Offensive Security for Defenders
Master Offensive Security for Defenders
Think like an attacker to defend like an expert. Learn offensive security techniques to understand real attacker campaigns, uncover detection gaps, and build resilient defenses that go far beyond alerts, so you can detect, disrupt, and stop sophisticated adversaries in your environment.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Offensive Foundations
What Offensive Security for Defenders teaches: learn the attacker's full campaign from the inside, recon, infrastructure, access, credentials, lateral movement, evasion, objectives, so you can build detection at every stage and turn real TTPs into production Sentinel and Defender XDR detections. The campaign you'll learn to read, the detections you walk away with, and how the course is structured. Start here.
Show 6 lessonsHide lessons
- 0.1OD0.1 The Gap Between Alerts and CampaignsPreview
- 0.2OD0.2 How Attackers Think Differently from DefendersPreview
- 0.3OD0.3 The Pyramid of Pain. Why Operational Patterns MatterPreview
- 0.4OD0.4 What This Course Teaches and What It Doesn'tPreview
- 0.5OD0.5 Course Roadmap, 12 Modules in ContextPreview
- 0.6Module SummaryPreview
The offensive lifecycle from the attacker's perspective. Target selection, objective mapping, constraint analysis, reconnaissance, the decision matrix, timing strategies, team structures, and documented campaign patterns, the operational planning that determines every technique choice the attacker makes.
Show 14 lessonsHide lessons
- 1.1OD1.1 The Offensive Lifecycle. Planning to Objective
- 1.2OD1.2 Target Selection and Objective Mapping
- 1.3OD1.3 Constraint Analysis. Budget, Time, and Capability
- 1.4OD1.4 Risk Tolerance and Operational Security
- 1.5OD1.5 Passive Reconnaissance. What's Visible Before the Attack
- 1.6OD1.6 Active Reconnaissance. Probing Without Being Caught
- 1.7OD1.7 The Attacker's Decision Matrix
- 1.8OD1.8 Operational Timing. Why Attacks Happen When They Do
- 1.9OD1.9 Team Structures and Attacker Roles
- 1.10OD1.10 Documented Campaigns. Ransomware Operations
- 1.11OD1.11 Documented Campaigns. Espionage and Supply Chain
- 1.12OD1.12 The Defender's Operational Profile
- 1.13Module Summary
- 1.14Check My Knowledge
Phase 2: The Campaign Lifecycle
How attackers build and manage C2 infrastructure: team servers, redirectors, domain fronting, CDN abuse, cloud-hosted C2, and disposable infrastructure. The infrastructure lifecycle from build through burn, and what each phase looks like to your network monitoring.
Show 14 lessonsHide lessons
- 2.1OD2.1 Infrastructure as an Operational System
- 2.2OD2.2 Command and Control Frameworks. Building and Detecting C2 Traffic
- 2.3OD2.3 Redirectors, Domain Fronting, and CDN Abuse
- 2.4OD2.4 Domain and Certificate Tradecraft
- 2.5OD2.5 Cloud-Hosted Attack Infrastructure
- 2.6OD2.6 Infrastructure Lifecycle. Build, Stage, Operate, Burn
- 2.7OD2.7 Detecting Infrastructure Staging Before the Attack
- 2.8OD2.8 Infrastructure Rotation. How Attackers Survive Your Blocking
- 2.9OD2.9 Phishing Infrastructure. A Separate Operation
- 2.10OD2.10 Exfiltration Channels. The Infrastructure You Haven't Found
- 2.11OD2.11 Infrastructure Takedown. Dismantling vs Monitoring
- 2.12OD2.12 Campaign Telemetry Exercise. Infrastructure Staging
- 2.13Module Summary
- 2.14Check My Knowledge
How attackers build, obfuscate, and deliver payloads. Multi-stage dropper architecture, runtime evasion (AMSI/ETW bypass), Mark-of-the-Web defeat, delivery method selection, and the full delivery-to-execution chain, from the attacker's engineering decisions to what each stage produces in your telemetry.
