Full-scope, goal-based operations that emulate a real threat actor while staying safe and in scope. Each area below is its own deep dive.
Initial Access & Phishing
- Pretext design and payload delivery
- Malicious document / loader tradecraft
- Landing pages and credential capture
Redirectors & C2 Infrastructure
- Redirector chains and domain fronting
- C2 profile hardening and traffic shaping
- OPSEC for infrastructure separation
AV Bypass
- Understanding signature vs heuristic detection
- Payload obfuscation and packing
- Testing against representative engines
EDR Bypass
- Telemetry sources: hooks, ETW, kernel callbacks
- Unhooking, indirect syscalls, and BYOVD concepts
- Behavioural evasion vs static evasion
Lateral Movement & Persistence
- Living-off-the-land techniques
- Credential material and ticket abuse
- Persistence with clean removal
Exfiltration & Impact
- Staged, throttled exfiltration
- Objective demonstration without real harm
- Reporting mapped to detection gaps