry, and which half of this course a simulator cannot teach.

ResourcesOperational Reference

The consolidated lookup and the step-by-step procedures from this course, in one place.

Show 2 lessonsHide lessons
  1. 1Campaign Detection Quick Reference
  2. 2Offensive-to-Defensive Field Manual
ResourcesReferences & Further Reading

External sources this course draws on: vendor documentation, frameworks, standards, and research.

Course Completion

CompletionCourse Exam

Offensive Security for Defenders end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.

Show 1 lessonHide lessons
  1. 1Course Completion. Offensive Security for Defenders

Course overview

The Offensive Security for Defenders course is built specifically for Security Professionals who want to detect campaigns, not just alerts. You'll gain practical, hands-on expertise to:

✓ Simulate real-world attacker techniques using MITRE ATT&CK and living-off-the-land methods
✓ Think like a red teamer to identify blind spots in your current detection and prevention controls
✓ Improve threat detection engineering by understanding how attacks actually work
✓ Translate offensive knowledge into stronger defenses, hunting, and response capabilities

By the end, you'll have the offensive mindset and technical skills to proactively find and close detection gaps, making your organization significantly harder to compromise.

How this course works

This is an offensive course written for defenders, so every technique is taught with the artifact it leaves rather than the outcome it achieves. The loop is the same throughout.

1. Run the technique yourself. Reading about an attack tells you what it does. Running it tells you what it produces, and only the second is detectable.

2. Find what it wrote down. Every technique touches something: a process, a registry key, an authentication event, a network flow. That footprint is the detection surface.

3. Ask what the attacker can change and what they cannot. A tool name is changeable. The syscall the technique depends on is not. Detections built on the second survive.

4. Build the detection against the durable half. Then test it by running the technique again, which is the only proof that the rule works.

5. Try to defeat your own rule. If you can bypass it in ten minutes, so can somebody who does this for a living, and better to find out now.

What this course assumes

No minimum experience and no prerequisite course, and no offensive background assumed. The course teaches the attacker's technique to the depth a defender needs and not beyond it.

What makes it go faster: a lab you can break, virtual is fine, and comfort at a command line. Neither is required, and every technique is shown with the telemetry it produced.

What this course does not cover: penetration testing as a profession, exploit development, and red team operations. Offensive technique here is a means to a detection, and the course does not pretend otherwise.

Who this course is for

You're a Security Professional (SOC analyst, Detection Engineer, Threat Hunter, or Blue Teamer) who wants to move beyond triaging alerts to detecting full attacker campaigns. This course is built for you if you want to:

✓ Develop an offensive security mindset to better understand and counter real adversaries
✓ Learn how attackers operate so you can build more resilient detections and defenses
✓ Bridge the gap between red team tactics and blue team detection engineering
✓ Significantly improve your ability to find stealthy, persistent threats in your environment

In short: if you're ready to detect campaigns, not just alerts, and become a much more effective defender, this course is for you.

What you'll learn

By the end of this Offensive Security for Defenders course you will be able to:

✓ Understand and replicate common attacker techniques across the MITRE ATT&CK framework
✓ Simulate realistic attack scenarios to test and improve your detection capabilities
✓ Identify detection gaps and blind spots by thinking like a red teamer
✓ Build high-fidelity detections and hunting queries based on real campaign behavior
✓ Apply offensive knowledge to enhance threat hunting, incident response, and detection engineering
✓ Develop a campaign-aware defensive strategy that focuses on adversary behavior rather than isolated IOCs

Key course takeaways

✓ Develop a true offensive mindset that makes you a far more effective defender
✓ Master the ability to detect full attacker campaigns instead of just individual alerts
✓ Proactively identify and close detection gaps before real attackers exploit them
✓ Translate red team techniques into stronger blue team detections and hunting playbooks
✓ Significantly improve your organization's resilience against sophisticated, stealthy threats
✓ Become the defender who understands attackers better than they understand your environment

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches offensive concepts from a defender's perspective. Familiarity with KQL, Microsoft Sentinel, and Defender XDR will help you move faster, but neither is required. Every tool and technique is explained at first use.

What are the device requirements?

A device with a modern browser. Access to a lab environment for running offensive tools (the course walks you through setup). You will also benefit from a Microsoft 365 E5 developer tenant for detection development.

How will the course benefit your career?

Defenders who understand offensive operations are dramatically more effective at detection engineering, threat hunting, and incident response. This course gives you the attacker's perspective so you can anticipate campaign patterns, build detections that survive tool rotation, and investigate incidents at the campaign level rather than the alert level.

Offensive understanding is increasingly a prerequisite for senior detection engineering, threat hunting, and security architecture roles.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy detection rules, queries, and analysis techniques in your production environment. You may not redistribute course content or share account credentials.

Offensive techniques: All attack execution is in your own isolated lab. Do not execute techniques against systems you do not own or have explicit written authorization to test.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.