Cover Image for Operating C2 for Red Team Operations: Pivoting & Beacon Object Files
Cover Image for Operating C2 for Red Team Operations: Pivoting & Beacon Object Files
Avatar for TryHackMe
Presented by
TryHackMe
4 Going

Operating C2 for Red Team Operations: Pivoting & Beacon Object Files

Zoom
Get Tickets
Welcome! Please choose your desired ticket type:
About Event

​Who this workshop is for

  • ​Security practitioners who want hands-on time driving a C2, not another tool demo

  • ​Pentesters and red teamers who want a structured grounding in C2 tradecraft and the OPSEC thinking behind it

  • ​Blue teamers, detection engineers, and defenders who want to see how operators move, so they can catch them

​No prior C2 experience needed. We start from standing up the server and build up to live pivoting, so beginners and experienced operators both have room to work.

​What's included

  • ​Live, hands-on sessions in a dedicated lab range, where you operate a real C2

  • ​Live hands-on throughout: land your first agent, then pivot deeper across the range

  • ​Certificate of participation with CEP Credits

  • ​Recording included: a full session recording for everyone who registers

  • ​A dedicated detection walkthrough: how the blue team catches what you ran

  • ​Closing Q&A with the instructors on screen

  • ​A place in a focused, small cohort working the same range together


​Red teams are expected to emulate real adversaries. But operating a C2 framework end-to-end, standing up the server, landing your first agent, keeping your footprint small, and pivoting deeper, is a skill set most practitioners never get structured time to build.

​Spraying tools across a network isn't tradecraft. Modern defenders see noisy operators coming.

​Sleep and jitter. In-process execution. Beacon Object Files. SOCKS pivoting. These aren't advanced extras. They're the everyday mechanics of operating with OPSEC in mind. And for most people, the only place to pick them up is mid-engagement, where there's no room to experiment.

​Not because people don't care. Because a realistic, safe range time is hard to come by.

​This workshop closes that gap.

​In one focused session, you'll stand up an open-source C2, drive it through the full kill chain (foothold, post-ex, BOFs, pivot), and learn to think about OPSEC at every step, the way an operator does on a live engagement.

​What makes this workshop different

  • ​It's built around live operation in a lab range, not a slide deck and a Q&A

  • ​You run the full chain yourself (first agent, post-ex comms, BOF execution, lateral movement), the way a real op unfolds

  • ​A dedicated detection segment shows how the blue team catches what you ran, so you leave understanding both sides of the engagement

​What you'll learn

​A focused, hands-on grounding in how red teams operate command and control, and the OPSEC thinking that separates good ops from noisy ones.

​The foundations of C2

  • ​What C2 is, why red teams rely on it, and the core architecture: team server, listeners, redirectors

  • ​How to stand up an open-source C2 and generate, then deploy, an agent into the range

  • ​How to land your first agent and run clean post-exploitation comms

​How to operate with OPSEC in mind

  • ​How sleep, jitter, and timing shape an agent's traffic and reduce noise

  • ​Why in-process execution beats spawning new processes for OPSEC

  • ​What Beacon Object Files are, how to load and run pre-built BOFs, and where they sit in a post-ex workflow

​How to move through the network

  • ​How to use a single foothold to reach internal hosts

  • ​SOCKS proxying and port forwarding to work across network segments

  • ​How to move laterally through the range the way an operator does, and how each move looks to a defender

​​Learn directly from:

​Ariz Soriano, Senior Content Engineer at TryHackMe and Associate Director of Red Team Operations at THEOS Cyber. Ariz built the Theos red team from the ground up and now runs a practice delivering multiple concurrent APT simulation and purple teaming engagements a year. At TryHackMe he creates hands-on cybersecurity labs based on real-world attack techniques.

​Andrea Brosio, Senior Content Engineer at TryHackMe. Offensive security engineer with 6+ years of experience in red teaming: malware development, EDR evasion techniques, and building offensive tooling. Currently building AI driven pipelines for automated vulnerability discovery and exploitation. Speaker at DEF CON and multiple BSides events.

​DiscoverPricingHelp

Avatar for TryHackMe
Presented by
TryHackMe
4 Going