Training: Offense for Defense (O4D)
Blue team, meet your next must-have skillset.
Join us for Offense for Defense, a high-impact, hands-on cybersecurity course built specifically for blue team professionals, systems administrators, SOC analysts, threat hunters, and incident responders. This training arms defenders with the tactics, tools, and mindset of attackers, empowering teams to proactively identify weaknesses and design better detection and response. All while learning from one of the most prominent names in cybersecurity instruction and enterprise penetration testing, Tim Medin.
Through Tim and Offensive Security Consultant and Social Engineering Expert Jason Downey, you will gain real-world experience with tools like Atomic Red Team and the MITRE ATT&CK Framework, simulating real attacks to test and enhance your defensive posture. From OSINT and initial access vectors to Active Directory attacks, evasion tactics, privilege escalation, and lateral movement, you’ll walk away with actionable skills to harden your environment against the most persistent threats.
Join cybersecurity teams across the globe who are transforming their defense strategies with offensive knowledge. Don’t Just Play Defense – Own the Field.
Course Offerings
On-Demand:
$749
In Person:
Wild West Hackin’ Fest Deadwood – October 6-7, 2026
Lab Environment
You’ll be working from a Kali Linux and a Windows system to access other Windows systems on the same Active Directory Domain, but with the easiest setup ever.
In fact, there is no setup. It is all accessible and handled in your browser! No giant downloads. No messing with VMware. No annoying VPN setup. No configuration or compatibility issues.
Unlike the big guys, your lab network is specific to you. No one (but you) can break your network. And you can revert your lab network anytime you want to. You can access the lab network immediately after you sign up. Like we said, no giant downloads, funky setup, or VPN issues.
What You Will Be Able to Do
*denotes the section has a practical, hands-on lab exercise
Understand the Adversary Mindset
- Think like an attacker to defend like a pro
- Understand why offensive techniques matter for defenders
- Gain strategic insight into attacker behavior, and how it lets you get ahead
**Practical Attack Emulation ***
- Realistic attack simulation using Atomic Red Team
- Leveraging the MITRE ATT&CK framework for detection engineering
- Building resilient detections by simulating adversarial Tactics, Techniques, and Procedures (TTPs)
**OSINT & Recon: What Attackers Know Before the Breach ***
- Understand what information is interesting to an attacker, and why
- See your organization the way an attacker does
- Enumerate your external footprint and exposure without scanning
- Understand public data exposure risks
Initial Access Techniques & Detection
- Understand the most common methods attackers use to gain initial access
- Learn why social engineering, phishing, and vishing are so effective and what you can do to help prevent it
- Understand the impact of credential attacks, phishing, and public-facing exploits
**Password Attacks – Credential Stuffing and Password Guessing ***
- Account defenses using password managers, MFA, passkeys, and hardware keys
- Protecting accounts with Managed Service Accounts (MSA, lMSA, and gMSA) and Local Administrator Password Solution (LAPS)
- Practical effective and safe password stuffing/guessing techniques
Evading Detection
- Understand how and why attackers evade defenses
- Effective evasion by Living Off the Land (LOL) and using built-in tools and features
- Strategies for implementing Application Control (formerly Application Whitelisting)
**Privilege Escalation (PrivEsc) and Persistence ***
- Understand common techniques for PrivEsc and Persistence including registry, service, and scheduled task abuse
- Practical steps to identify PrivEsc opportunities, allowing you to mitigate before the breach
- Understand different types of persistence and the pros and cons of each
**Abusing Built-in Windows Protocols ***
- Understand the weaknesses of NBNS, LLMNR, mDNS and other protocols and how they can be abused to leak access
- Coercing authentication and relay attacks
- Using Responder to gain credentials
**File Share Pillaging and Data Exposure Identification ***
- Understand the risks of overshared information, even if it is on internal systems
- Common misconfigurations in SMB/NFS shares
- Share auditing and cleanup playbooks
**Lateral Movement ***
- Understand why attackers move their goals
- Learn why attackers don’t need super privileged accounts (e.g., Domain Admin) to accomplish their goals
- Execute practical lateral movement attacks using common tools and protocols
**Practical Kerberos ***
- Learn Kerberoasting from the creator himself (Tim Medin), as well as other Kerberos attacks
- Understand other common Kerberos attacks (Silver Ticket, Golden Ticket, Over-pass-the-Hash, Pass-the-Ticket)
- Understand secure Kerberos implementation and delegation
**Active Directory (AD): Defense at the Core ***
- Understand AD misconfigurations and their risk to the organization
- Hardening and monitoring guidance for AD
- Identify AD misconfigurations and vulnerabilities using PingCastle and Bloodhound
**Active Directory Certificate Services (AD CS) ***
- Common AD CS misconfigurations that can lead to privilege escalation, data theft, and persistence
- Practical exploitation techniques for abusing AD CS
- Remediation and secure implementation best practices
Hands-On Labs
- Guided exercises for each attack/defense concept
- Simulated network environments
- Practical takeaways
- Full video walkthrough of every lab exercise.
What we provide our students
Zero Setup. Total Control.
No virtual machines. No VPNs. No downloads.
Just launch your browser and you’re in.
- Work directly from Kali Linux + Windows systems in a dedicated lab
- Your lab is yours alone – no shared networks, no interference
- Break it, revert it, reset it – on your terms
- Instant access after signup – no waiting, no fuss
Access to Red Siege Instructors.
All students will have the ability to ask questions during, and after completion to the Red Siege instructors via our Discord
Certification of Completion.
All students will be presented a certification of completion at the end of the course to the email provided. Get Started Now
Tim and Jason are fun presenters, that’s for sure! I really enjoyed the Sliver and Kerberoasting sections and learning how to figure out what to go after and then the insight on how to approach fixes!
Henry R., Cybersecurity Analyst
It is nice to have a breakdown of the fundamentals. I feel like this course is good for people wanting to refresh their Active Directory Knowledge or understand the overall Offense for Defense mentality!
Micheal K., Security Consultant
Overall, the information was helpful and the provided remediations are a great starting point to improving and building on my organization's security posture.
Alexi M., Incident Responder
Interested in the training options, including custom training? Contact us for details or questions.
Name:
First
Last
Company:
Email:
Describe Your Training Request:
Message:
REQUEST INFORMATION ON TRAINING