Group Purchasing
Group Purchasing

SEC699: Advanced Purple Teaming - Adversary Emulation & Detection Engineering

SEC699Offensive Operations
  • 5 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Erik Van BuggenhoutJean-François Maes
Erik Van Buggenhout & Jean-François Maes
SEC699: Advanced Purple Teaming - Adversary Emulation & Detection Engineering
Course authored by:
Erik Van BuggenhoutJean-François Maes
Erik Van Buggenhout & Jean-François Maes
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 29 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Advanced purple team training empowers security professionals to simulate sophisticated threat actor techniques through comprehensive adversary emulation across complex enterprise environments.

Course Overview

SEC699 delivers cutting-edge purple team training that immerses IT security professionals in advanced adversary emulation techniques. Participants will explore real-world threat actor strategies across dynamic enterprise settings, focusing on detection and emulation methodologies. With 60% hands-on lab time, students will develop skills in automation, tooling, planning, and executing complex adversary scenarios using tools like Covenant and Caldera. The course progressively builds expertise from foundational concepts to intricate purple team techniques, culminating in comprehensive threat actor emulation plans.

Intensive Purple Team Tactics: Adversary Emulation for Breach Prevention & Detection

This cutting-edge purple team training immerses participants in the world of adversary emulation to fortify defenses against data breaches. Delving into the realm of real-life threat actors, students undergo hands-on experiences within a dynamic enterprise setting, mastering the art of detection and emulation of adversarial techniques.Sixty percent of class time is spent on labs, and class activities include:

  • A course section on typical automation strategies such as Ansible, Docker, and Terraform, which can be used to deploy a multi-domain enterprise environment for adversary emulation at the press of a button
  • Building a proper process as well as tooling and planning for purple teaming
  • Building adversary emulation plans that mimic real-life threat actors such as APT-28, APT-34, and Turla, using tools such as Covenant and Caldera to execute the plans
  • In-depth techniques such as Kerberos Delegation attacks, Attack Surface Reduction/Applocker bypasses, EDR bypasses, AMSI, process injection, and COM Object Hi-jacking
  • Detection engineering and delemetry review to detect the above techniques.
  • A dynamic capstone where your adversary emulation skills are put to the test.

SEC699 is a natural follow-up to SEC599. Course authors Erik Van Buggenhout (lead author of SEC599) and Jean-Francois Maes (lead author of SEC565) are both certified GIAC Security Experts as well as experienced practitioners with a deep understanding of how cyber attacks work through both red and blue team activities. In SEC699, they combine these skill sets to teach students adversary emulation methods for data breach prevention and detection.

The SEC699 Journey Is Structured As Follows:

In section one, we will lay the foundations that are required to perform successful adversary emulation and purple teaming. As this is an advanced course, we will go in-depth on several tools that we'll be using and learn how to further extend existing tools.

Sections two through four will be heavily hands-on with a focus on advanced techniques and their defenses (particularly detection strategies). Section two focuses on Initial Access techniques, section three covers Lateral Movement and Privilege Escalation, while section four deals with Persistence.

Finally, in section five, we will build an emulation plan for a variety of threat actors. These emulation plans will be executed both manually using popular C2 frameworks and automatically using BAS (Breach Attack Simulation) tools.

Author Statement

"After the success of SEC599, I'm very excited to unleash this course offering upon the SANS audience! SEC699 is an amazing course that came about because we listened to student requests for a hands-on adversary emulation class leveraging an enterprise lab environment. This is it!

"SEC699 attendees will learn advanced red and blue team techniques for proper purple teaming in an enterprise environment. Throughout the week we do not just focus on explaining 'tips and tricks,' but also empower students to build and adapt their own tooling for proper adversary emulation. This includes running MITRE ATT&CK techniques both manually using popular C2 frameworks, but also in an automated fashion using BAS (Breach Attack Simulation) tools.

Upon executing TTPs, we will dive into what telemetry was generated and investigate how we can build security analytics to detect said TTPs.This will allow students to build detection engineering pipelines they can replicate when they get back in the office."

"The SEC699 lab environment is fully built using Teraform and covers multiple domains and forests that can be attacked! Students spin up the lab environment in their own AWS account and can thus keep on practicing months (and years) after they took the class!"

- Erik Van Buggenhout

What You’ll Learn

  • Build advanced adversary emulation infrastructure
  • Develop sophisticated purple team strategies
  • Execute complex initial access techniques
  • Perform lateral movement and escalation tactics
  • Create comprehensive threat actor emulation plans

Business Takeaways

  • Build realistic adversary emulation plans to better protect your organization
  • Deliver advanced attacks, including application whitelisting bypasses, cross-forest attacks (abusing delegation), and stealth persistence strategies
  • Building SIGMA rules to detect advanced adversary techniques

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC699: Advanced Purple Teaming - Adversary Emulation & Detection Engineering.

