🚨Important Changes Coming to Constructing Defense - Please Read ⚠️

Hey Everyone!

First off, I want to thank all of you for signing up for Constructing Defense 🙂

I wanted to let you know about some upcoming changes to the course - I'll post the message in long form and then a "tldr" summary at the bottom.


Constructing Defense launched in January of 2024 - since then, additions to the course included:

  • A Ludus lab deploy option

  • A bunch of additional modules

  • The entire course re-done with Splunk as our SIEM

In that time, a new version of Constructing Defense has also been introduced on the justhacking.com platform.

This version takes Constructing Defense to a whole new level, as participants now have the option of purchasing Constructing Defense with all the labs pre-built and cloud accessible.

More recently, we also introduced ConDef Lite on the justhacking.com platform for folks who have the necessary hardware to build the lab without using the cloud. ConDef Lite matches exactly what you purchased through constructingdefense.com!

Although this has enhanced the delivery of Constructing Defense, it has also confused participants and made it difficult to support multiple "streams" and deploy options of the course.


Given this dynamic, I have made the decision to move Constructing Defense to the justhacking.com platform on a permanent basis.

If you have purchased the course on this platform, keep an eye on the inbox for the email account that you used to sign up with, as you will be offered a free coupon for ConDef Lite. This email will also contain a special offer to upgrade to Constructing Defense 2025.

If you are in the middle of going through the course on this platform and do not want to switch over, no worries there either, as this version of Constructing Defense will be up and available until at least November 24 2025, at that time, I will get a temperature check and potentially renew this platform for another year to give folks more time to migrate their progress over.

There are no price increases to the course and no changes to the lifetime availability.


Going forward, new modules will be created using Splunk only and the current stream of the course using Sumo Logic will be archived and no longer supported.

Likewise, I plan to sunset the AWS Terraform deploy option of the course, as it is now redundant given the Ludus deploy options.

These changes will allow me to focus on streamlining the Ludus deploy of the course as well as creating new modules without having to duplicate efforts like recording videos for two different SIEM platforms.

If you have any questions or concerns, please do not hesitate to reach me, either through comments here or anton@constructingdefense.com

Cheers and thank you all!


TLDR:

  • Constructing Defense is moving to justhacking.com

  • If you have already signed up for Constructing Defense, keep an eye out on the inbox for the email you used to sign up for the course, you will given free access to ConDef Lite on justhacking.com and a special offer to upgrade to Constructing Defense 2025!

  • Current version of Constructing Defense will remain online until November 24th 2025 and potentially longer depending on how the migration goes, so you will not lose your progress if you are in the middle of the course

  • New modules will be done in Splunk only

  • AWS Terraform deploy option will be archived in favor of Ludus

  • No changes to pricing

  • No changes to lifetime access

Current State:

New State:

Constructing Defense

Buy nowLearn more
  • 🚨Important Changes Coming to Constructing Defense - Please Read ⚠️3

Welcome to Constructing Defense!

  • Welcome & Introduction
  • Changelog

Lab Overview

  • Lab Overview4
  • General Lab Build Approach2

Lab Construction

  • ISO Downloads - Windows Server 20192
  • ISO Downloads - Windows 11
  • ISO Downloads - Ubuntu2
  • ISO Downloads - PCAP3

Lab Construction - AWS Version

  • Terraform Setup9
  • Domain Controller
  • Windows 11 A & V
  • Certer
  • Linux A & Linux V2

[Splunk] - Lab Construction & Provisioning - Ludus Version

  • [Splunk] - Ludus Overview5
  • [Splunk] - Ludus Deploy4
  • [Splunk] - Ludus Post Deploy Setup

Lab Construction & Provisioning - Ludus Version

  • Ludus Overview
  • Ludus Setup10
  • Ludus Post Deploy Setup4

Lab Provisioning

  • Domain Controller6
  • Windows 11 A & V7
  • Certer
  • Linux A & Linux V4
  • PCAP15
  • PCAP - New Malcolm Version10
  • Cloud Accounts - Azure1
  • Cloud Accounts - Amazon Web Services (AWS)1
  • Kubernetes Setup
  • Sysmon Setup7

Telemetry Setup & Miscellaneous Lab Configuration

  • Section Intro
  • Windows Auditing and GPO Setup
  • Disabling Defender
  • Certificate Enrollment
  • Linux Auditd + Laurel19
  • Sumo Logic SIEM Account
  • [Sumo Logic] - Windows Event Collection3
  • [Sumo Logic] - Linux Event Collection3
  • [Legacy] - Kubernetes Monitoring
  • [Sumo Logic] - Kubernetes Monitoring5
  • [Sumo Logic] - Cloud Collection - AWS5
  • [Sumo Logic] - Cloud Collection - Azure5
  • [Splunk] - Splunk Setup
  • [Splunk] - Forwarder Setup (Windows)5
  • [Splunk] - Forwarder Setup (Linux)3
  • [Splunk] - Kubernetes Monitoring9
  • [Splunk] - Cloud Collection - AWS5
  • [Splunk] - Cloud Collection - Azure/Entra

