Offensive security training
Nobody learns to defend a system by watching slides about attacks. Our training is built around labs that participants break with their own hands — and only after that does defense make sense.
Tracks
Content is assembled from your context: the stack the team uses, the incidents they have lived through, and the real level of the group, measured before the first session.
- Secure development — the failure classes that show up in the team code, exploited and then fixed by the participants themselves.
- Web application and API security — from the OWASP Top 10 to the logic flaws no list covers.
- Offensive security fundamentals — reconnaissance, enumeration, exploitation and post-exploitation, for those starting out.
- Active Directory for infrastructure teams — how escalation paths form and how to close them.
- Attacker mindset for technical leadership — how to prioritize risk when everything looks urgent.
Format
In-person classes in Porto Alegre or live remote sessions. We do not work with recorded video, because the part that teaches is the question that comes up mid-lab.
Each module alternates short exposition with long practice. Participants get access to their own lab environment, which stays available for a period afterwards for anyone who wants to redo the exercises.
Duration is defined with you. Common formats range from a half-day workshop on a specific topic to a multi-week track with weekly sessions.
What you receive
- Supporting material and the labs used in class, for later reference.
- Access to the lab environment for a period after the course ends.
- Progress report for the group, highlighting the points that deserve reinforcement.
- Recording of the sessions, when the remote format is chosen.
Who it is for
- Development teams that receive pentest findings and want to stop reintroducing the same flaws.
- Infrastructure teams responsible for Windows and Active Directory environments.
- Security professionals moving into offensive roles.
- Organizations that need to demonstrate continuous training for audit or certification.
Frequently asked
- Is the training in person or remote?
- Both. In person in Porto Alegre and the surrounding region, or live remote anywhere. The hands-on content is identical, since the lab is accessed remotely in both formats.
- What is the ideal group size?
- Between eight and fifteen people. Below that the discussion dynamic suffers; above it, following each participant through the labs gets difficult.
- Is prior knowledge required?
- It depends on the track. Fundamentals start from zero and only ask for command line familiarity. Specific tracks such as Active Directory assume prior administration experience. We align the level before finalizing the programme.
Find out before they do.
Scoped in a week. NDA first. We reply within 24 business hours.
Request an engagement