Red Team Level 3
MotiGraph
Track

Red Team Level 3

The expert tier: an integrated OSEP, OSWE and OSED preparation path across advanced evasion, white-box web exploitation and Windows user-mode exploit development — the three specialisations that together map to OSCE3.

36 Courses
161 Lessons
278 Hours
34 Weeks
Advanced Level
  • Advanced Evasion
  • Exploit Development
  • Web Exploitation
  • Reverse Engineering
  • OSEP
  • OSWE
  • OSED
  • OSCE3
About This Track

What You Are Signing Up For

This is the final level of the Red Team route, and it is not more of the same. The two levels before it taught three similar offensive skills each; this level teaches three genuinely different specialisations that only a security researcher holds together. OSEP takes you past defences that stop everyone else — client-side attack chains, application allow-listing bypass, advanced antivirus and EDR evasion, process injection and enterprise Active Directory exploitation. OSWE turns you from a black-box web tester into a white-box one who reads source code and builds a custom exploit from it, from SSRF and deserialisation to a full remote-code-execution chain. OSED is different again: reverse engineering and Windows user-mode exploit development, from a buffer overflow through DEP and ASLR bypass to custom shellcode. It is twenty-five percent advanced theory and seventy-five percent lab work, and it ends with three separate expert assessments, one per specialisation.

  • Three real specialisations, not three variations: advanced evasion, web exploit development and binary exploit development.
  • Seventy-five percent hands-on across Windows internals, source-code review and exploit-development labs.
  • White-box web work: read the source, find the bug, write the exploit, reach RCE.
  • Windows user-mode exploit development: reverse engineering, DEP and ASLR bypass, custom shellcode.
  • Ends with three separate expert assessments, one for each of OSEP, OSWE and OSED.

What You Will Be Able to Do

  • Build multi-stage client-side attack chains and bypass application allow-listing.
  • Evade modern antivirus and EDR by understanding, and testing, how they detect.
  • Chain advanced Active Directory and forest attacks with defence in the way.
  • Recover and read application source code, and trace user input to a dangerous sink.
  • Develop custom web exploits: SSRF, deserialisation, prototype pollution and RCE chains.
  • Reverse engineer a Windows binary and discover a memory-corruption vulnerability.
  • Write a working exploit, bypass DEP and ASLR, and deliver custom shellcode.
  • Turn a discovered vulnerability into a documented, reliable proof of concept.

Requirements

  • Red Team Levels 1 and 2, or equivalent experience.
  • Solid pentesting, Windows, Active Directory and networking.
  • Programming: Python and PowerShell, with C/C++ and assembly for the exploit-development track.
  • This is an expert track — it is not an entry point.

Who It Is For

  • Experienced penetration testers moving to the advanced level.
  • Red team operators specialising in evasion and advanced exploitation.
  • Web security researchers focused on white-box testing and source-code analysis.
  • Aspiring exploit developers entering reverse engineering and binary exploitation.
  • Security researchers turning vulnerabilities into working exploits in authorised labs.

This is a preparation and training track for OSEP, OSWE and OSED — not those certifications. The official exams and requirements are set and awarded only by OffSec, and passing all three grants OSCE3 through OffSec, not through this track. Everything here — advanced evasion, exploit development, source-code exploitation — is carried out in authorised, isolated lab environments only, never against systems you do not own or have explicit permission to test.

Skills

What You Will Learn

Advanced Evasion (OSEP)

  • Windows internals: processes, memory, PE format and the APIs
  • Offensive PowerShell and .NET tradecraft
  • Client-side attack development and initial-access chains
  • Application allow-listing bypass and LOLBAS
  • Advanced AV and EDR evasion, and process injection
  • Advanced Active Directory and forest exploitation

Web Exploitation (OSWE)

  • Modern web architecture and white-box methodology
  • Source-code recovery and manual code review
  • Advanced SSRF and internal access chains
  • Prototype pollution, persistent XSS and session hijacking
  • .NET deserialisation and blind SQL injection to RCE
  • File-upload filter bypass and fuzzing for discovery

