Welcome to the v2.1 party!
Welcome to the v2.1 party!
Linux Attack, Detection and Forensics v2.1 - Hands-on Purple Teaming Playbook
Introduction
Introduction
Defensive/DFIR Tooling
Defensive/DFIR Tooling
Linux EDR Architecture
Linux EDR Architecture
Linux MITRE ATT&CK Matrix
Linux MITRE ATT&CK Matrix
Initial Access - TA0001
Initial Access - TA0001
Persistence - TA0003
Persistence - TA0003
Privilege Escalation - TA0004
Privilege Escalation - TA0004
Defense Evasion - TA0005
Defense Evasion - TA0005
Command and Control - TA0011
Command and Control - TA0011
Discovery - TA0007
Discovery - TA0007
Lateral Movement - TA0008
Lateral Movement - TA0008
Exfiltration - TA0010
Exfiltration - TA0010
Automated Attack Emulation Projects
Automated Attack Emulation Projects
Kubernetes
Kubernetes
Welcome to the Linux Attack, Detection, and Live Forensics v2.1! After almost 4 years of active development and constant research, I have done for v1.0, I decided to refresh the overall approach a bit. Due to the considerable dynamics of our Linux cybersecurity space and, above all, the active development of the EDRmetry Matrix project, I decided that the new version of the course will be developed in a more modular way, with better navigation and structure. The natural course of action was, of course, to categorize the content into the MITRE ATTACK Framework, exactly what has already been done with the EDRmetry Matrix. Everything came together to the idea of ​​integrating EDRmetry Matrix as a v2.0 core, serving as a central knowledge base for offensive techniques. With this perspective, I began working on individual detection points and forensic artifacts. Thanks to PurpleLabs, I was able to achieve a complete and easily expandable Linux-oriented Purple Teaming Training platform in the playbook format.
Custom Prevention/Response Add-On => v2.1
Detection and Forensics tell you if the attacker is inside. Prevention/Response is what you do ahead of the attack. Mass exploitation is automated and increasingly unpredictable. In principle, assume that right now, at this very moment, across multiple points in your infrastructure, you may already be under a zero-day attack. Malware creation has gotten cheap and disposable, and adversaries create custom offsec tooling and weaponize CVEs within hours of disclosure and scale campaigns easily. Patching windows of critical infrastructures that spanned weeks are now compressed to hours, and often too late. To effectively combat these threats, we must enhance our ability to not only detect malicious activity but also to be informed by the threat-hunting and CTI process to understand the true attacker behavior and, most importantly, develop custom mitigation policies on the fly. The enforcement capabilities that block entire technique classes at the lowest possible level, independent of signatures, hashes, and patch timelines, have never been more important.
The Prevention/Response Add-on for every offensive lab scenario extends the base course with the other side of the kill chain -> stopping/blocking attacks before they complete.
Full scope, not vendor-dependent. Not signature-dependent. Grounded in the same low-level Linux internals that the base course teaches. AI made every attack faster. The Prevention/Response Add-on section makes stopping them practical via custom kernel-level enforcement policies using Tetragon and eBPF LSM C within at least 4 different stages:
Baseline Profiling
Profile Enforcing
Anti-Lateral Movement & Anti-Pivoting
Live Patching
Dynamic format
The main style of materials does not change, though. Still, the content takes on an "Attack vs Detection + Forensics + Response" approach in a condensed format. However, I decided to limit the individual instructions to only commands/queries + screenshots in the form of individual generic flows that you can perform alternately. Materials no longer include verbal descriptions such as "log in to TARGET_X" or "execute the command on KALI_X", etc. However, they directly indicate where to perform a given action. This way, I want to encourage you to think even more actively about a given scenario instead of mindlessly copying and pasting commands. I was looking for a way that would allow me, firstly, to easily deliver new content, and secondly, to deliver labs in a dynamic format. What does this mean in practice? It means that everyone can experience these labs from a different perspective.
Hands-on to theory ratio is 90:10
In an era of ubiquitous use of AI engines, I also decided to minimize the theoretical material presented, focusing on practical experience only. This means the course officially triggers the need to consult external sources or query the AI ​​about the details of a given technique. From my perspective, there is no point in rewriting, editing, or creating something that has already been written a long time ago. Therefore, we can safely say that the hands-on to theory ratio is 90:10. That's also why I called this product a Purple Teaming Playbook. It is a treasure trove of offensive and detection/forensics knowledge that shows you many different ways of hands-on actions.
Higher entry level
Of course, nothing comes for free. Personally, I believe that the new approach requires a higher entry threshold in terms of entry skills. I think the new program is dedicated to seasoned professionals who have more than a basic understanding of Linux OS internals. The step-by-step formula significantly eliminates this difficulty, but you really need to know what you are doing. What will you gain? You can really expect a strong injection of fresh knowledge and new hands-on experiences. Saying that, the content is dedicated to experienced Red/Blue/DFIR/SOC/CERT team members who aim to dig deeper into understanding Linux internals and the corresponding threat ecosystem.
Let's move on!