Identity-Driven Offensive Tradecraft (IDOT)
BLUF
Identity-driven Offensive Tradecraft by SpecterOps is a great opportunity to deepen your understanding of (well) identity-based attacks, focusing in AD(CS|DS), EntraID, SCCM, and some more. My personal highlights were the large-scale lab environment, that one could explorer at their own pace, and the spontaneous discussions with the excellent instructors. So if you wanted to explore topics beyond the provided slide deck you had many chances to do so, including among training attendees. While OPSEC was not enforced, a daily defensive debrief went through what alerts were triggered and how that could be avoided. This along the interspersed “Red vs Blue” slides meant that even blue team folk will get explicit value out of the training. And also amazing stickers and other swag.
Similarly to last year I had the privilege of attending BlackHat Europe as a great way to end the year and learn new things. While the original idea was to attend both the conference and training, some rather large cuts in the training offering let to attending a 4-day training.
As you have already seen from the title the training in question was Adversary Tactics - Identity-driven Offensive Tradecraft by SpecterOps. In this post I want to describe the course a bit more in the hope of helping others with their training decisions. This will mostly be through the lens of the blue-team, with some “purple” perspectives.
So what was the course all about? For this I will quote SpecterOps themselves:
… Participants will learn how to abuse the intricacies of different authentication and authorization mechanisms to traverse on-premises and cloud environments, gain access to integrated systems, and even cross tenants. Participants will also be equipped with a practical approach to identifying known Attack Paths and forging new ones within complex operational environments and across people, processes, and technology1.
The course contents stayed true to the publicly available information, so I will refrain from regurgitating the curriculum (that you will also find with the link above). Instead I focus on the parts that I found particularly interesting.
Curriculum Highlights
Day 1
In the provided read ahead materials and the first slides, it was highlighted that attendees should have a good understanding of Windows and Active Directory as well as working through a C2 Framework. The course provided you out of the box with a CobaltStrike and Mythic team server, leaving you to choose with which you want to do the labs.
Instead of several smaller targeted labs each team of four had their own large-scale environment that you could explorer/exploit freely. The only exception to that was the EntraID/Azure stuff on day four, which was shared between teams, and which railroaded you into certain attack paths. We used this freedom to take some shortcuts on day one, which enabled us to “skip” some the latter labs, while spending more time experimenting on labs like NTLM relaying.
While the most theoretical the initial discussion about “Attack Path Theory and The Clean Source Principle” provided some nice food for thought. If you read the SpecterOps blog for either a long time or read some older posts you will find these topics to somewhat familiar23 .
Most attack-related sections also contained a “Red vs Blue” part, where detection and further evasion opportunities of the taught tradecraft were highlighted. Some of them we would revisit on the following morning.
Day 2
A defender will also actively “hunt” students in the lab to push them to improve their tradecraft by making educated decisions.
The day started with a defensive debrief, which become a main stay for the remaining days. Here the “hunter” showcased the alerts one of the team raised on the day before and explained (based on the “Red vs Blue” slides) how these detections could be evaded. This was also the part, were each team could get credentials for their Elastic instance to see their alerts in real-time.
My personal technical highlight was the entire “NTLM Relay” topic of the day, which included both user and machine coercion alongside some ADIDNS tradecraft. A nice primer on NTLM Relay Attacks is also available on the SpecterOps Blog4 .
Update 2026 There is now another blog post, that goes into some details on the "there and back again" NTLM relay tradecraft.
Day 3
On this day I particularly enjoyed the large amount of time spent on SMS aka. SCCM aka. MECM aka. CCM and the accompanying Misconfiguration Manager project. This part was taught by one of the authors of the said project. Coincidentally the author of a related tool pxethiefy was an attendee of this training.
Day 4
The last day focused entirely on identity-attacks within EntraID and Azure. A large part of the day was spend teaching about the underlying principals and technologies, such as OAuth flows, different token and identity types and so on. While I have not really mentioned it this emphasis on understanding the why as compared to only knowing the how was the primary focus throughout the entire course.
After the course was over the lab environment stayed up for a few more days, allowing you to revisit part of the lab.
Footnotes
-
https://specterops.io/training/identity-driven-offensive-tradecraft/ ↩
-
https://specterops.io/blog/2024/07/17/the-security-principle-every-attacker-needs-to-follow/#access-control-fundamentals ↩
-
https://specterops.io/blog/2025/10/08/the-clean-source-principle-and-the-future-of-identity-security/ ↩
-
https://specterops.io/blog/2025/04/08/the-renaissance-of-ntlm-relay-attacks-everything-you-need-to-know ↩