Exploit Development (OSED)

  • Reverse engineering with WinDbg and IDA
  • Windows memory, the stack and binary analysis
  • Buffer overflow exploitation and register control
  • Custom shellcode development
  • DEP bypass with ROP, and ASLR bypass
  • Format-string vulnerabilities and reliable exploits

Research Method

  • Vulnerability research as a repeatable process
  • Root-cause analysis, not just a working payload
  • Proof-of-concept then reliable exploit
  • Documentation an exam and a client both require
Hands On

What You Will Build

Every project below is yours to keep and to show. By the end you have a portfolio, not a certificate alone.

Specialisation Labs

  • OSEP lab: initial access, defence bypass, internal access and AD
  • OSWE lab: source code to code review to custom exploit to RCE
  • OSED lab: binary to reverse engineering to exploit to mitigation bypass to shellcode

Expert Assessment

  • Challenge 1 (OSEP): a corporate lab solved as a multi-stage attack chain
  • Challenge 2 (OSWE): a web application with source, exploited from analysis to RCE
  • Challenge 3 (OSED): a vulnerable Windows binary, exploited with a mitigation bypass and custom shellcode

Graduation Project

You finish not with one capstone but with three, because the level is three specialisations. In the OSEP challenge you take a corporate lab as a multi-stage attack chain that gets past its defences. In the OSWE challenge you are handed a web application with its source code and must analyse it, find the vulnerability, understand the root cause, build a proof of concept and drive it to remote code execution, documenting the exploit as you go. In the OSED challenge you are given a vulnerable Windows binary and must reverse engineer it, find the flaw, develop the exploit, bypass its mitigations and deliver custom shellcode inside the lab. Each is graded the way its certification is.

The Roadmap

Your Path Through This Track

Red Team Level 3 roadmap
The Route

Course by Course

36 modules · 161 lessons. Open any module to see what is inside it.

  1. 01 OSEP · OSWE · OSED Advanced Offensive Security Foundation Advanced 6 lessons 6 hours

    The shared groundwork for three very different specialisations. A fast, advanced review of the networking, Windows internals, web architecture and programming — Python, PowerShell, C/C++, .NET and a first look at assembly — that a security researcher

    • Foundation
    • Python
    • C/C++
    • Assembly
    • Advanced networking and web architecture refresher
    • Windows and Linux internals refresher
    • Python and PowerShell for offensive tooling
    • C/C++ and .NET fundamentals for researchers
    • Assembly and debugging concepts, first look
    • Vulnerability research as a method
    Open course
  2. 02 OSEP · OSED Advanced Windows Internals Advanced 6 lessons 10 hours

    What actually happens inside Windows, below the level a pentester ever needs. Processes, threads, handles and virtual memory; DLLs and the PE format; the Windows and native APIs; user mode versus kernel mode; tokens and security descriptors. Both the

    • Windows Internals
    • PE Format
    • Windows APIs
    • OSEP
    • OSED
    • Processes, threads and handles
    • Virtual memory and memory management
    • DLLs and the PE format
    • Windows APIs and native APIs
    • User mode versus kernel mode
    • Tokens and security descriptors
    Open course
  3. 03 OSEP Advanced PowerShell and .NET Advanced 6 lessons 8 hours

    Building your own tooling, and understanding the controls built to stop it. PowerShell internals and the .NET runtime — reflection, delegates, P/Invoke and the Windows APIs — and the security controls you will meet: AMSI, script block logging, constr

    • PowerShell
    • .NET
    • P/Invoke
    • AMSI
    • OSEP
    • PowerShell internals and the .NET runtime
    • Assemblies, reflection and delegates
    • P/Invoke and calling Windows APIs
    • AMSI, script block logging, constrained language mode
    • Application and execution controls
    • Lab: build a small enumeration tool
    Open course
  4. 04 OSEP Client-Side Attack Development Advanced 5 lessons 8 hours

    When the perimeter holds, the way in is a person, and OSEP expects you to build the chain that reaches them. Malicious document and macro concepts, HTA and HTML applications, Windows libraries and shortcuts, and how these combine into a multi-stage i

