From exploitation to mitigation: Mastering NTLM relay end-to-end.
Get two days of hands-on, scenario-driven training inside real NTLM relay attacks, learn to exploit, detect and build deployable defenses in live Active Directory environments.
2-day workshop – €490
(VAT excluded)
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
In collaboration with:
This workshop is delivered through custom-built, guided training by Cyber Helmets, enriched with Hack The Box Academy’s sophisticated labs and curated content.
What you’ll do
What you’ll gain
Format & what’s included
Who it’s for
Blue Teamers, Purple Teamers, Windows/AD admins, Incident Responders, Security Engineers with basic AD/Windows familiarity. If you’ve read about NTLM relay but never executed it end-to-end, this is for you.
Requirements
Agenda: Your 2-day training journey.
Day 1 – Offense to Understand Risk
NTLM protocol refresher → Relay mechanics and tooling → Same-/cross-protocol relays → Post-relay paths (local admin, secrets extraction, lateral movement) → Lab blocks after each module.
Day 2 – Detection & Defense
Relayed traffic fingerprints → Log sources & correlations → Hardening playbook (SMB signing, EPA, mitigations without breaking stuff) → Blue-team labs → Personalization: draft your rollout checklist.
The workshop will be led by Marios Pappas, an experienced penetration tester and red teamer with deep expertise in Active Directory security.
Get two days of hands-on, scenario-driven training inside real NTLM relay attacks, learn to exploit, detect and build deployable defenses in live Active Directory environments.
2-day workshop – €490
(VAT excluded)
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. Workshop syllabus, venue information, and preparation details will be sent to all registered participants prior to the event.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Syllabus:
Intro to GCP
Exploitation of GCP Services
Methodologies
Security Services
Syllabus:
Intro to AWS
Exploitation of AWS Services
Methologies
Common Detection Mechanisms
Syllabus:
Azure Basics
Exploitation of Azure Services
Methologies
Common Detection Mechanisms
Fundamentals and Setup
Advanced Techniques and Practical Application
Advanced Techniques and Practical Application
Fundamentals & Setup