FLF Root Repo
FLF Root Repo
Lab guides synced from GitHub. Re-import from Admin → Docs to refresh this list.
card navigation
All cards of the V3 Core Deck
Initial Compromise
- Phishing
- Compomised Web Server
- Unauthorized Cloud Access
- Insider Threat
- External Password Spray
- Trusted Relationship
- Social Engineering
- Bring Your Own (Exploited) Device
- External Service Exploitation
- Credential Stuffing
Pivot & Escalate
- Internal Password Spray
- Kerberoasting
- Broadcast / Multicast Protocol Poisoning
- Weaponizing Active Directory
- Credential Harvesting
- New Service Creation / Modification
- Local Privilege Escalation
C2 & Exfil
- HTTP As Exfil
- HTTPS As Exfil
- Domain Name System As C2
- Backround Intelligent Transfer Service As Exfil
- Cloud Based Services As Exfil
- Domain Fronting As C2
Persistence
- Malicious Service
- Dynamic Link Library Hijacking
- Malicious Driver
- New User Added
- Application Shimming
- Malicious Browser Plugins
- Logon Scripts
- Malicious Firmware
- Accesibility Features
Detection
- Server Analysis
- Security Informations And Event Management Log Analysis
- Firewall Log Analysis
- Network Threat Hunting
- Active Defense And Cyber Deception
- Endpoint Security Protection Analysis
- User And Entity Behavious Analytics
- Endpoint Analysis
- Isolation
- Crisis Management
- Memory Analysis
- Cloud Event Log Analysis
- Permissions Audit
Green Expansion Deck V2
Initial Compromise
Pivot & Escalate
- Server Message Block (SMB) Abuse
- Internal Spearphishing
- Access Token Manipulation
- Stale Network Address Configurations (SNAC) Attack
- Cleartext Passwords in Files
C2 & Exfil
Persistence
- Dormant Malware
- Third-Party Malware Injection
- Malicious Email Rules
- Service Recovery Hijacking
- Startup Registry Injection
Detection
Cloud Security Expansion
Initial Compromise
Pivot & Escalate
C2 & Exfil
Persistence
Detection
navigation
Information Security Core Skills
- Applocker
- Atomic RedTeam and Bluespawn
- DeepBlueCLI
- Nessus
- Host Firewalls and Nmap
- Password Cracking
- Password Spraying
- External Password Spraying
- Responder
- RITA and AC Hunter
- Sysmon
- Web Testing
- PingCastle
- Azure IR
- Wireless
Intro To SOC
- Linux CLI
- TCPDump
- Web Log Review
- Web Testing
- WindowsCLI
- Wireshark
- Nessus
- DeepBlueCLI
- Domain Log Review
- Understanding ASNs
- Velociraptor
- Firewall Log Review
- Hunting DCSync, Sharepoint and Kerberoasting
- Scapy
- Hayabusa
- RITA2
- Email Analysis
- ACHunter2
Active Defense & Cyber Deception
Network Honeypots
Endpoint / Identity / AD deception
Web / Application
Malware capture & analysis
DNS / Network tooling
Phishing / Social-engineering
Red/Purple team detection testing
File / Data deception & auditing
coursenavigation
Course Navigation
Welcome
Log Analysis Basics
Security Tools & Foundational Platforms
- Intro
- LimaCharlie Hands-On
- Elastic SIEM Hands-On
- Viewing Alerts & Logs
- Writing & Modifying Basic Detection Rules
- Telemetry Searching
- Elastic Cloud Lab
- Elastic Local Lab
Introduction to Detection & Threat Behavior