    • Client-Side
    • Macros
    • HTA
    • Initial Access
    • OSEP
    • Client-side attack concepts
    • Malicious document and macro concepts
    • HTA and HTML applications
    • Windows libraries and shortcuts
    • Building a multi-stage initial-access chain
    Open course
  5. 05 OSEP Application Whitelisting and Execution Controls Advanced 5 lessons 8 hours

    A core PEN-300 subject: getting execution where a policy says you should not have it. Application whitelisting, Windows Defender Application Control and AppLocker, execution policies and trusted applications, and the signed-binary proxy execution — L

    • WDAC
    • AppLocker
    • LOLBAS
    • OSEP
    • Application whitelisting, WDAC and AppLocker
    • Execution policies and trusted applications
    • LOLBins and LOLBAS
    • Signed binary proxy execution
    • The detection surface of a bypass
    Open course
  6. 06 OSEP Advanced Defense Evasion Advanced 6 lessons 10 hours

    Not how do I run a payload, but why is it blocked and how do I test the blocking. AV architecture and EDR, AMSI and security telemetry, static and behavioural detection, memory scanning and userland monitoring, and the payload-customisation and execu

    • AV
    • EDR
    • AMSI
    • Evasion
    • OSEP
    • AV architecture and EDR concepts
    • AMSI and security telemetry
    • Static and behavioural detection
    • Memory scanning and userland monitoring
    • Payload customisation and execution tradecraft
    • Lab: testing a detection mechanism
    Open course
  7. 07 OSEP Process Injection and In-Memory Execution Advanced 5 lessons 8 hours

    Running code without touching disk, and understanding why that matters against modern defences. Process architecture and injection concepts, memory allocation and remote threads, DLL injection and thread context, and the reflective-loading and stagin

    • Process Injection
    • In-Memory
    • Reflective Loading
    • OSEP
    • Process architecture and injection concepts
    • Memory allocation and remote threads
    • DLL injection concepts and thread context
    • In-memory execution and reflective loading
    • Payload staging
    Open course
  8. 08 OSEP Advanced Active Directory Exploitation Advanced 6 lessons 10 hours

    Building on the CRTP and CRTO work from Level 2, but now with defences in the way and a forest as the target. Cross-domain attacks and trust relationships, advanced AD attack chains, multi-stage exploitation and domain-persistence concepts, taken fro

    • Active Directory
    • Forest
    • Attack Chains
    • OSEP
    • Forest architecture and cross-domain attacks
    • Trust relationships and credential access
    • Advanced AD attack chains
    • Multi-stage exploitation with defence present
    • Domain persistence concepts and enterprise objectives
    • Lab: foothold to enterprise objective
    Open course
  9. 09 OSEP Advanced Lateral Movement Advanced 4 lessons 6 hours

    Moving through an enterprise while defences watch. Windows Remote Management, SMB, WMI, DCOM and PowerShell Remoting; credential-based and token-based movement; and the multi-hop internal attack chains that reach the target through the network rather

    • Lateral Movement
    • WMI
    • DCOM
    • OSEP
    • WinRM, SMB, WMI and DCOM
    • PowerShell Remoting
    • Credential-based and token-based movement
    • Multi-hop internal attack chains
    Open course
  10. 10 OSEP Red Team Campaign Automation Advanced 4 lessons 6 hours

    Turning a proven attack into repeatable tradecraft. Automation with PowerShell, Python and .NET; payload generation and staging; attack chaining; and the operator workflow that lets one person run a campaign the same way twice.

