Goals / What to expect

Goals / What to expect

The goal of this product is to show and describe in detail chunks of different offensive executions we can usually find during real attack campaigns. There are a few main ideas and goals behind the course:

  • Teach you what offensive techniques exist in Linux, with mapping to the Linux Matrix

  • Deliver you a ready-to-copy-and-paste block of code that you can use during your own penetration testing/emulation engagements, red teaming, detection coverage testing, or EDR evaluations, with the possibility of chaining and creating advanced Linux custom attack paths

  • Provide you with step-by-step, hands-on instructions about the full Linux Kill Chain vs Detection

  • Teach you how to handle true hands-on evaluation testing of modern Linux EDR

  • Explain by offense what you should expect from modern Linux EDR products, with a focus on the internals, capabilities, detection, and operational efficiency

  • Power up your Breach and Attack Simulation Platforms (BAS)

  • Show you how to evaluate your Linux security tool's effectiveness across the attack lifecycle

  • Develop a more effective and scalable strategy to secure your organization

By using EDRmetry Matrix, you'll examine and learn how to execute custom Linux EDR attack tests mapped to MITRE ATT&CK Framework as evaluation checks. Thanks to the generic approach, you will be able to run your tests against whatever EDR you have/want to have in your production/testing/Cyber Range environment.

This practical approach will equip you with the skills to enhance your organization's defense against Linux advanced persistent threats.

EDRmetry Linux Matrix For Download / Self-Hosted - Comprehensive Hands-On Attack TTPs Catalog

Buy nowLearn more

1. EDRmetry Overview

  • Introduction
  • What you will get?
  • Goals / What to expect
  • EDRmetry Matrix
  • Virtual Machines / C2
  • EDRmetry Generic Flow
  • Contextual Execution
  • Changelog / Updates

2. EDRmetry Deployment

  • Deploy your EDRmetry Matrix Docker Container
  • Download EDRmetry Matrix JSON Database
  • Import your EDRmetry Matrix JSON Database
  • Provision your TARGET_X VM
  • Provision your KALI_X or C2_X VM
  • Request for HTTPS Hosted Access to EDRmetry Matrix

3. Research and emulation of Linux threats

  • MITRE ATT&CK TACTICS in the Linux Ecosystem
  • Linux Threat Landscape
  • Initial Access - TA0001
  • Discovery - TA0007
  • Execution - TA0002
  • Defense Evasion - TA0005
  • Persistence - TA0003
  • Privilege Escalation - TA0004
  • Exfiltration - TA0010
  • Command and Control - TA0011
  • Lateral Movement - TA0008
  • Credentials Access - TA0006
  • Impact - TA0040
  • Collection - TA0009