Certified Red Team Fundamentals
Oct 28, 2026, 9:00 AM · 8 hr 5 min · Room C
Session description
Most defenders have never seen an attack from the other side of the keyboard. This full-day, hands-on workshop puts you in the seat of a penetration tester working through a realistic engagement against a vulnerable target environment. You won't watch slides. You'll work through the full attack lifecycle in a live lab, using the same industry-standard tooling red teamers rely on every day.
Across seven guided modules and a capstone challenge, you'll perform network reconnaissance with Nmap, brute-force authentication services with Hydra, identify and weaponize known vulnerabilities from public exploit databases, gain initial access, analyze suspicious files, escalate privileges using crafted Python payloads, move through a target environment to collect sensitive data, and apply defense evasion techniques to understand how attackers stay quiet.
Each module ties back to the MITRE ATT&CK framework so attendees leave with a mental model they can apply to their own environments. Whether they're starting a red team career, transitioning from a SOC role, or running blue team operations and want to understand what they're actually defending against.
By the end of the day, you'll have completed a guided engagement end-to-end and will have the foundation to continue practicing on your own.
What you'll cover
9:00–9:30 — Setup, lab access verification, threat actor mindset briefing, engagement scenario walkthrough
9:30–10:30 — Module 1: Reconnaissance and Discovery (lab exercise)
10:30–10:45 — Break
10:45–12:00 — Module 2: Initial Access, Vulnerability Assessment, Exploit-DB, and password attacks with Hydra (lab exercise)
12:00–12:45 — Lunch
12:45–1:45 — Module 3: File Analysis and Privilege Escalation with Python payloads (lab exercise)
1:45–2:30 — Module 4: Collection — locating and exfiltrating sensitive data (lab exercise)
2:30–2:40 — Break
2:40–3:40 — Module 5: Defense Evasion + Capstone Challenge (timed, unguided engagement using everything from the day)
3:40–4:00 — Debrief, reporting walkthrough, Q&A, recommended next steps
Requirements
A working understanding of cybersecurity fundamentals (networking basics, common protocols, Linux command line comfort). No prior penetration testing experience required.
Technical Requirements:
Laptop (Windows, macOS, or Linux). Chromebooks, tablets, and phones are not supported.
Google Chrome with RDP support
All hands-on work will be conducted remotely via a browser-based platform.
Takeaways
Execute a complete attack chain (reconnaissance with Nmap, password attacks with Hydra, public-exploit weaponization, and Linux privilege escalation) against a live target environment.
Adapt and run a Python-based public exploit that requires environment-specific modifications, mirroring real engagement workflow.
Map every technique used to MITRE ATT&CK, so findings translate directly into language SOC and detection teams already speak.
Produce a red team report that ties technical findings to business impact and remediation guidance.