    • Automation
    • PowerShell
    • Python
    • OSEP
    • Automation with PowerShell, Python and .NET
    • Payload generation and staging
    • Attack chaining and operator workflow
    • Repeatable tradecraft
    Open course
  11. 11 OSWE Foundation Advanced Web Application Architecture Advanced 5 lessons 6 hours

    You cannot review code you do not understand, so the OSWE track opens with the architecture underneath a modern application. Client and server, APIs, authentication and authorisation, sessions, routing and middleware, serialization and databases, acr

    • Web Architecture
    • APIs
    • Frameworks
    • OSWE
    • Modern web architecture: client, server, APIs
    • Authentication, authorisation and sessions
    • Routing, middleware and frameworks
    • Serialization and databases
    • Reading across languages: JS, PHP, Java, C#, Python
    Open course
  12. 12 OSWE Web Traffic Analysis and Burp Suite Advanced 4 lessons 6 hours

    The instrument of white-box web work, driven precisely. HTTP requests and responses, cookies, headers and sessions; Burp Proxy, Repeater, Comparer and Decoder; and the request manipulation and scoping that a source-driven exploit depends on.

    • Burp Suite
    • HTTP
    • OSWE
    • HTTP requests, responses, cookies and headers
    • Burp Proxy and Repeater
    • Comparer, Decoder and scope
    • Request manipulation for source-driven exploits
    Open course
  13. 13 OSWE Source Code Recovery Advanced 4 lessons 8 hours

    White-box testing assumes you have the source; often you have to recover it first. Recovering source from managed .NET assemblies and decompiling Java, then reading the recovered application structure — classes, methods, controllers, routing and depe

    • Source Recovery
    • .NET
    • Java Decompilation
    • OSWE
    • Recovering managed .NET source
    • Java decompilation
    • Reconstructing application structure
    • Mapping classes, controllers and routing
    Open course
  14. 14 OSWE White-Box Source Code Analysis Advanced 6 lessons 10 hours

    The central skill of OSWE and the core of WEB-300: finding a vulnerability by reading code, not by throwing payloads. A methodology — understand the architecture, find the entry point, trace user input, identify a dangerous sink, understand the valid

    • Code Review
    • Data Flow
    • Sinks
    • OSWE
    • The code-review methodology
    • Program flow and data flow
    • Sources, sinks and dangerous functions
    • Input validation and sanitization
    • Authentication and authorisation logic
    • Lab: from source to a discovered vulnerability
    Open course
  15. 15 OSWE Advanced SSRF Advanced 4 lessons 6 hours

    Server-side request forgery as a route into the internal network, explicit in the current WEB-300. SSRF architecture and internal services, URL parsing and filter bypass, cloud-metadata concepts, and the SSRF-to-RCE chains that turn a single request

    • SSRF
    • Filter Bypass
    • OSWE
    • SSRF architecture and internal services
    • URL parsing and filter bypass
    • Cloud metadata concepts
    • SSRF to RCE chains
    Open course
  16. 16 OSWE JavaScript Prototype Pollution Advanced 4 lessons 6 hours

    A modern JavaScript class of bug, on the current WEB-300 syllabus. JavaScript objects and the prototype chain, how pollution happens, its client-side and server-side impact, and the gadget chains that carry it toward remote code execution.

    • JavaScript
    • Prototype Pollution
    • Gadgets
    • OSWE
    • JavaScript objects and the prototype chain
    • How prototype pollution occurs
    • Client-side and server-side impact
    • Gadget chains and RCE concepts
    Open course
  17. 17 OSWE Persistent XSS and Advanced Client-Side Exploitation Advanced 4 lessons 6 hours

    Stored cross-site scripting taken past a proof-of-concept alert, on the WEB-300 syllabus. The browser context and session access, application logic and client-side controls, and how a stored payload becomes account compromise or privilege abuse.

    • XSS
    • Client-Side
    • OSWE
    • Stored and persistent XSS
    • Browser context and session access
    • XSS to account compromise
    • Bypassing client-side controls
    Open course
  18. 18 OSWE Session Hijacking Advanced 4 lessons 6 hours

    Advanced session attacks from the WEB-300 syllabus. Session architecture, tokens, storage and validation; session fixation concepts; and how a weakness in session handling becomes authentication bypass and then privilege escalation.

