EFFORT
4 WEEKS
40h trainer-led
FORMAT
Self-paced
or instructor-led
CERTIFIES
City & Guilds
Assured
PREREQUISITES
Intermediate
.
For teams & organizations — volume pricing, instructor-led delivery, custom scenarios.
1,600
ZX305 – Network Security
Valid for 6 months
// ZX OFFENSE · LEVEL 4 · ZX305
Network Security
Secure complex network infrastructures
Master techniques to identify weaknesses and protect organizational networks through advanced networking, Active Directory, PowerShell, and cryptography.
Overview
This course teaches offensive network security techniques, focusing on identifying and exploiting vulnerabilities in Windows domain environments. Students learn to perform network reconnaissance, exploit Active Directory weaknesses, leverage PowerShell for enumeration, and execute post-exploitation activities. The curriculum emphasizes hands-on attack frameworks and tools used in penetration testing, including credential harvesting, pass-the-hash attacks, and domain persistence techniques. This is an advanced-level course designed for security professionals seeking practical offensive security skills against enterprise networks.
Learning Objectives
By the end of this course, students will be able to:
-
Configure and analyze network subnets to identify hosts and potential attack surfaces
-
Execute network-based attacks including credential capture, man-in-the-middle, and protocol exploitation
-
Deploy and configure Active Directory domain environments for security testing
-
Analyze domain event logs to identify security incidents and attacker activities
-
Utilize PowerShell for system enumeration, log analysis, and administrative task automation
-
Enumerate Active Directory objects, users, groups, and permissions using multiple tools and protocols
-
Exploit domain vulnerabilities using frameworks like Metasploit, Impacket, and CrackMapExec
-
Perform post-exploitation activities including credential dumping, lateral movement, and persistence
Course Modules
-
Subnetting
This module covers IP addressing fundamentals and subnet calculation techniques essential for network reconnaissance. Students learn to divide networks into subnets, calculate host ranges, and use tools like Packet Tracer to visualize network topologies. These skills form the foundation for identifying target systems and planning network-based attacks.
-
Network Attacks
This module explores offensive techniques targeting network protocols and services. Students learn to exploit weaknesses in DHCP, SMB/SMB2, LLMNR, and NBNS protocols to capture credentials and gain unauthorized access. The module covers tools like Responder for protocol poisoning, pass-the-hash attacks, and methods for collecting network traffic and cracking captured password hashes.
-
Domain Setup
This module provides hands-on experience installing and configuring Windows Active Directory domains. Students deploy domain controllers, configure domain services, and establish the infrastructure needed for subsequent exploitation exercises. Understanding proper domain setup is essential for recognizing misconfigurations and security weaknesses in production environments.
-
Domain Events
This module focuses on Windows domain event logging and monitoring. Students learn to interpret security events, authentication logs, and audit trails that record domain activities. The module teaches how attackers use event log analysis to understand domain behavior and how defenders use these same logs to detect intrusions and track attacker movements.
-
PowerShell
This module teaches PowerShell scripting for Windows system administration and security assessment. Students learn essential commands, text manipulation techniques, and methods for querying event logs programmatically. The module emphasizes PowerShell's role in enumeration, showing how to extract system information, user data, and security configurations without triggering traditional detection mechanisms.
-
Domain Enumeration
This module covers techniques for mapping Active Directory environments and identifying potential targets. Students use tools like Rpcclient to query domain information remotely, extract user lists, enumerate group memberships, and discover domain trusts. The module emphasizes stealthy reconnaissance methods that gather intelligence while minimizing detection risk.
-
Domain Exploitation
This module teaches students to weaponize enumeration findings by exploiting Active Directory vulnerabilities. Students use Metasploit, Impacket, and CrackMapExec to execute attacks against domain controllers and member systems. The module covers authentication attacks, privilege escalation techniques, and methods for gaining administrative access to domain resources.
-
Domain Post
This module focuses on post-exploitation activities after gaining initial domain access. Students learn to use Mimikatz for credential dumping, PSexec for remote command execution, and techniques for maintaining persistent access. The module covers advanced attacks like Golden Ticket creation, which allows attackers to forge Kerberos authentication tickets and maintain long-term domain compromise.
-
Domain Security
This module examines defensive measures and security controls for protecting Active Directory environments. Students learn to identify security weaknesses from an attacker's perspective and understand how proper security configurations prevent the attacks taught in previous modules. The module bridges offensive techniques with defensive strategies, helping students think like both attackers and defenders.
-
Cryptography
This module introduces encryption principles and their application in network security. Students explore both classic and modern encryption techniques, understanding how cryptography protects data in transit and at rest. The module provides foundational knowledge of cryptographic protocols used in network communications and how weaknesses in implementation can be exploited during security assessments.
// Where you'll do all of this
You won't watch this.
You'll run it live.
Every module above is executed inside Cyberium Arena — real tools on real nodes, deployed on the live internet, with live threat intelligence running from your first login. Not a sandbox. Not a VM. Not a video.
Live Internet
Real Tools
Sand Box
VM




Delivery and Assessment
The course is delivered through hands-on laboratories where students practice attack techniques in controlled environments. Students work with industry-standard offensive security tools and frameworks, performing scanning, enumeration, exploitation, and post-exploitation exercises against Windows domain infrastructures. Practical scenarios reinforce theoretical concepts and build real-world penetration testing skills.
Certification
Certificate of completion.
1,600
ZX305 – Network Security
Valid for 6 months
Ready when you are
Trusted since 2016 — national police, military cyber units & Fortune 500 teams · City & Guilds Assured
