OPSEC & Evasion
Course Description
OPSEC is what separates amateurs from professionals. Learn to operate without detection and maintain stealth throughout engagements.
Learning Objectives
- Plan operations with OPSEC in mind
- Evade EDR and antivirus solutions
- Blend with normal network traffic
- Avoid attribution and detection
- Clean artifacts and tracks
- Maintain operational security
Course Structure
Modules
Module 1: OPSEC Fundamentals (5h)
- OPSEC principles
- Threat modeling
- Risk assessment
- Operation planning
Module 2: Infrastructure OPSEC (6h)
- Anonymous hosting
- Domain selection
- Redirectors
- VPN/Proxy chains
- Payment OPSEC
Module 3: Endpoint Evasion (8h)
- AV evasion techniques
- EDR bypass methods
- AMSI bypass
- ETW evasion
- Process injection stealth
Module 4: Network Evasion (6h)
- Traffic blending
- Protocol mimicry
- Domain fronting
- DNS over HTTPS
- Encrypted channels
Module 5: Behavioral Evasion (5h)
- Living off the land
- Timing operations
- User behavior mimicry
- Alert threshold avoidance
Module 6: Anti-Forensics (6h)
- Log manipulation
- Timestomping
- Memory clearing
- Artifact removal
- Secure deletion
Module 7: Attribution Prevention (4h)
- False flags
- Tool signature removal
- Language/timezone hiding
- Operational patterns
Tools
| Tool | Purpose |
|---|---|
| Proxychains | Traffic routing |
| Tor | Anonymization |
| Timestomp | Time manipulation |
| BleachBit | Artifact cleanup |
📄️ Overview
Operational security and detection evasion for red team operators