    • Sessions
    • Authentication Bypass
    • OSWE
    • Session architecture, tokens and storage
    • Session validation and fixation concepts
    • Session hijacking
    • Session weakness to privilege escalation
    Open course
  19. 19 OSWE .NET Deserialization Advanced 4 lessons 8 hours

    One of the highest-impact web vulnerability classes and a core WEB-300 topic. Serialization and object graphs, .NET serialization specifically, the gadget chains that make dangerous deserialization exploitable, and developing the exploit that reaches

    • Deserialization
    • .NET
    • RCE
    • OSWE
    • Serialization, deserialization and object graphs
    • .NET serialization specifics
    • Gadget chains
    • Lab: deserialization to RCE
    Open course
  20. 20 OSWE Blind SQL Injection Advanced 4 lessons 6 hours

    Injection where the application tells you nothing directly, on the WEB-300 syllabus. Boolean-based and time-based blind injection, data extraction and DBMS identification, manual versus automated technique, and the concepts that carry blind injection

    • Blind SQLi
    • Data Extraction
    • OSWE
    • Boolean-based blind injection
    • Time-based blind injection
    • Data extraction and DBMS identification
    • Manual versus automated technique
    Open course
  21. 21 OSWE File Upload Security and Filter Bypass Advanced 4 lessons 6 hours

    Bypassing upload restrictions and extension filters, explicit in WEB-300. File-upload architecture, MIME and content validation, extension filters and filename handling, and how a bypass becomes code execution on the server.

    • File Upload
    • Filter Bypass
    • OSWE
    • File-upload architecture and validation
    • MIME, extension and content filter bypass
    • Filename handling flaws
    • Upload to code execution
    Open course
  22. 22 OSWE Fuzzing and Vulnerability Discovery Advanced 5 lessons 8 hours

    Finding what code review alone might miss. Fuzzing concepts and input generation, endpoint and parameter discovery, error and response analysis, automated fuzzing and writing custom fuzzers, and the triage that turns a pile of anomalies into a confir

    • Fuzzing
    • Discovery
    • Triage
    • OSWE
    • Fuzzing concepts and input generation
    • Endpoint and parameter discovery
    • Error and response analysis
    • Automated fuzzing and custom fuzzers
    • Vulnerability triage
    Open course
  23. 23 OSWE Remote Code Execution Chains Advanced 4 lessons 8 hours

    The OSWE finish line: linking primitives into a full compromise. How an initial vulnerability, a primitive, a filter bypass and code execution combine into RCE and system access — worked through the WEB-300 archetypes: deserialization to RCE, SSRF to

    • RCE
    • Chaining
    • OSWE
    • From vulnerability to primitive to code execution
    • Deserialization and SSRF chains
    • SQLi and upload chains
    • Lab: build and document a full RCE chain
    Open course
  24. 24 OSED Foundation Exploit Development Fundamentals Advanced 4 lessons 6 hours

    A different discipline entirely, and it starts with the machine. Memory, processes, the stack and the heap; registers and instructions; assembly and calling conventions; and the debugging that makes all of it visible. Everything in the OSED track bui

    • Exploit Dev
    • Assembly
    • Stack
    • OSED
    • Memory, processes, the stack and the heap
    • Registers and instructions
    • Assembly and calling conventions
    • Debugging fundamentals
    Open course
  25. 25 OSED Reverse Engineering Advanced 5 lessons 10 hours

    Reading a program that came without source, with the tools EXP-301 uses. IDA Pro and WinDbg, disassemblers and debuggers; static and dynamic analysis; function identification, control flow and data flow; and using all of it to find the vulnerability

    • Reverse Engineering
    • IDA
    • WinDbg
    • OSED
    • IDA Pro and WinDbg
    • Static analysis and disassembly
    • Dynamic analysis and debugging
    • Function identification, control and data flow
    • API calls and vulnerability discovery
    Open course
  26. 26 OSED Windows Memory and Binary Analysis Advanced 4 lessons 8 hours

    The binary and the memory it lives in, in detail. The PE format, sections, imports and exports; DLLs; the stack and heap; memory permissions and virtual memory; and the Windows APIs a binary calls — the map an exploit developer navigates.

