

Building and Breaking Active Directory Advanced
Who this talk is for:
Red teamers and operators ready to put a framework's functionality under the microscope
Pentesters who've sat through Part 1 and want the practical, hands-on evaluation criteria
Security practitioners choosing between C2 frameworks and want a repeatable way to compare them
What's included:
Live talk, grounded in real engagements, not a feature comparison slide deck
A practical checklist for evaluating any C2 framework
Certificate of participation with CPE credits
Architecture tells you if a framework can survive an op.
Functionality tells you if it's actually usable.
In Part 2, we go from the "why" to the "how", walking through the practical checklist for evaluating a C2 framework's functionality: payload creation, listener setup, and module customization.
Along the way, you'll see where these functional choices have made or broken real engagements.
What makes this talk different:
It's built around a checklist you can actually apply, not abstract best practices
You'll see the functional decisions, payloads, listeners, modules, tested against real engagements
You leave ready to evaluate any C2 framework on your own
What you'll learn:
A practical, reusable checklist covering payload creation, listener setup, and module customization
How to stress-test a framework's functionality before committing to it
Real cases where functional choices decided whether an engagement succeeded
Learn directly from:
Stefan Apostol, Content Engineer at TryHackMe
Tinus Green, Content Engineer at TryHackMe
Recording notice: This event will be recorded. We may share the recording with registered attendees and may also use selected portions publicly, including on our website or social channels. By registering for and attending this event, you agree to this recording and use.