Show 14 lessonsHide lessons
- 3.1OD3.1 The Payload Decision Tree
- 3.2OD3.2 Dropper and Loader Architecture. Multi-Stage Delivery
- 3.3OD3.3 Obfuscation and Evasion. What Survives and What Doesn't
- 3.4OD3.4 AMSI, ETW, and Runtime Evasion
- 3.5OD3.5 Mark-of-the-Web Bypass and Trusted Binary Abuse
- 3.6OD3.6 Delivery Method Selection. The Attacker's Routing Decision
- 3.7OD3.7 Email-Based Delivery. From Crafted Phish to Mass Campaign
- 3.8OD3.8 Web-Based Delivery. Watering Holes, Drive-Bys, and SEO Poisoning
- 3.9OD3.9 Supply Chain and Trusted Relationship Delivery
- 3.10OD3.10 Payload Testing. How Attackers QA Before Delivery
- 3.11OD3.11 The Delivery-to-Execution Chain. Connecting the Artifacts
- 3.12OD3.12 Campaign Telemetry Exercise. Payload Delivery
- 3.13Module Summary
- 3.14Check My Knowledge
How attackers choose their initial access method based on the target's visible defenses. AiTM phishing, device code phishing, OAuth consent abuse, application exploitation, and trusted relationship compromise. The attacker's choice reveals their capability, resources, and timeline, intelligence that changes your response before the first lateral movement.
Show 14 lessonsHide lessons
- 4.1OD4.1 The Initial Access Decision
- 4.2OD4.2 AiTM Phishing. The MFA Bypass
- 4.3OD4.3 Device Code Phishing
- 4.4OD4.4 OAuth Consent Phishing
- 4.5OD4.5 Exploiting Public-Facing Applications
- 4.6OD4.6 Trusted Relationship Abuse
- 4.7OD4.7 What the Access Method Reveals
- 4.8OD4.8 Containing Initial Access. Method-Specific Response
- 4.9OD4.9 Pre-Access Staging Detection
- 4.10OD4.10 Access Method Correlation Across Log Sources
- 4.11OD4.11 Campaign Telemetry Exercise. Initial Access
- 4.12OD4.12 Interactive Lab: Initial Access Classifier
- 4.13Module Summary
- 4.14Check My Knowledge
What the attacker does immediately after landing and why they do it in a specific order. Discovery commands reveal the environment. Credential harvesting determines how far they can move. Persistence survives your containment. C2 establishment makes everything that follows possible. The first 30 minutes are the noisiest, and your best detection window.
Show 14 lessonsHide lessons
- 5.1OD5.1 The Post-Compromise Priority List
- 5.2OD5.2 Discovery Command Sequences
- 5.3OD5.3 Environment Profiling. What the Attacker Learns
- 5.4OD5.4 Credential Harvesting Priorities
- 5.5OD5.5 Persistence Decisions
- 5.6OD5.6 C2 Establishment and Validation
- 5.7OD5.7 Defense Evasion in the First Minutes
- 5.8OD5.8 The 30-Minute Detection Window
- 5.9OD5.9 Access-Method-Specific Post-Compromise Sequences
- 5.10OD5.10 Automated vs Manual Post-Compromise
- 5.11OD5.11 Containing the First 30 Minutes
- 5.12OD5.12 Campaign Telemetry Exercise. The First 30 Minutes
- 5.13Module Summary
- 5.14Check My Knowledge
How attackers think about credentials as operational resources, not individual passwords to steal, but an inventory of keys with different values, lifespans, and reuse potential. Which credentials to harvest depends on the objective. How to use them depends on the environment. When to use them depends on the campaign timing. The credential inventory is the campaign's fuel, it determines how far the attacker can move, how long they can stay, and what they can access.
Show 14 lessonsHide lessons
- 6.1OD6.1 Credentials as Operational Resources
- 6.2OD6.2 Password and Hash Operations
- 6.3OD6.3 Kerberos Abuse as an Operational System
- 6.4OD6.4 Token and Session Operations
- 6.5OD6.5 Certificate-Based Credential Abuse
- 6.6OD6.6 Cloud Credential Operations
- 6.7OD6.7 Credential Reuse Chains
- 6.8OD6.8 Credential Tiering Failures
- 6.9OD6.9 Credential Operation Detection at Campaign Scale
- 6.10OD6.10 Defending the Credential Lifecycle
- 6.11OD6.11 Campaign Telemetry Exercise. Credential Operations
- 6.12OD6.12 Interactive Lab: Credential Chain Mapper
- 6.13Module Summary
- 6.14Check My Knowledge
Not just 'T1021', how attackers decide WHERE to move, WHAT credentials to use, WHEN to move, and HOW FAST to move. The operational logic: high-value target identification, trust relationship mapping, movement timing relative to business hours and monitoring cadence, and protocol selection based on the detection surface. The credential inventory from M6 is the fuel. The movement decisions from this module are the route. Together, they form the campaign's movement narrative.
