Skip to content

Mastering breach and adversarial attack simulation engagements

Description

Name of Training: Mastering Breach and Adversarial Attack Simulation Engagements
Trainer: ABX
Dates: November 08-09, 2026
Time: 9:00 am - 5:00 pm
Venue: Exhibition World Bahrain
Cost: 1200 BHD

Important Note: This training is exclusively available to government entities and participants from GCC countries.

1. Short Summary

Participants learn to safely emulate real-world threat actors and unknown adversaries in controlled enterprise environments, selecting from a wide range of offensive tradecraft and TTPs to plan and execute realistic attack simulation engagements. The course also covers AI-assisted attack simulation and modern offensive cyber security techniques, equipping defenders to rigorously assess and strengthen their organization’s cyber defense posture.

2. Course Description

The hands-on training provides participants with a deeper understanding of advanced offensive cyber security operations, breach simulation, and adversary emulation engagements. Participants learn to safely emulate real-world threat actors and unknown adversaries in controlled enterprise environments, selecting from a wide range of offensive tradecraft and TTPs to plan and execute realistic attack simulation engagements.

A significant portion of the course is dedicated to Cobalt Strike, the de facto enterprise C2 framework, Malleable C2 profiles, Beacon operations, lateral movement, and enterprise AD compromise simulation exercises against modern detection stacks.

Participants will also work with AI-assisted adversary simulation, including the use of locally hosted uncensored open-source models for tasks where commercial frontier models refuse or sanitize the output, supporting workflows such as malware variant generation, evasion refactoring, pretext crafting, and on-the-fly TTP recommendation during live engagements.

Building on this, the course introduces agentic breach simulation, where autonomous agents drive multi-stage attack chains and adapt to defensive responses, alongside supply chain attack simulations that mimic one of the fastest-growing categories of real-world breaches.

The training benefits both offensive and defensive professionals: red teamers sharpen their tradecraft and C2 operations, while SOC analysts, detection engineers, and blue teamers gain visibility into modern attacker behaviors, including AI-assisted evasion, so they can harden their environments against the threat actor playbooks actually being used today.

Participants who opt to take the proficiency exam at the end of the program will receive the CBAS certification, formally recognizing their capability to plan, lead, and execute enterprise-grade breach and adversary simulation engagements.

3. Course Outline

PART I - Foundations and Adversary Emulation

Module 1: Taking the First Step - Understanding the Fundamentals

3.1.1 Introduction to offensive cyber security operations
3.1.2 Adversary emulation vs adversary simulation
3.1.3 Assessing return on investment (ROI)
3.1.4 Breach and attack simulation (BAS)
3.1.5 Cyber threat intelligence and threat-informed defense
3.1.6 Cyber defense systems, blue teams, and the importance of purple teaming
3.1.7 Frameworks and standards: MITRE ATT&CK matrix, Cyber Kill Chain
3.1.8 Evolution of threat actors
3.1.9 Red teaming
3.1.10 Adversarial Exposure Validation
3.1.11 Introduction to AI-assisted offensive operations and agentic adversary simulation
3.1.12 Supply chain compromise as a dominant breach category

Module 2: Introduction to Adversary Emulation Engagements

3.2.1 Adversary emulation kickoff in your organization

  • Adversary emulation exercises

3.2.2 Collecting actionable cyber threat intelligence from public sources

  • Threat Report ATT&CK Mapper (TRAM)

3.2.3 Identifying and selecting TTPs to emulate, building an emulation plan

3.2.4 Performing and executing adversary emulation engagements to test cyber defenses

3.2.5 Testing endpoint security controls with adversary emulation techniques

3.2.6 Open-source projects for effective emulation of threats

3.2.7 Adversary emulation - Atomic Red Team

  • Executing Atomic Red Team

3.2.8 Adversary emulation - MITRE Caldera project

  • Getting started with the Caldera project
  • Deploying Caldera in your organization's environment
  • Emulating threat actors with Caldera
  • Emulating known threat actors with Caldera ATT&CK Navigator
  • Using VECTR for generating reports and documentation
  • Using AI/GPT systems for practical threat-intel-powered adversarial attack emulation

