Offensive SecurityAdvanced~9 months

Red Team

Advanced adversary simulation including social engineering, physical security, and sophisticated attack chains.

10 Topics

Key concepts

3 Levels

Beginner to Advanced

5 Tools

Curated for this track

8 Questions

Test yourself

About this track

Adversary simulation against a defence that is watching.

Red teaming is not penetration testing with a better name. The objective is different: rather than enumerating vulnerabilities, you emulate a specific adversary against a live defence to test whether that defence detects and responds.

That changes the skill set. Stealth, infrastructure, and tradecraft matter more than exploit count. This track covers command-and-control design, evasion, and the human and physical vectors that technical controls do not cover — all of which assume you already have solid penetration testing fundamentals.

Every technique here belongs inside a written rules-of-engagement document, agreed with the organisation being tested, before anything is executed.

Key topics

10 topics grouped into three modules, in the order you should meet them.

  1. 01

    Planning & OSINT

    4 topics
    • 1.

      Adversary Simulation

      Emulating a documented threat actor's behaviour rather than improvising freely.

    • 2.

      Social Engineering

      The human attack surface, which remains the most reliable initial access vector.

    • 3.

      Phishing Campaigns

      Pretext, infrastructure, and payload delivery that survives contact with a mail gateway.

    • 4.

      C2 Frameworks

      Command-and-control design, redirectors, and traffic that blends into the baseline.

  2. 02

    Access & control

    4 topics
    • 5.

      Evasion Techniques

      Understanding EDR telemetry well enough to operate underneath it.

    • 6.

      Physical Security

      Badge cloning, tailgating, and drop devices — where the network perimeter ends.

    • 7.

      OSINT

      Building the target picture from public sources before touching anything.

    • 8.

      Initial Access

      The first foothold, and choosing the vector with the best noise-to-value ratio.

  3. 03

    Persistence & evasion

    2 topics
    • 9.

      Persistence

      Surviving reboots and credential resets without leaving obvious artefacts.

    • 10.

      Exfiltration

      Demonstrating data loss over channels the defence is not inspecting.

What you'll be able to do

  • Plan an engagement around a specific threat actor's documented behaviour
  • Stand up resilient command-and-control infrastructure
  • Gain and keep access without tripping the defences you are testing
  • Debrief a blue team on exactly what they missed and why