    • PE Format
    • Memory
    • DLLs
    • OSED
    • PE format: sections, imports, exports
    • DLLs and loading
    • The stack, the heap and memory permissions
    • Virtual memory and Windows APIs
    Open course
  27. 27 OSED Buffer Overflow Exploitation Advanced 5 lessons 10 hours

    The foundational memory-corruption bug, worked end to end. Stack buffer overflow and crash analysis, offset discovery and register control, taking control of the instruction pointer, understanding the memory layout, and building a reliable proof of c

    • Buffer Overflow
    • Register Control
    • OSED
    • Stack buffer overflow and crash analysis
    • Offset discovery
    • Register control and the instruction pointer
    • Memory layout and exploit reliability
    • Lab: a reliable proof of concept
    Open course
  28. 28 OSED Shellcode Development Advanced 4 lessons 8 hours

    Writing the payload the exploit delivers, a required OSED skill. Shellcode architecture and position independence, resolving Windows APIs, designing a custom payload, handling bad characters, encoding, and testing the shellcode until it runs reliably

    • Shellcode
    • Position Independent
    • Encoding
    • OSED
    • Shellcode architecture and position independence
    • Resolving Windows APIs from shellcode
    • Custom payload design and bad characters
    • Encoding and testing
    Open course
  29. 29 OSED DEP Bypass Advanced 4 lessons 8 hours

    The first modern mitigation an exploit must defeat, central to EXP-301. Data Execution Prevention and NX, memory protections, and return-oriented programming — gadget discovery and ROP chains — used to regain execution without executing from data, re

    • DEP
    • ROP
    • Gadgets
    • OSED
    • DEP, NX and memory protections
    • Return-oriented programming concepts
    • Gadget discovery
    • ROP chains and reliability
    Open course
  30. 30 OSED ASLR Bypass Advanced 4 lessons 8 hours

    Defeating address randomisation, the second mitigation EXP-301 tackles. How ASLR randomises addresses, why an information disclosure is the usual answer, using an address leak to find a module base, and combining a leak with ROP into a reliable explo

    • ASLR
    • Info Leak
    • OSED
    • ASLR and address randomisation
    • Information disclosure and address leaks
    • Resolving module bases
    • Combining a leak with ROP
    Open course
  31. 31 OSED Format String Vulnerabilities Advanced 4 lessons 6 hours

    A distinct bug class named in the EXP-301 skills. Format strings and stack analysis, using them to disclose memory and then to modify it, and the concepts that build a reliable exploit out of a formatting mistake.

    • Format String
    • Memory Disclosure
    • OSED
    • Format strings and stack analysis
    • Memory disclosure
    • Memory modification
    • Building a reliable exploit
    Open course
  32. 32 OSED Advanced Exploit Development Advanced 4 lessons 8 hours

    Putting the mitigations, the shellcode and the primitives together into one working exploit. Multi-stage exploitation, custom ROP and API resolution, payload integration, and the debugging and troubleshooting that turn a fragile crash into a reliable

    • Multi-Stage
    • Custom ROP
    • Reliability
    • OSED
    • Multi-stage exploitation
    • Custom ROP and API resolution
    • Payload integration and reliability
    • Debugging and troubleshooting an exploit
    Open course
  33. 33 OSED Exploit Development with Python Advanced 4 lessons 6 hours

    The language that ties an exploit together, a stated EXP-301 prerequisite. Python for sockets and binary data, packing and unpacking memory addresses, and automating exploitation and testing so an exploit can be run and re-run reliably.

