Offensive Security

CA404: Adversary Emulation with MITRE ATT&CK

Course authored by:

Drinor Selmanaj, Perparim Mjeku, Rinor Shehu, Altin Gashi

41 Hours of Instruction

Includes lectures, guest speakers, and Q&A sessions

Hands-on labs

10 Labs

Live Online or On-Demand Access

Join weekly synchronous sessions or access all material and recorded lectures anytime

Advanced Level

Advanced content for seasoned professionals seeking specialization

Prerequisite

  • CA401 Linux Operations
  • CA403 Windows Security
  • CA305 Enterprise Pen-testing

Course Overview

Adversary emulation is not about simulating attacks — it is about replicating real threat behavior to expose defensive weaknesses. You analyze advanced persistent threats, map their tactics and techniques to MITRE ATT&CK, and execute emulation scenarios in controlled environments. The course bridges red and blue teams through threat-informed defense, applying cyber threat intelligence to strengthen detection and response. By the end, you can design, execute, and evaluate adversary emulation exercises to measurable effect.

What You’ll Learn

* Analyze APT tactics, techniques, and procedures using the MITRE ATT&CK framework
* Develop adversary profiles and build structured emulation plans
* Plan and execute engagements with defined scope and rules of engagement
* Assess detection and response capabilities across security operations
* Report findings to strengthen defensive posture and organizational resilience

Business Takeaways

* Identify gaps in detection, response, and mitigation through realistic threat scenarios
* Improve collaboration between red, blue, and purple teams
* Optimize security investments based on evidence, not assumptions
* Enable continuous improvement through repeatable, structured testing

Syllabus: 4 Sections to Transformation

The CA404 program focuses on turning attacker behavior into structured, repeatable security testing. It covers everything from mapping real-world TTPs to building and executing adversary emulation plans across enterprise environments.

syllabus overview

Justify Training to Your Manager

Section 1

FOUNDATIONS: ADVERSARY THINKING & ATT&CK FRAMEWORK

Establish how modern attackers operate and why traditional security assessments fall short.
Learn how the ATT&CK framework models real-world behavior across the full attack lifecycle.

TOPICS COVERED

  • Adversary emulation vs pentesting vs red teaming.
  • Advanced Persistent Threats (APT) behavior and motivations.
  • MITRE ATT&CK structure (tactics, techniques, procedures).
  • Attack lifecycle phases from reconnaissance to impact.
  • Mapping attacker behavior to defensive strategies.

LABS

  • ATT&CK Navigator Mapping
  • Assessment Type Analysis

Section 2

APPLICATION: REAL-WORLD TTPs, VISUALIZATION & INTELLIGENCE

Shift into how attacks are executed in practice and how defenders interpret them.
Use visualization and intelligence to translate raw data into actionable security insights.

TOPICS COVERED

  • Execution of real-world TTPs (phishing, credential access, lateral movement).
  • Step-by-step adversary techniques and procedures.
  • ATT&CK Navigator and coverage visualization.
  • Cyber Threat Intelligence collection and enrichment.
  • Mapping intelligence reports to ATT&CK techniques.

LABS

  • TTP Execution Chain
  • Threat Coverage Visualization
  • CTI Enrichment & Gap Analysis

Section 3

DESIGN: ADVERSARY EMULATION PLANNING & IMPLEMENTATION

Develop structured approaches to simulate adversaries within enterprise environments.
Focus on building realistic emulation plans aligned with organizational objectives.

TOPICS COVERED

  • Defining adversary emulation goals and objectives.
  • Selecting and profiling threat actors.
  • Building TTP outlines and adversary models.
  • Engagement planning (scope, rules, communication).
  • Implementing adversary tradecraft in controlled environments.
  • Detection mapping and mitigation alignment.

LABS

  • Emulation Plan Document
  • Tradecraft Implementation

Section 4

EXECUTION: AUTOMATION, OPERATIONS & REAL ADVERSARY SCENARIOS

Bring emulation plans to life through execution, measurement, and iteration.
Validate defenses by simulating real attacker campaigns and analyzing outcomes.

TOPICS COVERED

  • Executing adversary TTPs and documenting results.
  • Measuring detection and response effectiveness.
  • Automation tools (Caldera, Atomic Red Team).
  • Adversary emulation resources and libraries.
  • Full campaign simulations (financial, state-sponsored, espionage scenarios).
  • Reporting findings and improving security posture.

LABS

  • Atomic Red Team Testing
  • Caldera Campaign Simulation
  • Structured Adversary Emulation Report.

Course Schedule
& Pricing

Looking for Group Purchase Options? See below

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Frequently Asked Questions

Mission-critical information for prospective operatives

What is adversary emulation and how is it different from traditional testing?

Adversary emulation is a security assessment approach that mimics real-world attackers using their actual tactics, techniques, and procedures (TTPs). Unlike traditional penetration testing, which focuses on finding vulnerabilities, adversary emulation evaluates how well an organization can detect and respond to realistic attacker behavior across the full attack lifecycle.

The book explains that focusing only on indicators like IPs or hashes is ineffective because attackers can easily change them. Instead, it highlights the importance of analyzing TTPs (attacker behavior), which are much harder to modify and provide stronger detection capabilities, as illustrated by the “Pyramid of Pain” concept.

The book uses MITRE ATT&CK as a structured framework to model and map attacker behavior across different stages such as reconnaissance, execution, persistence, and exfiltration. This provides a common language that helps both red and blue teams understand, simulate, and defend against real threats.

According to the book, the goal is to assess an organization holistically by testing people, processes, and technology using realistic threat scenarios. It helps identify detection gaps, improve response capabilities, and align defenses with actual threats instead of theoretical risks.

The book highlights that adversary emulation reduces the gap between red and blue teams by encouraging shared understanding and collaboration. Instead of competing, both sides work together to test defenses, validate detections, and continuously improve the organization’s security posture.