Learning objectives
- Turn business objectives into adversary scenarios
- Plan an operation with rules of engagement and stop criteria
- Measure prevention and detection in a repeatable way
- Conduct an improvement-focused purple team debrief
Who should attend
Experienced penetration testers, red teamers, purple teamers and control validation managers.
Prerequisites
Hands-on experience in internal penetration testing, Active Directory, networking and security operations.
Course outline
- Objectives, threat, rules of engagement, operational security and governance
- Threat intelligence, scenarios and ATT&CK technique selection
- Test infrastructure, emulation and evidence management
- Controlled execution, communications and stop criteria
- Control measurement, detection gaps and purple teaming
- Executive report, technical report and improvement plan
Learning approach
Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.
Reference source: MITRE ATT&CK Enterprise ↗
Strictly defensive and authorised training focused on control validation. It does not award a MITRE certification.
Strictly defensive and authorised training focused on control validation. It does not award a MITRE certification.
