Red Team Operator / Corporate Pentest Capstone
Advanced certification for red team operators. Covers corporate pentest chain, pivot, post-exploitation, and reporting.
Corporate Pentest Chain and Pivoting
Vigenère Cipher Cryptanalysis: Kasiski Examination and Index of Coincidence Attack
Cracking Columnar Transposition Ciphers: Key-Length Detection and Column Reordering
AES-ECB Block Alignment Attack: Exploiting Deterministic Encryption for Oracle Leakage
CBC Padding Oracle Attack: Byte-by-Byte Plaintext Recovery via PKCS#7 Error Responses
AES-CTR Nonce Reuse Attack: XOR-Based Keystream Recovery and Plaintext Decryption
Exploiting Symmetric Key Reuse Across Users: Cross-Account Ciphertext Oracle Attacks
Extracting Hardcoded Symmetric Keys from Binaries via Static Reverse Engineering
Attacking Weak Key Derivation Functions: Dictionary Attacks on Under-Iterated Password Hashing
XOR Keystream Reuse Attack: Many-Time Pad Cryptanalysis and Statistical Key Recovery
Cracking RSA Small Public Exponents: Cube-Root Recovery and Low-Exponent Bias
RSA Broadcast Attack: CRT-Based Plaintext Recovery Across Multiple Recipients
Factoring Weak RSA Primes via Fermat Factorisation and Pollard p-1 Method
WAV spectrogram stego
WAV echo stego
LSB RGB stego
Bit plane image stego
Alpha channel LSB stego
XOR two-image stego
DCT block image stego
Recovering Wide Strings (UTF-16LE) from Memory: C2 URL and Credential Extraction via Volatility
Detecting XOR-Encoded Payloads in Memory Dumps: Entropy Analysis and Brute-Force Key Recovery
Underground Forum-to-Pastebin OSINT Pivot: Alias Correlation and Leaked Document Discovery
Email-to-S3 OSINT Pivot: SMTP Reconnaissance Chaining to Cloud Storage Data Exposure
WHOIS-to-Employee OSINT Chain: Domain Registration Pivoting to Internal Staff Identification
Social-to-Chat OSINT Pivot: Instagram-to-Messaging Platform Identity Correlation
Controlled Post-Exploitation and Impact Assessment
Advanced GOT Overwrite: 64-Bit Multi-Byte %hn/%hhn Writes with Null-Byte Bypass
Format String Arbitrary Write: Exploiting %n for GOT Overwrite and Code Redirection
Integer Truncation Exploitation: 64-to-32-Bit Narrowing, Size Check Bypass and Memory Corruption
Signed/Unsigned Confusion Exploitation: Negative Index Underflow and Memory Corruption via Sign Mismatch
Advanced seccomp Bypass: 32-Bit int 0x80 Syscall Table Exploitation Outside 64-Bit Filter Coverage
Docker Volume Misconfiguration: Sensitive Host Path Exposure and Container-to-Host Escalation
Privileged Container Escape: Linux Capability Abuse and Host Device Access for Breakout
Kubernetes Dashboard Unauthenticated Access: Pod Creation, Secret Enumeration and Admin Escalation
Kubernetes RBAC Privilege Escalation: ClusterRoleBinding Abuse and Service Account Token Misuse
Kubernetes Secret Enumeration in Cluster: Namespace Traversal and Sensitive Data Extraction
Kubernetes Service Account Abuse: Token-Based API Access and Lateral Movement Within Cluster
IAM policy misconfig
Analyzing Kerberoasting PCAP Captures via TGS-REQ Identification and Hashcat Ticket Extraction
Decrypting TLS Traffic via SSLKEYLOGFILE Integration and Encrypted Session Reconstruction
Analyzing gRPC PCAP Captures via HTTP/2 Stream Identification and Protobuf Parameter Extraction
Report, Detection Replay and Debrief [Non-CTF]
No cards in this course yet.
CTFFactory Red Team Operator — Advanced
Advanced credential — awarded upon completion