• $700 or 5 monthly payments of $149

Detection Engineering Professional: Attack Simulation & Defense

  • Course
  • 149 Lessons
  • Discord access

A hands-on detection engineering course for practitioners with a few years in security. Simulate real attacks in a Windows Active Directory lab, trace them through Windows Event Logs, Sysmon, and EDR, then write, tune, and validate your own detection rules. This is where you learn to own the detections that catch intrusions, not just recognize them.

Read more about the instructors, course contents and special pricing:

Contents

Course Slide Deck & Practice Labs

In this course slide deck, you will find all materials both presented in the videos and many practical labs for you to become more practically knowledgeable.

So have fun, practice a lot and remember to always say thanks to the one above for everything good and challenging in life, because challenges are what build us 😀

Good luck, and with all my heart, enjoy the course!

Detection Engineering Professional: Attack Simulation & Defense - Presentation
Attack Simulation and Detection Engineering Practice Labs.pdf
Process Injection Tool - TrainSec Injector.zip

1: Welcome & Intro

1 - Welcome.mp4
2 - What you will find here.mp4
Preview
3 - Blue Team / Purple Team Fundamentals.mp4
4 - The Essence of this Course.mp4
Preview

2: Attack & Defense Mindset

1 - Introduction.mp4
2 - Who is a Hacker.mp4
3 - Basic Concepts - Part 1.mp4
4 - Basic Concepts - Part 2.mp4
5 - The CIA Triad.mp4
6 - The DAD Triad.mp4
7 - The Cyber Kill-Chain - Part 1.mp4
8 - The Cyber Kill-Chain - Part 2.mp4
9 - Threat Actor Types.mp4
10 - Infamous Cyber Attacks.mp4
11 - Attacker's Goals & Desires.mp4
12 - How attackers hide their traces.mp4
13 - The Darknet.mp4

3: Attacker's Martial Art

1 - Reconnaissance.mp4
2 - Google Hacking & Dorks.mp4
3 - Port Mapping with Nmap.mp4
4 - AV-EDR Bypass - Part 1.mp4
5 - AV-EDR Bypass - Part 2.mp4
6 - Social Engineering Phishing Web Page.mp4
7 - SSL Stripping - Part 1.mp4
8 - SSL Stripping - Part 2.mp4
9 - Infrastructure Exploitation.mp4
10 - Post Exploitation - Part 1.mp4
11 - Post Exploitation - Part 2.mp4
12 - Remote Brute Force.mp4

4: Introduction to Malware Attacks

1 - Intro.mp4
2 - Types of Malware.mp4
3 - Malware Analysis.mp4
4 - The ATT&CK MITRE Framework.mp4
5 - Atomic Red Team.mp4
6 - The Emotet Usecase - Part 1.mp4
7 - The Emotet Usecase - Part 2.mp4
Preview

5: Proactive Defense - Cybersecurity Hardening

1 - Intro.mp4
2 - Basic Concepts.mp4
3 - The Principle of Least Privilege - Part 1.mp4
4 - The Principle of Least Privilege - Part 2.mp4
5 - General Security Best Practices.mp4
6 - VLAN Hopping.mp4
7 - More Attack Techniques.mp4
8 - Network Attacks Mitigation Practices.mp4
9 - DDoS Attacks & Mitigations.mp4
10 - Brute Force & Physical Access Attacks.mp4
11 - DNS Zone Transfer Attack & Mitigations.mp4
12 - Credential Dumping & Mitigations.mp4
13 - OS & Network Security.mp4

6: Proactive Defense - Threat Hunting & Incident Response

1 - IR Intro.mp4
2 - IR Intro - Part 2.mp4
3 - Preparation.mp4
4 - Identification & Analysis.mp4
5 - Identification & Analysis - Part 2.mp4
6 - Incident Containment.mp4
7 - Incident Containment - Part 2.mp4
8 - Incident Eradication & Recovery.mp4
9 - The Aftermath - What happens after the Incident.mp4
10 - Threat Hunting.mp4
11 - Threat Hunting - Part 2.mp4
12 - Threat Hunting - Part 3.mp4

7: Working with Windows Event Logs

1 - Intro & Log Sources.mp4
2 - Exploring Windows Event Viewer.mp4
3 - Exploring Windows Event Viewer - Part 2.mp4
4 - Common Windows Event IDs.mp4
5 - Common Windows Event IDs - Part 2.mp4
6 - Analyzing Event ID 4625 Failed Logon.mp4
7 - Analyzing Event ID 4625 Failed Logon - Part 2.mp4
Preview
8 - Analyzing Event ID 4624 Successful Logon.mp4
9 - Domain Discovery & Lack of Telemetry Data.mp4
10 - Domain Discovery & Lack of Telemetry Data - Part 2.mp4