Scripting for SOC Tasks
- Intro
- Python Scripting Basics
- Powershell Basics
- Lab 1 Detect Brute Force Script
- Lab 2 Collect System Info Powershell Script
- Scapy Documentation part 1
- Scapy Documentation part 2
- Scapy Lab
- Scapy Lab solution
Networking & Telemetry 101
Web Security
Browser & Cloud Security Fundamentals
Deception Systems
- Intro to Deception Techniques
- Generating Traps
- Active Defense & Cyber Deception
- Legal Notes
- Dionaea Lab
- Beelzebub Lab
Forensics Fundamentals
Email Fundamentals
- Identifying Phishing
- Common Email-Based Attacks
- Email Security Solutions
- Projects to Try
- Phishing Email Lab
Malware Forensics
- Introduction
- The Malware Analysis Workflow
- Malware Execution Chain
- Safe Analysis Environment
- Static Analysis
- Dynamic Analysis
- Behavioral Forensics and IOC(Indicators Of Compomise) Extraction
- Basic Unpacking and Deobfuscation
- Reverse Engineering
Documentation & Case Notes
Soft Skills
Other
- card navigation
- C2 Basic Terminology & Theory
- BITS easy 1
- BITS easy 2
- BITS hard
- BITS medium
- CBSE easy 1
- CBSE easy 2
- CBSE hard
- CBSE medium
- DF easy 1
- DF easy 2
- DF hard
- DF medium
- DNS easy 1
- DNS easy 2
- DNS hard
- DNS medium
- HE easy 1
- HE easy 2
- HE hard
- HE medium
- http exfil easy 1
- http exfil easy 2
- http exfil hard
- http exfil medium
- gost
- havok
- leviathan
- mythic
- sliver
- uboatrat
- ADCD easy 1
- ADCD easy 2
- ADCD hard
- ADCD medium
- CELA easy 1
- CELA easy 2
- CELA hard
- CELA medium
- CM easy 1
- CM easy 2
- CM hard
- CM medium
- EA easy 1
- EA easy 2
- EA hard
- EA medium
- EPA easy 1
- EPA easy 2
- EPA hard
- EPA medium
- FLA easy 1
- FLA easy 2
- FLA hard
- FLA medium
- ISO easy 1
- ISO easy 2
- ISO hard
- ISO medium
- MA easy 1
- MA easy 2
- MA hard
- MA medium
- NTH easy 1
- NTH easy 2
- NTH hard
- NTH medium
- PA easy 1
- PA easy 2
- PA hard
- PA medium
- SA easy 1
- SA easy 2
- SA hard
- SA medium
- siem easy 1
- siem easy 2
- siem hard
- siem medium
- UEBA easy 1
- UEBA easy 2
- UEBA hard
- UEBA medium
- ac hunter
- canarytokens
- deepbluecli
- elastic security
- Elastic Doc Cloud
- hayabusa
- honeybadger
- ritaLab1
- ritaLab2
- ritaLab3
- ritaLab4
- ritaLab5
- ritaLab6
- ritaLab7
- velociraptor
- volatilityLab1
- volatilityLab2
- volatilityLab3
- volatilityLab4
- wazuh
- BYOED easy 1
- BYOED easy 2
- BYOED hard
- BYOED medium
- CRED easy 1
- CRED easy 2
- CRED hard
- CRED medium
- CWS easy 1
- CWS easy 2
- CWS hard
- CWS medium
- EPS easy 1
- EPS easy 2
- EPS hard
- EPS medium
- ESE easy 1
- ESE easy 2
- ESE hard
- ESE medium
- IT easy 1
- IT easy 2
- IT hard
- IT medium
- phish easy 1
- phish easy 2
- phish hard
- phish medium
- SE easy 1
- SE easy 2
- SE hard
- SE medium
- TR easy 1
- TR easy 2
- TR hard
- TR medium
- UCA easy 1
- UCA easy 2
- UCA hard
- UCA medium
- burp suite
- caido
- credmaster
- Evilginx
- Exploit DB
- gato x
- GoPhish
- hashcat
- Metasploit
- Nuclei
- osint
- scoutsuite
- Shodan
- SocialEngineerToolkit
- sqlmap
- BMPP easy 1
- BMPP easy 2