Lab Executions

  • Section Intro
  • Getting to Know Ourselves3
  • Our First Shell1
  • First Shell - Detection 1
  • First Shell - Detection 2
  • Our Second Shell - Exploring the Network Layer5
  • Second Shell - Bonus Round
  • Credential Access on Windows Hosts - LSASS
  • Credential Access on Windows Hosts - File Shares1
  • Credential Access on Windows Hosts - Kerberoasting
  • Credential Access on Windows Hosts - DCSync
  • Lateral Movement in Windows Environments - WMIExec5
  • Lateral Movement in Windows Environments - PSExec
  • Discovery/Recon Detection on Windows Hosts
  • Profiling Rundll32 Executions on Windows Hosts
  • LOLBAS / LOLBINs
  • Active Directory Certificate Services3
  • Authentication Anomalies on Windows Hosts - The Classic Brute Force
  • Authentication Anomalies on Windows Hosts - The Kerberos Approach
  • Credential Access on Linux Hosts - The Shadow File
  • Credential Access on Linux Hosts - Through a C2 Framework
  • Lateral Movement on Linux Hosts - Interactive Bash Prompts
  • Web Shell Detections on Linux Hosts
  • Kubernetes Threat Detection - Dipping our Toes
  • Kubernetes Threat Detection - The Host Layer
  • Kubernetes Threat Detection - The Host Layer - Enumeration
  • Kubernetes Threat Detection - Tunneling & Exposed Services
  • Kubernetes Goat 🐐
  • Kubernetes Threat Detection - Poisoned Pod
  • Azure - Password Sprays
  • Azure - MFA Madness
  • Azure - Wrangling Applications
  • [Legacy] - Azure - Bad to the Bone3
  • [Updated] - Azure - Bad to the Bone
  • Azure - AzureHound2
  • Azure/Entra Session Hijacking via Browser Cookie Theft 🍪
  • Azure Session Hijack via HAR File
  • AWS - Account Set Up and CLI Access2
  • AWS - CloudTrail - IAM User Creation
  • AWS - CloudTrail - IAM User Enumeration
  • AWS - CloudTrail - Pacu - IAM Brute Force
  • AWS - CloudTrail - Pacu - S3 Bucket Exfil
  • Adding a bit of Purple
  • Endpoint Analysis with Hayabusa and Langchain
  • Kerberos Attacks & Defenses - Pass the Ticket
  • Kerberos Attacks & Defenses - Golden Ticket
  • Web Sockets & .NET Assemblies
  • DPAPI at the Host and Network Layer
  • Purple Teaming Memory Forensics with MemProcFS

Lab Executions - Splunk

  • [Splunk] - Getting to Know Ourselves
  • [Splunk] - Our First Shell3
  • [Splunk] First Shell - Detection 12
  • [Splunk] - First Shell - Detection 2
  • [Splunk] - Our Second Shell - Exploring the Network Layer2
  • [Splunk] - Second Shell - Bonus Round
  • [Splunk] - Credential Access on Windows Hosts - LSASS
  • [Splunk] - Credential Access on Windows Hosts - File Shares
  • [Splunk] - Credential Access on Windows Hosts - Kerberoasting
  • [Splunk] - Credential Access on Windows Hosts - DCSync
  • [Splunk] - Lateral Movement in Windows Environments - WMIExec
  • [Splunk] - Lateral Movement in Windows Environments - PSExec
  • [Splunk] - Discovery/Recon Detection on Windows Hosts
  • [Splunk] - Profiling Rundll32 Executions on Windows Hosts
  • [Splunk] - LOLBAS / LOLBINs
  • [Splunk] - Active Directory Certificate Services
  • [Splunk] - Authentication Anomalies on Windows Hosts - The Classic Brute Force
  • [Splunk] - Authentication Anomalies on Windows Hosts - The Kerberos Approach
  • [Splunk] - Credential Access on Linux Hosts - The Shadow File
  • [Splunk] - Credential Access on Linux Hosts - Through a C2 Framework
  • [Splunk] - Lateral Movement on Linux Hosts - Interactive Bash Prompts
  • [Splunk] - Web Shell Detections on Linux Hosts
  • [Splunk] - Kubernetes Threat Detection - Dipping our Toes
  • [Splunk] - Kubernetes Threat Detection - The Host Layer
  • [Splunk] - Kubernetes Threat Detection - The Host Layer - Enumeration
  • [Splunk] - Kubernetes Threat Detection - Tunneling & Exposed Services
  • [Splunk] - Kubernetes Goat 🐐
  • [Splunk] - Kubernetes Threat Detection - Poisoned Pod
  • [Splunk] - Azure - Password Sprays
  • [Splunk] - Azure - MFA Madness
  • [Splunk] - Azure - Wrangling Applications
  • [Legacy] - Azure - Bad to the Bone
  • [Updated] - Azure - Bad to the Bone
  • [Splunk] - Azure - AzureHound
  • [Splunk] - Azure/Entra Session Hijacking via Browser Cookie Theft 🍪
  • [Splunk] - Azure Session Hijack via HAR File
  • [Splunk] - AWS - Account Set Up and CLI Access
  • [Splunk] - AWS - CloudTrail - IAM User Creation
  • [Splunk] - AWS - CloudTrail - IAM User Enumeration
  • [Splunk] - AWS - CloudTrail - Pacu - IAM Brute Force
  • [Splunk] - AWS - CloudTrail - Pacu - S3 Bucket Exfil
  • [Splunk] - Adding a bit of Purple
  • [Splunk] - Endpoint Analysis with Hayabusa and Langchain
  • [Splunk] - Kerberos Attacks & Defenses - Pass the Ticket
  • [Splunk] - Kerberos Attacks & Defenses - Golden Ticket
  • [Splunk] - Web Sockets & .NET Assemblies
  • [Splunk] - Purple Teaming Memory Forensics with MemProcFS

Saying Goodbye 👋

  • Outro4