Show 14 lessonsHide lessons
- 7.1OD7.1 Movement as a Decision Problem
- 7.2OD7.2 Target Prioritization. Where to Move and Why
- 7.3OD7.3 Protocol Selection. How to Move
- 7.4OD7.4 Movement Timing and Pacing
- 7.5OD7.5 Trust Relationships as Movement Highways
- 7.6OD7.6 Multi-Hop Movement Analysis
- 7.7OD7.7 Cloud Lateral Movement
- 7.8OD7.8 Lateral Movement Evasion
- 7.9OD7.9 Movement Detection Across Log Sources
- 7.10OD7.10 Containing Lateral Movement
- 7.11OD7.11 Campaign Telemetry Exercise. Lateral Movement
- 7.12OD7.12 Interactive Lab: Movement Path Reconstructor
- 7.13Module Summary
- 7.14Check My Knowledge
How attackers think about your defenses, not as impenetrable barriers but as a landscape of controls to navigate. They bypass the controls in their path and accept the ones that merely log. They test whether they've been detected before escalating. They adapt when a tool is blocked. They clear evidence when they think the investigation is getting close. Every evasion action leaves its own trace, the meta-signals of an attacker who knows they're being watched.
Show 14 lessonsHide lessons
- 8.1OD8.1 The Evasion Mindset
- 8.2OD8.2 EDR Evasion Philosophy
- 8.3OD8.3 Log Awareness and Evidence Destruction
- 8.4OD8.4 Timestomping and Anti-Forensics
- 8.5OD8.5 Living Off the Land. Blending with the Environment
- 8.6OD8.6 Detection Testing by the Attacker
- 8.7OD8.7 Adapting Mid-Campaign
- 8.8OD8.8 Cloud Evasion
- 8.9OD8.9 The Meta-Signals of Evasion
- 8.10OD8.10 Evasion-Aware Detection Design
- 8.11OD8.11 Campaign Telemetry Exercise. Defense Evasion
- 8.12OD8.12 Interactive Lab: Evasion Detection Challenge
- 8.13Module Summary
- 8.14Check My Knowledge
The endgame. Modules 4–8 taught the operational journey, initial access, post-compromise, credentials, lateral movement, evasion. Module 9 covers what happens when the attacker reaches the objective. Ransomware deploys through a specific operational sequence: backup destruction, shadow copy deletion, encryption staging, GPO push, ransom note deployment. Data theft follows a pipeline: identification, staging, compression, channel selection, transfer.
Show 14 lessonsHide lessons
- 9.1OD9.1 Objective Execution as the Culmination of Operations
- 9.2OD9.2 Ransomware as an Operational Sequence
- 9.3OD9.3 Data Theft and Exfiltration Operations
- 9.4OD9.4 Double Extortion Operations
- 9.5OD9.5 Espionage Operations. The Long Game
- 9.6OD9.6 Business Email Compromise Operations
- 9.7OD9.7 Sabotage and Destructive Operations
- 9.8OD9.8 Cloud-Native Objective Execution
- 9.9OD9.9 Detecting Objective Staging
- 9.10OD9.10 Objective-Informed Containment
- 9.11OD9.11 Campaign Telemetry Exercise. Objective Execution
- 9.12OD9.12 Interactive Lab: Objective Classifier
- 9.13Module Summary
- 9.14Check My Knowledge
The capstone defensive skill. Three alerts arrive across three systems over six hours: a suspicious PowerShell execution, an unusual logon, and a new scheduled task. Each triggers a rule. Each is triaged independently. Each is closed as low-severity. Together, they're a credential-access campaign that culminated in persistent access and data staging.
Show 14 lessonsHide lessons
- 10.1OD10.1 From Alerts to Narrative
- 10.2OD10.2 Campaign Timeline Construction
- 10.3OD10.3 Multi-Source Correlation Techniques
- 10.4OD10.4 Behavioral Clustering
- 10.5OD10.5 Kill Chain Reconstruction
- 10.6OD10.6 Filling the Gaps
- 10.7OD10.7 Attribution at the Operational Level
- 10.8OD10.8 Building Campaign-Level Detection Rules
- 10.9OD10.9 Confidence Scoring and Alternative Hypotheses
- 10.10OD10.10 The Investigation Brief
- 10.11OD10.11 Campaign Telemetry Exercise, 72-Hour CHAIN-HARVEST
- 10.12OD10.12 Interactive Lab: Campaign Reconstruction Tool
- 10.13Module Summary
- 10.14Check My Knowledge
The final module. Modules 0–10 taught you how attackers think, plan, execute, evade, and achieve their objectives, and how defenders detect, correlate, and reconstruct campaigns. Module 11 translates that understanding into program-level decisions.