- BMPP hard
- BMPP medium
- CH easy 1
- CH easy 2
- CH hard
- CH medium
- IPS easy 1
- IPS easy 2
- IPS hard
- IPS medium
- kerberoasting easy 1
- kerberoasting easy 2
- kerberoasting hard
- kerberoasting medium
- LPE easy 1
- LPE easy 2
- LPE hard
- LPE medium
- NSC easy 1
- NSC easy 2
- NSC hard
- NSC medium
- WAD easy 1
- WAD easy 2
- WAD hard
- WAD medium
- hashcat
- impacket
- inveigh
- lolbins
- net use
- netexec
- peass ng
- powershell
- psexec
- responder
- rubeus
- seatbelt
- sharpup
- AF easy 1
- AF easy 2
- AF hard
- AF medium
- AS easy 1
- AS easy 2
- AS hard
- AS medium
- DLL easy 1
- DLL easy 2
- DLL hard
- DLL medium
- LS easy 1
- LS easy 2
- LS hard
- LS medium
- MBP easy 1
- MBP easy 2
- MBP hard
- MBP medium
- MDR easy 1
- MDR easy 2
- MDR hard
- MDR medium
- MF easy 1
- MF easy 2
- MF hard
- MF medium
- MS easy 1
- MS easy 2
- MS hard
- MS medium
- NUA easy 1
- NUA easy 2
- NUA hard
- NUA medium
- atomic red team
- beef
- evilginx
- flashrom
- havok
- impacket
- metasploit
- powershell
- psexec
- sdb explorer
- sharpersist
- sharpstayPER
- shimgen
- PME easy 1
- PME easy 2
- PME hard
- PME medium
- PSR easy 1
- PSR easy 2
- PSR hard
- PSR medium
- SW easy 1
- SW easy 2
- SW hard
- SW medium
- HSTS easy 1
- HSTS easy 2
- HSTS hard
- HSTS medium
- PA easy 1
- PA easy 2
- PA hard
- PA medium
- SCA easy 1
- SCA easy 2
- SCA hard
- SCA medium
- ATM easy 1
- ATM easy 2
- ATM hard
- ATM medium
- CPF easy 1
- CPF easy 2
- CPF hard
- CPF medium
- IS easy 1
- IS easy 2
- IS hard
- IS medium
- SMB easy 1
- SMB easy 2
- SMB hard
- SMB medium
- SNAC easy 1
- SNAC easy 2
- SNAC hard
- SNAC medium
- responder
- DM easy 1
- DM easy 2
- DM hard
- DM medium
- MER easy 1
- MER easy 2
- MER hard
- MER medium
- SRH easy 1
- SRH easy 2
- SRH hard
- SRH medium
- SRI easy 1
- SRI easy 2
- SRI hard
- SRI medium
- TPMI easy 1
- TPMI easy 2
- TPMI hard
- TPMI medium
- navigation
- hayabusa
- ACHunterCE
- CuckooSandbox
- Metta
- azure logs
- cookie theft
- rmm takeover
- ws 3 security logs
- beelzebub
- falcon
- LCAR
- limacharlie
- MemoryAnalysis(Volatility)
- n8n part1
- n8n part2
- lab01
- lab02
- lab03
- lab04
- README
- ACHunter2
- RITA
- temp
- Video
- LabListBnB
- vsagent c2
- arp poison ctf
- arp poison lab
- covert tcp ctf
- covert tcp lab
- IPSec & IKEv2
- IPSec & IKEv2 CTF
- ospf ctf
- ospf lab
- fragroute ctf
- fragroute lab
- port knocking ctf
- Port Knocking Lab
- WireGuardLab
- WireGuard CTF
- README
- powershell for soc
- scripting for soc
- network logs
- ritaLab1
- ritaLab2
- ritaLab3
- ritaLab4
- ritaLab5
- ritaLab6
- ritaLab7
- webLabPart1
- webLabPart2
- volatilityLab1
- volatilityLab2
- volatilityLab3
- volatilityLab4
- email01 ctf
- email02 ctf
- email03 ctf
- email04 ctf
- email05 ctf
- email06 ctf
- email07 ctf
- email08 ctf
- Lab MalwareForensics
- Autopsy
- Binary Ninja
- Dionaea
- Elastic Doc Cloud
- Elastic Doc Local
- FTK Imager
- Hayabusa
- IDA Free
- PEStudio
- Rita
- snort
- suricata
- tcpdump
- Volatility
- WinEventViewer
- wireshark
- zeek
- coursenavigation