Red Team Operations & Adversary Simulation
C2 frameworks, MITRE ATT&CK-driven campaigns, defense evasion, and full attack-chain adversary emulation.
Course overview
The advanced track for anyone who has already learned to break into things and now wants to operate like an adversary from first contact to objective. This course goes past single-exploit thinking into full campaign design: building an emulation plan from real threat intelligence and MITRE ATT&CK, standing up your own command-and-control infrastructure with Sliver, understanding how Cobalt Strike-style C2 architecture and malleable profiles actually work, and running initial access, execution, defense evasion, persistence, privilege escalation, credential access, and lateral movement as a single coherent operation rather than a checklist. Every technique is taught the way MITRE ATT&CK, published vendor threat research, and red-team certifications like CRTO and OSEP teach it: how it works, why it works, how blue teams detect it, and how to write it up afterward. The course closes with purple teaming, detection engineering, and the kind of report that gets an engagement re-booked, all inside strict rules-of-engagement and authorized-testing framing throughout.
What you'll learn
- Design a red team engagement: scoping, rules of engagement, deconfliction, and objectives-based (crown-jewel/flag) testing
- Read cyber threat intelligence and translate a real threat actor's TTPs into a MITRE ATT&CK-mapped adversary emulation plan
- Explain C2 framework architecture (listeners, beacons/implants, malleable profiles) across Cobalt Strike-style and open-source frameworks
- Stand up and operate a Sliver C2 server, generate implants, and manage sessions and beacons hands-on in a lab
- Build attack infrastructure with redirectors, domain categorization, and cloud-hosted C2 while maintaining operator OPSEC
- Execute initial access via phishing pretexts and payload delivery chains, and explain living-off-the-land execution techniques
- Explain how EDR telemetry, AMSI, and process injection work well enough to reason about evasion and its detection tradeoffs
- Apply Windows and Linux persistence and privilege escalation tradecraft from a red-team operator's perspective
- Perform credential access and lateral movement (pass-the-hash, ticket attacks, WMI/WinRM/PsExec) across a simulated environment
- Shape C2 network traffic (malleable profiles, domain fronting concepts, beacon jitter) and reason about network-based detection
- Run a purple team exercise, contribute to detection engineering, and write a red-team report that communicates TTPs and business risk
Who this course is for
Pentesters and security practitioners who already have solid fundamentals (comparable to this platform's Kali Linux and Active Directory Offensive Security courses, or equivalent experience) and want to move from single-target exploitation into full-scope adversary simulation and red team operations. Assumes comfort with Windows/Linux command lines, core networking, and at least conceptual familiarity with Active Directory.
Curriculum
Module 1: Welcome to Red Team Operations
- What Red Teaming Actually Is (and Isn't)
- Red Team vs. Pentest vs. Purple Team: Choosing the Right Engagement
- The Adversary Emulation Mindset
- Legal, Ethical, and Rules-of-Engagement Foundations
- Module 1 Knowledge Check
Module 2: MITRE ATT&CK and Threat Intelligence
- The MITRE ATT&CK Matrix, Explained
- Reading Threat Intel: From CTI Reports to TTPs
- Building an Adversary Emulation Plan with ATT&CK Navigator
- Lab: Map a Real Threat Actor to ATT&CK Techniques
On completion of every module, enrolled students receive a verifiable certificate of completion. Full curriculum, hands-on labs, and instructor support are available at pentestnotes.tech/courses/red-team-operations-adversary-simulation.