How security testing works
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
Objective-based exercises that test detection and response, and the collaborative loop that actually improves them.
A red team exercise answers a question no other test does: can an objective be achieved without the defenders noticing and responding in time?
This course covers when that question is worth asking, how to plan an exercise around threat intelligence and ATT&CK, how to run a purple-team loop that fixes detections while everyone is still in the room, and how to measure the outcome in something other than findings.
4 lessons · 55 min
What a red team answers, what it costs, and the signs you should buy something else first.
Choosing scenarios that resemble your actual adversaries, and writing them down as testable techniques.
Execute, observe, fix, re-run — improving detection while the people who own it are still present.
Times, coverage and quality — the numbers that say whether defence improved.
Sign in and enrol to leave a review.
No reviews yet — be the first once you have worked through it.
2 min read
2 min read
2 min read
2 min read
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
A methodical way through an application: mapping, authentication flows, access control and business logic.
Discovery, service enumeration, configuration weaknesses and proving that segmentation exists outside the diagram.