Module 01
The APT lifecycle
Access, foothold, persistence, escalation, lateral movement and objective execution — and why each stage leaves traces.
Home / Training / Advanced Persistent Threat
APT certification
A certification covering how persistent adversaries operate, and how to detect and evict them.
Understanding the adversary that stays.
SOC analysts, incident responders, threat intelligence staff and infrastructure teams.
| Code | APT |
| Format | Instructor-led, scenario-driven |
| Assessment | Practical exercise and written report |
| Delivery | Private cohort or scheduled open cohort |
| Prerequisite | None, though security experience helps |
Module 01
Access, foothold, persistence, escalation, lateral movement and objective execution — and why each stage leaves traces.
Module 02
Adversaries abusing legitimate tools and credentials, and why signature-based detection misses it.
Module 03
Common C2 patterns, beaconing behaviour and infrastructure reuse.
Module 04
Turning adversary behaviour into detections, and testing whether they actually fire.
Module 05
Hypothesis-driven hunting, scoping an intrusion, and confirming an adversary is gone rather than quiet.
Authorisation is part of the curriculum. These techniques are legal only when applied with written permission against systems and people you are authorised to test. Every module that covers technique also covers the boundary — scope, consent, data handling and the point at which the work would become unlawful. We do not teach techniques for use outside an authorised engagement.
Tell us how many participants and whether you want an open or private cohort. We will send dates and the full syllabus.