Skip to main content

COURSE // BETA

Red Cell Operator I Briefing

Red Team Mindset. Relentless Offence.

COURSE ID:armory-red-cell-operator-i
TIER:Agent
DURATION:TBD
ACCESS:Paid

Course Specifications

The long-awaited and carefully forged Red Cell Operator I course is out now! From your initial scope to compromising an Active Directory domain to gain complete domain ownership, through to drafting a comprehensive, client-facing report at the end, this course covers the entire kill chain of a red team assessment, all whilst using Sliver as your command-and-control framework.

To highlight some of the most riveting content, this course covers:

  • Understanding a red team’s pre-engagement planning and the essential components that constitute it
  • Using OSINT to gather compromised credentials from leaked databases
  • Bypassing MFA using Evilginx2
  • Leveraging and chaining modern phishing techniques, such as FileFix, to establish Sliver C2 implant sessions on Windows hosts
  • Understanding, and implementing, the three pillars of system compromise - TA0007, TA0003 and TA0004
  • Exploiting Kerberos and Active Directory’s authentication model and its weaknesses to forge bespoke sessions, abuse permissions and, ultimately, achieve domain administrator rights
  • Composing a report, with clear and actionable deliverables

Although this outline barely scratches the surface of what’s covered, this course is designed to help you properly understand your TTPs, not just demonstrate your competency at executing commands. Each unit delves deep into its subject to, ultimately, forge a fortified red team operator out of you.