8: Sysmon Detection Engineering

1 - Sysmon Intro.mp4
2 - Sysmon Intro - Part 2.mp4
3 - Core Sysmon Event IDs & Blind Spots.mp4
4 - Deploying Sysmon.mp4
5 - Detecting Nltest using ProcessCreate Event.mp4
6 - Detecting Nltest using ProcessCreate Event - Part 2.mp4
7 - Detecting the Net command using ProcessCreate Event.mp4
8 - Detecting the Net command using ProcessCreate Event - Part 2.mp4
9 - Detecting DNS Queries.mp4
10 - Detecting DNS Queries - Part 2.mp4
11 - Detecting Persistence using the FileCreate event.mp4
12 - Detecting Persistence using the FileCreate event - Part 2.mp4
13 - Detecting Persistence using RegistryEvent.mp4
14 - Detecting Persistence using RegistryEvent - Part 2.mp4
15 - Detecting Credential Access using ImageLoad.mp4
16 - Detecting Credential Access using ImageLoad - Part 2.mp4
17 - Sysmon Events Exclusion.mp4
18 - Detecting the CreateRemoteThread Process Injection.mp4
Preview

9: EDR - XDR Detection Fundamentals & Deployment

1 - Intro.mp4
2 - AV vs. EDR vs. XDR vs. SIEM.mp4
3 - Detection Kill-Chain & Process Tree.mp4
4 - Detection Correlation.mp4
5 - Incidents & Alerts Chain of Events.mp4
6 - Elastic Security EDR Overview.mp4
7 - Deploying Elastic Defend.mp4
8 - Deploying Elastic Defend - Part 2.mp4
9 - Optimizing the Security Policy and Enabling Anti-Tampering.mp4
10 - EDR Telemetry Collection Sanity Check.mp4
Preview

10: Attack and Defense - Initial Access and Lateral Movement

1 - Attack & Defense Intro.mp4
2 - RDP Attack Simulation.mp4
3 - RDP Attack Investigation.mp4
4 - RDP Attack Detection.mp4
5 - RDP Attack Detection - Part 2.mp4
6 - RDP Attack Detection - Part 3.mp4
7 - PSexec Attack Simulation.mp4
8 - PSexec Attack Investigation.mp4
9 - PSexec Attack Detection.mp4
10 - WinRM Attack Simulation.mp4
Preview
11 - WinRM Attack Investigation.mp4
12 - WinRM Attack Detection.mp4

11: Attack and Defense - Discovery

1 - Nltest Discovery Simulation.mp4
2 - Nltest Discovery Investigation.mp4
3 - Nltest Discovery Detection.mp4
4 - Net Discovery Simulation.mp4
5 - Net Discovery Investigation.mp4
6 - Net Discovery Detection.mp4

12: Attack and Defense - Living-off-the-Land (LOLbin & Friends)

1 - The Emotet Usecase - Detecting PowerShell Attacks.mp4
2 - WMI Attack Simulation.mp4
3 - WMI Attack Investigation.mp4
4 - WMI Attack Detection.mp4
Preview
5 - KeyMgr Detection Bypass Red Team Edition.mp4
6 - KeyMgr Detection Bypass Red Team Edition - Part 2.mp4

13: Attack and Defense - Persistence & Credential Access

1 - Registry Persistence Attack Simulation.mp4
2 - Registry Persistence Attack Investigation.mp4
3 - Registry Persistence Attack Detection.mp4
4 - Service Persistence Attack Simulation.mp4
5 - Service Persistence Attack Investigation.mp4
6 - Service Persistence Attack Detection.mp4
7 - Startup Folder Persistence Attack Simulation.mp4
8 - Startup Folder Persistence Attack Investigation.mp4
9 - Startup Folder Persistence Attack Detection.mp4
10 - Credential Access Techniques.mp4

14: Attack and Defense - AI & Process Injection

Process Injection Tool - TrainSec Injector.zip
1 - Process Injection Techniques Attack Simulation.mp4
2 - Process Injection Techniques Attack Investigation & Detection.mp4
3 - AI Assisted Detection Engineering.mp4
4 - AI Assisted Detection Engineering - Part 2.mp4
5 - AI Assisted Detection Engineering - Part 3.mp4

15: To know your enemy, you must become your enemy - Final Notes & Labs

1 - Pro Tips.mp4
2 - Attack Simulation and Detection Engineering Practice Labs.mp4
3 - Thank you.mp4

Bonus Content

1 - Interesting Windows Folder Paths.mp4
2 - Interesting Windows Folder Paths - Part 2.mp4
3 - Interesting Windows Registry Keys.mp4
DEF CON 34 - The Silent Tunneler - A Real-World Incident Response Story.mp4