Red Team Operations and Adversary Emulation
Red teaming is more than exploitation; it is a planned operation against a defended organization, judged by what defenders learn. This red team training covers the full engagement lifecycle, from objectives and rules of engagement to infrastructure, command and control, or C2, and adversary emulation.
You emulate real threat actor behaviour mapped to the MITRE ATT&CK framework, work quietly against a monitored lab environment, and write reporting that turns your activity into concrete detection and prevention improvements.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Enterprise Penetration Testing
- Class size
- Capped at 12 learners

What you will be able to do
- Plan a red team engagement with clear objectives and rules of engagement
- Stand up resilient command and control infrastructure for an operation
- Emulate a named threat actor using techniques mapped to MITRE ATT&CK
- Move through a monitored environment while managing detection risk
- Adjust tradecraft in response to what the blue team detects
- Write an attack narrative tied to specific detection opportunities
- Run a debrief that leaves defenders with a prioritised action list
Course outline
5 modules
- Objectives, threat model and success criteria
- Rules of engagement and legal authorization
- Deconfliction and safety planning
- Choosing threat actors to emulate
What you need before you start
- Completion of Enterprise Penetration Testing or equivalent engagement experience
- Confidence with Active Directory attacks and post-exploitation
- Comfort administering Linux servers and basic networking
- Familiarity with the MITRE ATT&CK framework
Who this course is for
- Penetration testers moving into red team roles
- Security professionals building an internal red team
- Blue teamers who want to understand adversary operations
- Candidates preparing for the CompTIA PenTest+ exam
Where this leads
Prepares you for
PenTest+
Awarded by CompTIA
PenTest+ is issued by CompTIA when you pass its exam, not by the academy. This course goes beyond the exam into full engagement planning and C2, while reinforcing the planning, testing and reporting phases PenTest+ measures across the lifecycle.
Questions about this course
More in offensive security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



