Training: Initial Access Operations (IAO)

Initial Access Operations (IAO)

One of the most critical aspects of any Red Team Assessment is obtaining initial access into your target’s environment. The ability to capture valid credentials or execute code within your target’s environment is the first step toward accomplishing the rest of your assessment goals.

IAO Syllabus

Course Details

You will learn a variety of techniques used by attackers to phish companies and then write their own malware in a hands-on environment.

Key Takeaways

  • Understanding Development Methodology– Nearly all of Initial Access Operations is designed to have you write your own malware, however if you don’t know how to start, how do you? This course is designed to walk you through the methodology that our team follows when we write our own malware for our assessments. This isn’t just you being given code and told to figure it out. You’ll understand how we approach accomplishing this task when starting from scratch.
  • Code Injection Techniques– Not everyone knows how easy it is to inject code into your current process. What about placing your code into a malicious process? Even then, with Sysmon having an event dedicated to catching your CreateRemoteThread call, how can you bypass this? Initial Access Operations will show you how to answer all of these questions by performing a deep dive of the various techniques that allow you to perform code injection.
  • Custom Malware – Our class, and the instructors, are here to give you the tools and access to resources which will enable you to take the techniques you’re learning about and applying it to writing your own custom malware. We’ll show how you can expand upon the code samples you’re provided and truly customize the code you write to work only where you want, when you want.

What we provide our students

Students will be provided with all course materials, access to a lab environment for all software development, and all attendees are given custom code samples/templates for use during the course and future research. Finally, all attendees are given access to a Slack environment which will allow all attendees to have direct access to the instructors even after the course has ended.

There is so much to learn packed into a 2 day course and yet I feel like I understood it all. Efficient and well laid out. Highly Recommend. Gregory, Senior Offensive Ops

This course gets you up to speed quickly on the most common initial access attacks being used by attackers today. Just when you think you have a firm grasp on malware and phishing, Chris digs even deeper. Brandon, Red Team Lead

Interested in the training options, including custom training? Contact us for details or questions.