Section 1Introduction & Key Tools

Foundations for advanced purple team techniques, focusing on lab infrastructure deployment, purple team processes, detection engineering, and adversary emulation. Students will explore automation, tooling, and detection strategies through comprehensive hands-on exercises.

Topics covered

  • Course objectives
  • Lab environment architecture
  • Detection stack fundamentals
  • Telemetry analysis
  • Automated emulation strategies

Labs

  • VECTR Introduction
  • Elastic and SIGMA Stack Preparation
  • Adversary Emulation Stack Setup
  • Prelude Operator Configuration

Overview

In section one we will lay the foundations for the rest of the week by:

  • Leveraging the power of automation to deploy our lab infrastructure.
  • Learning how to build a purple team in-house, covering process, approach, and tooling.
  • Tracking purple teaming exercises using VECTR
  • Showing what an overall detection stack looks like, including a low-level view on how Windows systems generate telemetry (ETW, Kernel Callbacks...)
  • Detection engineering principles (rule-based detection vs anomalies, technique-centric detections vs tool-centric detections...)
  • How an adversary emulation stack can be built using freely available tools
  • Even if it's just the first section, it's heavy hands-on, as students will complete five different exercises.

Full Topic Details

  • Introduction
    • Course objectives
    • Building our lab environment
    • Introducing the lab architecture
    • Purple Teaming Organization
  • Key Tools
    • Overall detection stack
    • Log Sources & Raw Telemetry
    • Assessing detection coverage
    • Rule-based versus anomaly-based detection
    • Building a stack for adversary emulation
    • Automated emulation using Prelude Operator

Section 2Initial Intrusion Strategies Emulation & Detection

Comprehensive exploration of current attack strategies and endpoint defense mechanisms. Students will investigate Microsoft's built-in security features, understand bypass techniques for AMSI, AppLocker, and Attack Surface Reduction, and examine advanced Endpoint Detection & Response (EDR) evasion strategies.

Topics covered

  • Adversarial technique emulation
  • Anti-Malware Scanning Interface
  • Application execution control
  • Endpoint security evasion
  • Process manipulation strategies

Labs

  • VBA Stomping and AMSI Bypasses
  • AppLocker Configuration and Bypass
  • Attack Surface Reduction Circumvention
  • Process Spoofing Techniques
  • Advanced Process Manipulation

Overview

Section two starts with a state-of-the-art overview of current attack strategies and defenses for initial execution. We will zoom in on built-in defenses provided by Microsoft such as the Anti Malware Scanning Interface (AMSI). How does it work, how effective is it, and can it be bypassed? The course section will then move into the following modules:

Controlling execution on your endpoints using AppLocker. Introduced in Windows 7, Applocker is an application control technique that can be used to prevent execution of malicious payloads. We'll zoom in on its effectiveness and test several bypasses.

Controlling execution on your endpoints using Attack Surface Reduction (ASR) rules. Introduced in Windows 10, ASR rules are an additional security layer that can be used to prevent execution of malicious payloads. We'll zoom in on their effectiveness and test several bypasses.

We will look at a number of Endpoint Detection & Response (EDR) bypass strategies, including child-parent process ID spoofing, command line argument spoofing, process injection and hollowing, and direct syscalls. The rise of EDR tools has provided organizations with a means to enable in-depth detection and perform immediate response activities on their endpoints. These tools have changed the security landscape and have forced adversaries to get creative. Careful, it gets quite technical here...

Full Lab Details

  • VBA Stomping, Purging & AMSI Bypasses
  • Enabling and bypassing AppLocker
  • Bypassing Attack Surface Reduction
  • Child-parent spoofing
  • Process hollowing
  • Direct System calls

Full Topic Details

  • Initial Intrusion Strategies
    • Traditional Attack Strategies & Defenses
  • Emulating Adversarial Techniques & Detections
    • Anti-Malware Scanning Interface (AMSI)
    • Office Macro Obfuscation Techniques
    • Application Execution Control
    • ExploitGuard & Attack Surface Reduction Rules
  • Avoiding Endpoint Security Products
    • Hiding in Plain Sight - Creating New Processes
    • Do My Bidding - Abusing Existing Processes
    • Endpoint Security / Telemetry Tampering

Section 3Privilege Escalation & Lateral Movement Emulation & Detection

Deep dive into Active Directory reconnaissance, credential theft, and advanced lateral movement techniques. Students will explore comprehensive methods for enumerating AD resources, stealing credentials, and executing sophisticated attack strategies across network environments.

Topics covered

  • Active Directory enumeration
  • Credential dumping techniques
  • Kerberos attack strategies
  • Delegation vulnerability exploration
  • Advanced authentication bypass methods

Labs

  • BloodHound Attack Chain Analysis
  • Credential Stealing Techniques
  • NTLMv1 Downgrade Exploration
  • Delegation Attack Scenarios
  • Active Directory Certificate Services Abuse

Overview

The following modules will be covered in section three:

Enumerating Active Directory (AD) resources and configurations to map the overall attack surface of an AD environment.

Understanding the Local Security Authority Subsystem Service (LSASS) process. What is its purpose and how is it traditionally attacked? We will go in-depth and explain topics such as Security Support Providers and Authentication Packages. We'll then zoom in on the execution and detection of LSASS dumping attacks using a variety of tools (including Mimikatz, Dumpert, and ProcDump).

Given the focus of security products on LSASS, we will also investigate other credential dumping techniques. How can adversaries steal credentials without touching LSASS? Key techniques will include Internal Monologue (NTLMv1 downgrade), NTDS.dit stealing, and DCSync.

Provided with network-level access (or an initial payload on a network-connected device), how can we obtain additional credentials by forcing other Windows systems to connect to us? Topics include the use of Link-Local Multicast Name Resolution (LLMNR), but also IPv6-based man-in-the-middle attacks

A refresh on Kerberos and traditional attacks such as Kerberoasting, ASReproasting, golden tickets, silver tickets, and the Skeleton Key attack. We'll then focus on advanced attack strategies, primarily delegation attacks, before covering delegation attacks and Active Directory Certificate Service abuse.

Full Lab Details

  • Analyzing BloodHound attack chains
  • Stealing credentials from LSASS
  • Internal Monologue in NTLMv1 downgrades
  • Creative NTLMv2 Challenge-Response stealing
  • Abusing unconstrained delegation
  • Abusing constrained delegation
  • Abusing Active Directory Certificate Services

Full Topic Details

  • Active Directory Enumeration
    • Bloodhound Enumeration
  • Credential Dumping
    • LSASS Credential Stealing Techniques
    • Stealing credentials without touching LSASS
    • Stealing NTLMv2 Challenge-Response
  • Kerberos Attacks
    • Kerberos refresh
    • Unconstrained Delegation Attacks
    • (Resource-based) Constrained Delegation Attacks
  • Active Directory Certificate Services

Section 4Persistence Emulation & Detection

Examination of persistence strategies within Active Directory environments, focusing on advanced techniques for maintaining unauthorized access. Students will investigate complex methods like COM object hijacking, WMI persistence, and stealthy AD infiltration techniques.

Topics covered

  • Cross-domain infiltration
  • Persistence technique development
  • Advanced system manipulation
  • Stealthy access maintenance strategies

Labs

  • Domain and Forest Pivoting
  • COM Object Hijacking
  • WMI Persistence Mechanisms
  • Netsh Helper DLL Implementation
  • Office Persistence Techniques

Overview

This section will examine the security boundaries in an Active Directory (AD) environment and how adversaries can possibly pivot between different domains and forests. We'll look at typical persistence strategies used by adversaries as well as typical detection strategies. The course section will also present the following modules:

  • Abusing the Component Object Model (COM) to establish a persistent foothold in a target environment. We'll cover attacks including Phantom COM Objects and COM Search Order Hijacking.
  • Obtaining persistence through the use of Windows Management Instrumentation (WMI). We will explain WMI Event Filters, Event Consumers, and Event Filter to Consumer bindings
  • Establishing persistence through Dynamic Link Libraries (DLLs) such as AppCert, AppInit, and Netshell.
  • Leveraging Microsoft Office for persistence, with a focus on template shenanigans and malicious add-ins.
  • Abusing the Application Compatibility Toolkit to obtain persistence through application shims.
  • Stealth persistence using the AD

Full Lab Details

  • Pivoting between domains and forests
  • COM Object Hijacking
  • WMI Persistence
  • Implementing Netsh helper DLLs
  • Office Persistence
  • Application Shimming
  • Stealth AD persistence

Full Topic Details

  • Pivoting between domains and forests
    • Breaking Domain & Forest Trusts
  • Persistence Techniques
    • COM Object Hijacking
    • WMI Persistence
    • AppCert, AppInit & Netsh Helper DLLs
    • Office Template & Library tricks
    • Application shimming
    • Stealth AD Persistence
  • Conclusion

Section 5Emulation Plans (Extended Access to CTF Range)

Comprehensive threat actor emulation, developing and executing plans for sophisticated threat groups. Students will create detailed scenarios for APT-33, EvilCorp, APT-28, APT-34, and Turla, using advanced tools like Caldera, Covenant, and Prelude Operator.

Topics covered

  • Threat actor-specific emulation
  • Advanced execution frameworks
  • Post-course Capture The Flag challenge

Labs

  • Emulation Plan Development for Five Threat Actors
  • Tool-Specific Execution Strategies

Overview

In this course section we will build out emulation plans for five specific threat actors: APT-33, EvilCorp, APT-28, APT-34, and Turla. After completing the emulation plans, we will execute them using Caldera, Covenant, and Prelude Operator. After completion of the course, participants will gain access to an epic CTF to infiltrate or defend the corporate environment. Students will leverage all of the tools and techniques they've learned throughout the course for up to 7 days after class ends!

Full Topic Details

  • Executing Emulation Plans
    • APT-33 Emulation Plan
    • EvilCorp Emulation Plan
    • APT-28 Emulation Plan
    • APT-34 Emulation Plan
    • Turla Emulation Plan

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 8GB of RAM or more is required.
  • 200GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Additional requirements for this course:

  • An Amazon Web Services (AWS) account is required to perform hand-on labs during the course. SANS provides an AWS account for use throughout the duration of the course.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

If you have additional questions about the laptop specifications, please contact customer service.

SEC699 training is recommended for a diverse range of individuals, including:

  • Penetration testers
  • Ethical hackers
  • Defenders who want to better understand offensive methodologies, tools, and techniques
  • Red team members
  • Blue team members
  • Purple Team members
  • Forensics specialists who want to better understand offensive tactics

  • A SEC699 course VM that includes necessary scripts and dependencies that are used to spin up a detection lab on-demand

This is a fast-paced, advanced course that requires a strong desire to learn advanced red and blue team techniques. The following SANS courses are recommended either prior to or as a companion to taking this course:

Experience with programming in any language is highly recommended. At a minimum, students are advised to read up on basic programming concepts.

You should also be well versed with the fundamentals of penetration testing prior to taking this course. Familiarity with Linux and Windows is mandatory. A solid understanding of TCP/IP and networking concepts is required. Please contact the author at evanbuggenhout@nviso.be if you have any questions or concerns about the prerequisites.

SEC699 training is part of the Offensive Operations curriculum. It is considered Purple Team training, along with SEC598: AI and Security Automation for Red, Blue, and Purple Teams and SEC599: Defeating Advanced Adversaries – Purple Team Tactics & Kill Chain Defenses.

Purple team training is a collaborative cybersecurity approach that breaks down silos between red teams (attackers) and blue teams (defenders) to simulate real-world threats and improve detection and response capabilities. Rather than operating independently, both teams work together in live-fire exercises to test defenses and immediately fine-tune them based on observed adversary behavior. This training is essential because it accelerates the feedback loop, enhances defensive readiness, and builds stronger, more threat-informed detection strategies. SANS courses like SEC599 and SEC699 integrate purple team methodology to help professionals operationalize threat intelligence, validate controls, and build more resilient security operations.

SEC699: Purple Team Tactics – Adversary Emulation for Defenders is a career accelerator for cybersecurity professionals aiming to bridge offensive and defensive operations. This expert-level course builds deep technical expertise in emulating advanced adversary tactics and validating the effectiveness of enterprise defenses in real time. Whether you're a senior blue teamer, detection engineer, threat hunter, or transitioning from red team roles, SEC699 equips you with the skills and credibility to lead purple team initiatives, conduct threat-informed defense assessments, and drive measurable security outcomes. Graduates of SEC699 are often tapped for high-impact roles, including purple team leadership, adversary emulation programs, and cross-functional cybersecurity strategy.

Relevant Job Roles

Offensive Cyber Operations (OCEP)

Skills Framework for the Information Age

Execution of controlled cyber operations that emulate threat actor behaviour to evaluate organisational defences. Operations are used to identify weaknesses and enhance preparedness.

Explore learning path

Purple Teamer

Offensive Operations

In this fairly recent job position, you have a keen understanding of both how cybersecurity defenses (“Blue Team”) work and how adversaries operate (“Red Team”). During your day-today activities, you will organize and automate emulation of adversary techniques, highlight possible new log sources and use cases that help increase the detection coverage of the SOC, and propose security controls to improve resilience against the techniques. You will also work to help coordinate effective communication between traditional defensive and offensive roles.

Explore learning path

Red Teamer Training, Salary, and Career Path

Offensive Operations

Monitor and analyze activity across cloud environments, proactively detect and assess threats, and implement preventive controls and targeted defenses to protect critical business systems and data.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Amsterdam September 2026

    Amsterdam, NL & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €8,230 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Tokyo Winter 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    ¥1,335,000 JPY*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS 2027

    Orlando, FL, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
Showing 4 of 4

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources