Advanced Adversary Tactics Cyber Range

This cyber range covers a selection of the tactics and techniques represented in the MITRE ATT&CK® Matrix for Enterprise.

4 hours,

The Labs

Train hands-on

  • Sandworm APT Lab 1

    30 minutes
    Sandworm APT is an advanced hacking group that has been active since at least 2009. Most famous for their attacks on Ukrainian electrical companies and the NotPetya attacks in 2016, they are a Russian-backed threat group. In this lab, we’ll take a look at and emulate some of the techniques that Sandworm has used in the past to compromise, pivot from, and destroy a server.
  • Advanced Adversary Tactics - Defense Evasion

    30 minutes
    This lab covers multiple techniques related to defense evasion including crashing an antivirus to avoid detection, modifying PAM to allow for a backdoored password, and going through multiple methods of identifying virtual environments.
  • Advanced Adversary Tactics - Privilege Escalation XSS

    30 minutes
    This lab will cover using XSS techniques to steal tokens from other users and using these tokens to escalate to admin privileges.
  • Advanced Adversary Tactics - Reconnaissance and Resource Development

    30 minutes
    The first steps of the MITRE ATT&CK chain focus on learning about a target and gathering information for future attacks. This sort of information gathering can be instrumental to the success of future operations. For example, learning that a target uses a standard IT management software could cause an APT to target this software in a supply-chain vulnerability attack later on. In this lab we’ll take a look at some of the social engineering techniques and tools that can help aid Reconnaissance and Resource Development.
  • Sandworm APT Lab 2

    30 minutes
    Sandworm APT is an advanced hacking group that has been active since at least 2009. Most famous for their attacks on Ukrainian electrical companies and the NotPetya attacks in 2016, they are a Russian-backed threat group. In this lab we’ll take a look at and emulate some of the techniques that Sandworm has used in the past to compromise, pivot from, and destroy a server.
  • Advanced Adversary Tactics - Persistence

    30 minutes
    This lab covers multiple techniques related to persistence including tampering with desktop autostart application, .bashrc files, trojanizing binaries, and infecting a USB drive.
  • Advanced Adversary Tactics - Persistence 2

    30 minutes
    This lab covers multiple techniques related to persistence including creating a malicious browser extension and modify system processes.
  • Advanced Adversary Tactics - Pivoting with Proxychains

    30 minutes
    This lab covers configuring and using proxychains to pivot between machines on a network. The lab simulates pivoting that might occur were a raspberry pi or similar device added to a network.

Plans & pricing

Infosec Skills Personal

$299 / year

  • 190+ role-guided learning paths (e.g., Ethical Hacking, Threat Hunting)
  • 100s of hands-on labs in cloud-hosted cyber ranges
  • Custom certification practice exams (e.g., CISSP, Security+)
  • Skill assessments
  • Infosec peer community support

Infosec Skills Teams

$799 per license / year

  • Team administration and reporting
  • Dedicated client success manager
  • Single sign-on (SSO)
    Easily authenticate and manage your learners by connecting to any identity provider that supports the SAML 2.0 standard.
  • Integrations via API
    Retrieve training performance and engagement metrics and integrate learner data into your existing LMS or HRS.
  • 190+ role-guided learning paths and assessments (e.g., Incident Response)
  • 100s of hands-on labs in cloud-hosted cyber ranges
  • Create and assign custom learning paths
  • Custom certification practice exams (e.g., CISSP, CISA)
  • Optional upgrade: Guarantee team certification with live boot camps

Learn about scholarships and financing with

Affirm logo

Unlock 7 days of free training

  • 1,400+ hands-on courses and labs
  • Certification practice exams
  • Skill assessments