3.2.9 AI-assisted adversary simulation in practice

  • Locally hosted uncensored open-source models for tasks where commercial frontier models refuse or sanitise output
  • AI-driven workflows: malware variant generation, evasion refactoring, pretext crafting, on-the-fly TTP recommendation during live engagements
  • Operational security considerations for AI in red team workflows

PART II - Offensive Tradecraft, Loaders, and Cobalt Strike

Module 3: Breach and Adversary Simulation - Infrastructure and Tradecraft

3.3.1 Introducing the breach and adversary simulation range lab environment

3.3.2 Adversary and red team infrastructure

Building efficient adversary infrastructure: this module gives an overview of building production-ready red team infrastructure to bypass and validate the defenses of your organization.

  • Redirector design and traffic shaping
  • Domain fronting, categorisation, and reputation building
  • Phishing infrastructure and mail relays
  • OPSEC considerations for long-running engagements

3.3.3 Breach simulation lab infrastructure - guided walkthrough

4. Difficulty Level

Intermediate - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.

5. What Students Should Bring

Laptop

Minimum requirements:

  • CPU cores: 4 (8 recommended)
  • RAM: 16 GB (32 GB recommended)
  • Disk: 500 GB (1 TB recommended)
  • 6. What the Trainer Will Provide

During the training, students will be provided with:

  • All labs are hosted in AWS.
  • Studnets will have access to LMS.

7. Trainer(s) Bio

Abhijith B R (ABX)

Abhijith B R, also known by the pseudonym Abx, has more than a decade of experience in the offensive cyber security industry. He is a professional hacker, offensive cyber security specialist, red team consultant, security researcher, trainer and public speaker.

Currently, he is building BreachSimRange.io as a founder, director and involved with multiple organizations as a consulting specialist, to help them build offensive security operations programs, improve their current security posture, assess cyber defense systems, bridge the gap between business leadership and security professionals.

Abhijith was responsible for building and managing offensive security operations and adversary simulation for a prominent FinTech company called Envestnet, Inc. In the past, he held the position of Deputy Manager - Cyber Security at Nissan Motor Corporation, and prior to that, he worked as a Senior Security Analyst at EY.

As the founder of Adversary Village (https://adversaryvillage.org/), Abhijith spearheads a community initiative focused on adversary simulation, adversary-tactics, purple teaming, threat actor/ransomware research-emulation, and offensive cyber security. Adversary Village is part of DEF CON Villages and organizes hacking villages at prominent events such as the DEF CON Hacking Conference, RSA Conference etc.

Abx also acts as the Lead of an official DEF CON Group named DC0471. He is actively involved in leading the Tactical Adversary project (https://tacticaladversary.io/) a personal initiative that centers around offensive cyber security, adversary attack simulation and red teaming tradecraft.

Abhijith has spoken at various hacking and cyber security conferences such as, DEF CON hacker convention - Las Vegas, RSA Conference - San Francisco, The Diana Initiative - Las Vegas, DEF CON 28 safemode - DCG Village, Opensource India, Security BSides Las Vegas, BSides San Francisco, BSides Tampa, Hack Space Con - Kennedy space center Florida, Nullcon - Goa, c0c0n - Kerala, BSides Delhi etc.

8. Registration Terms and Conditions

8.1 Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.

8.2 Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.

8.3 All trainings are non-refundable after October 21, 2026.

8.4 Training tickets may be transferred to another student. Please email us at training@defcon.org for specifics.

8.5 If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).

8.6 Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.

8.7 DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.

8.8 By purchasing this ticket you agree to abide by the DEF CON Training Code of Conduct and the registration terms and conditions listed above.

Sale price 1,200 BD

Options
Back to top