Show 13 lessonsHide lessons
- 11.1OD11.1 From Understanding to Strategy
- 11.2OD11.2 Attacker Economics. What's Cheap and What's Expensive
- 11.3OD11.3 Threat Modeling from the Attacker's Perspective
- 11.4OD11.4 Detection Coverage Mapping
- 11.5OD11.5 Prioritizing Detection Investment
- 11.6OD11.6 The Detection Portfolio
- 11.7OD11.7 The Program Rhythm
- 11.8OD11.8 Measuring Detection Program Effectiveness
- 11.9OD11.9 The Threat-Informed Detection Roadmap
- 11.10OD11.10 Threat Model Exercise. Build the NE Detection Roadmap
- 11.11OD11.11 Interactive Lab: Detection Portfolio Assessor
- 11.12Module Summary
- 11.13Check My Knowledge
Phase 0: Course Resources
Detection sheets organized by attacker stage, each rule carrying how durable it is against the operator adapting.
Seven procedures for converting attacker understanding into detection capability, each with a state to reach.
An isolated lab for running attacker techniques safely, and the telemetry to observe them from the defender's side.
Show 5 lessonsHide lessons
Worked cases where understanding the operator's constraints changes the answer, including the wrong turns.
Seven events that arrive with an offensive question attached, each with prerequisites, a pre-flight, a numbered sequence and a worked handoff.
Where to practice reading attacker telemetry, and which half of this course a simulator cannot teach.
The consolidated lookup and the step-by-step procedures from this course, in one place.
Show 2 lessonsHide lessons
External sources this course draws on: vendor documentation, frameworks, standards, and research.
Course Completion
Offensive Security for Defenders end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.
Show 1 lessonHide lessons
Course overview
The Offensive Security for Defenders course is built specifically for Security Professionals who want to detect campaigns, not just alerts. You'll gain practical, hands-on expertise to:
By the end, you'll have the offensive mindset and technical skills to proactively find and close detection gaps, making your organization significantly harder to compromise.
How this course works
This is an offensive course written for defenders, so every technique is taught with the artifact it leaves rather than the outcome it achieves. The loop is the same throughout.
1. Run the technique yourself. Reading about an attack tells you what it does. Running it tells you what it produces, and only the second is detectable.
2. Find what it wrote down. Every technique touches something: a process, a registry key, an authentication event, a network flow. That footprint is the detection surface.
3. Ask what the attacker can change and what they cannot. A tool name is changeable. The syscall the technique depends on is not. Detections built on the second survive.
4. Build the detection against the durable half. Then test it by running the technique again, which is the only proof that the rule works.
5. Try to defeat your own rule. If you can bypass it in ten minutes, so can somebody who does this for a living, and better to find out now.
What this course assumes
No minimum experience and no prerequisite course, and no offensive background assumed. The course teaches the attacker's technique to the depth a defender needs and not beyond it.
What makes it go faster: a lab you can break, virtual is fine, and comfort at a command line. Neither is required, and every technique is shown with the telemetry it produced.
What this course does not cover: penetration testing as a profession, exploit development, and red team operations. Offensive technique here is a means to a detection, and the course does not pretend otherwise.
Who this course is for
You're a Security Professional (SOC analyst, Detection Engineer, Threat Hunter, or Blue Teamer) who wants to move beyond triaging alerts to detecting full attacker campaigns. This course is built for you if you want to:
In short: if you're ready to detect campaigns, not just alerts, and become a much more effective defender, this course is for you.
What you'll learn
By the end of this Offensive Security for Defenders course you will be able to:
Key course takeaways
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches offensive concepts from a defender's perspective. Familiarity with KQL, Microsoft Sentinel, and Defender XDR will help you move faster, but neither is required. Every tool and technique is explained at first use.
What are the device requirements?
A device with a modern browser. Access to a lab environment for running offensive tools (the course walks you through setup). You will also benefit from a Microsoft 365 E5 developer tenant for detection development.
How will the course benefit your career?
Defenders who understand offensive operations are dramatically more effective at detection engineering, threat hunting, and incident response. This course gives you the attacker's perspective so you can anticipate campaign patterns, build detections that survive tool rotation, and investigate incidents at the campaign level rather than the alert level.
Offensive understanding is increasingly a prerequisite for senior detection engineering, threat hunting, and security architecture roles.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy detection rules, queries, and analysis techniques in your production environment. You may not redistribute course content or share account credentials.
Offensive techniques: All attack execution is in your own isolated lab. Do not execute techniques against systems you do not own or have explicit written authorization to test.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.