    • Python
    • Sockets
    • Automation
    • OSED
    • Python sockets and binary data
    • Packing and unpacking memory addresses
    • Automating exploitation
    • Exploit testing
    Open course
  34. 34 OSWE · OSED Integrated Vulnerability Research Advanced 4 lessons 8 hours

    Where web and binary research turn out to be the same discipline. One research cycle applied to an application or a binary: recon, source or binary analysis, find the vulnerability, understand the root cause, develop a proof of concept, develop the e

    • Vulnerability Research
    • PoC
    • OSWE
    • OSED
    • Recon: application or binary
    • Source or binary analysis to a vulnerability
    • Root cause and proof of concept
    • Exploit development, validation and documentation
    Open course
  35. 35 OSEP · OSWE · OSED Expert Offensive Security Labs Advanced 3 lessons 10 hours

    Three lab tracks, one per specialisation, run end to end. Lab A (OSEP): initial access, a defence mechanism, a bypass, internal access and AD. Lab B (OSWE): source, code review, a vulnerability, a proof of concept, a custom exploit and RCE. Lab C (OS

    • Labs
    • OSEP
    • OSWE
    • OSED
    • Lab A (OSEP): access, bypass, internal, AD
    • Lab B (OSWE): source to custom exploit to RCE
    • Lab C (OSED): binary to exploit to shellcode
    Open course
  36. 36 Capstone Final Expert Offensive Security Assessment Advanced 3 lessons 12 hours

    Not one CTF but three challenges, one per certification. Challenge 1 (OSEP): a corporate lab solved as a multi-stage attack chain. Challenge 2 (OSWE): a web application handed to you with its source, taken from analysis to RCE and documented. Challen

    • Capstone
    • OSEP
    • OSWE
    • OSED
    • Challenge 1 (OSEP): advanced red team
    • Challenge 2 (OSWE): advanced web
    • Challenge 3 (OSED): exploit development
    Open course
After the Track

Roles This Track Prepares You For

  • Advanced Penetration Tester
  • Red Team Specialist
  • Web Security Researcher
  • Exploit Developer
  • Vulnerability Researcher
  • Offensive Security Engineer
  • Malware and Detection Researcher
  • Security Consultant — Senior
Same Diploma

Other Tracks in This Diploma

Red Team Level 1 Red Team Level 1 Track Beginner

Red Team Level 1

The complete offensive-security foundation: an integrated CEH, eJPT and OSCP+ preparation path, from cybersecurity fundamentals to OSCP-level practical pentesting.

  • Ethical Hacking
  • Penetration Testing
  • CEH
  • eJPT
  • OSCP+
  • Active Directory
  • Linux
  • Windows
  • One continuous route across CEH, eJPT and OSCP+ — not three disconnected courses.
  • Sixty to seventy percent hands-on labs, in authorised training environments only.
  • Real depth where OSCP+ demands it: Active Directory, privilege escalation, pivoting and reporting.
  • Ends with a full corporate pentest and a professional written report.
Red Team Level 2 Red Team Level 2 Track Advanced

Red Team Level 2

The jump from penetration tester to red team operator: an integrated CRTP, PNPT and CRTO preparation path across enterprise Active Directory, professional network engagements, Command & Control and OPSEC.

  • Red Team
  • Active Directory
  • Cobalt Strike
  • C2
  • CRTP
  • PNPT
  • CRTO
  • Adversary Simulation
  • One continuous route across CRTP, PNPT and CRTO — enterprise AD, professional engagements and C2.
  • Seventy percent hands-on in enterprise AD, internal network and C2 labs.
  • Real red team tradecraft: Cobalt Strike, C2 infrastructure, OPSEC and detection awareness.
  • Ends with a full enterprise adversary simulation across a multi-domain forest.
Blue Team Level 1 Blue Team Level 1 Track Beginner

Blue Team Level 1

The defensive foundation: an integrated Security+, BTL1 and SC-200 preparation path, from cybersecurity fundamentals to working a SOC on the Microsoft security stack.

  • Security+
  • BTL1
  • SC-200
  • SOC
  • SIEM
  • Microsoft Sentinel
  • Defender
  • Incident Response
  • One continuous route across Security+, BTL1 and SC-200 — fundamentals to a working SOC analyst.
  • Built around the tools a SOC actually uses: a SIEM, Microsoft Sentinel and Defender, and KQL.
  • Fourteen practical labs, from packet analysis to a full incident investigation.
  • Ends with a complete SOC investigation, triaged, hunted and reported.
Certified

Certificates You Can Earn

Finish your course and receive an accredited MotiGraph certificate you can add to your CV and share with employers.

MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample