Attack Techniques
Attack Technique
Interactive
AiTM Phishing →
How attackers proxy the login page in real time, stealing session cookies to bypass MFA without the victim ever knowing the login was intercepted.
T1566.002
T1539
T1550.004
Attack Technique
Interactive
Credential Theft →
LSASS dumps, SAM database access, Kerberoasting, Pass-the-Hash - how attackers extract and reuse credentials without ever cracking passwords in real time.
T1003.001
T1558.003
T1550.002
Attack Technique
Interactive
Kerberos & AD Attacks →
Play the six-message Kerberos exchange, then inject Kerberoasting, AS-REP Roasting, Golden and Silver tickets, Pass-the-Ticket, or DCSync and watch exactly where the chain gets poisoned.
T1558
T1550.003
T1003.006
Attack Technique
Interactive
Lateral Movement →
How attackers move from a compromised workstation to domain controllers, Exchange servers, and CI/CD pipelines - mapped to the foyl SecIntel network.
T1021.002
T1550.002
T1569.002
Attack Technique
Timeline
Ransomware Lifecycle →
From initial phishing email to full disk encryption - a step-by-step timeline showing how ransomware operators work, and where defenders can intervene at each phase.
T1486
T1490
T1041
Attack Technique
Interactive
DNS Tunnelling →
Attackers smuggle data and C2 traffic inside DNS queries. Type a secret, watch it chunk into subdomain lookups, and see the length, entropy, and volume signals that give it away.
T1071.004
T1048
Attack Technique
Interactive
Business Email Compromise →
How attackers impersonate executives and vendors to redirect wire transfers. Real email thread walkthrough with red-flag analysis and header inspection.
T1534
T1566.001
T1585.002
Attack Technique
3D Field Lab
Living off the Land →
Signed does not mean safe. Classify real command contexts, inspect process lineage, and see how attackers repurpose the tools already installed on a host.
T1218
T1059
Behavioral detection
Attack Technique
3D Simulator
Persistence →
Plant scheduled tasks, Run keys, services, and OAuth grants, then advance disruption events to discover exactly which return paths survive.
TA0003
T1053
T1547
Core Concepts
Core Concept
Interactive
Zero Trust →
Never trust, always verify. Flip the live signals on a single access request - identity, device, location, risk - and watch the policy engine allow, step up, or deny.
NIST 800-207
PEP / PDP
Core Concept
Interactive
MFA and Bypass Techniques →
How authenticator apps, push MFA, SMS, and passkeys each work - and where each method is vulnerable to AiTM proxying, SIM swapping, and push fatigue.
T1621
T1111
Core Concept
Visual
C2 Beacons →
How command-and-control beacons work, why they blend into normal traffic, and how security teams detect the patterns of a host checking in with an attacker's server.
T1071
T1573
T1132
Core Concept
Interactive
The Cyber Kill Chain →
The seven phases of every attack from reconnaissance to actions on objectives - mapped to the IRON CHIMNEY incident with detection opportunities at each phase.
Framework
Lockheed Martin
Core Concept
Interactive
Reading Security Logs →
Windows Event IDs, Sysmon, NGFW flows, and Entra ID sign-in logs - what they contain, what defenders look for, and how each event maps to a MITRE ATT&CK technique.
Windows EL
Sysmon
Entra ID