Glusvox
Cyber Security

Secure Enterprise Networks
& Active Directory

A 26-module program covering enterprise network infrastructure, Active Directory attack paths, and compliance-ready VAPT reporting.

Enterprise VAPT & Network Infrastructure Security

Learn how real enterprises are attacked and defended - from firewalls, VPNs, and NAC to Active Directory domain dominance, Kerberos exploitation, and OT/ICS security, taught in a full multi-domain lab environment.

  • 26 Hands-On Lab Modules
  • Active Directory & Kerberos Attack Paths
  • Enterprise Firewall & NAC Testing
  • 4-Week Enterprise Infrastructure Internship

Full Course Curriculum

26 modules, from network baselines to a guided enterprise infrastructure internship.

Module 1: Enterprise Network Architecture & Security Baselines
  • Tiered network models, DMZs, zero-trust segmentation, micro-segmentation, and security baselining.
Module 2: Network Infrastructure Protocols Deep Dive
  • Routing protocols (OSPF, BGP), switching protocols (VLAN, STP, 802.1Q), and tunneling mechanisms.
Module 3: Enterprise Firewall Technologies & Rule Evaluation
  • Stateful vs. Next-Gen Firewalls (Palo Alto, Fortinet, pfSense), rulebase analysis, and NAT configurations.
Module 4: Secure Remote Access & VPN Implementation
  • IPSec tunnels, SSL/TLS VPNs, WireGuard implementations, certificate validation, and split tunneling risks.
Module 5: Intrusion Detection & Prevention Systems (IDS/IPS)
  • Snort/Suricata rule architecture, signature-based vs. heuristic inspection, and tuning false alerts.
Module 6: Network Access Control (NAC) & 802.1X
  • EAP types, RADIUS/TACACS+ integration, posture checking, and dynamic VLAN assignment.
Module 7: Enterprise Network Mapping & Surface Scanning
  • Large-scale IP sweeping, Masscan, Amass, edge asset profiling, and identifying shadow IT.
Module 8: Router, Switch, and Firewall Penetration Testing
  • SNMP brute forcing, configuration downloading via TFTP, Cisco IOS exploit paths, and protocol abuse.
Module 9: Enterprise Vulnerability Management with Qualys/Nessus
  • Policy-based scanning, agent vs. agentless deployments, patch audit scans, and remediation orchestration.
Module 10: Active Directory Architecture & Kerberos Protocol
  • Forests, trees, domains, trust relationships, Kerberos authentication (TGT, TGS, PAC), and SPNs.
Module 11: Active Directory Domain Enumeration
  • BloodHound, SharpHound, PowerView, discovering shortest attack paths, ACL/ACE relationships.
Module 12: Kerberos Exploitation: Kerberoasting & AS-REP Roasting
  • Requesting TGS tickets, SPN discovery, offline cracking with Hashcat, and exploiting accounts without pre-auth.
Module 13: NTLM Relay & Credential Harvesting
  • LLMNR/NBT-NS poisoning (Responder), SMB signing checks, NTLM relaying to LDAP/SMB, and defense mechanisms.
Module 14: Token Manipulation & Impersonation
  • Pass-the-Hash (PtH), Pass-the-Ticket (PtT), Overpass-the-Hash, and mimicking elevated process tokens.
Module 15: AD Certificate Services (AD CS) Attacks
  • ESC1 to ESC8 templates, misconfigured certificate issuing, and domain persistence via machine certificates.
Module 16: Domain Dominance & Persistence
  • Golden & Silver Tickets, DCSync attacks, Skeleton Key injection, AdminSDHolder modifications, and DSRM abuse.
Module 17: Enterprise Wireless Infrastructure Security
  • WPA2/WPA3 Enterprise setup, RADIUS server impersonation, rogue AP detection, and wireless client isolation testing.
Module 18: VoIP & Telecom Security Auditing
  • SIP protocol mechanics, RTP interception, VoIP phone firmware exploitation, and call eavesdropping.
Module 19: Enterprise Cloud & Hybrid Identity Security
  • Microsoft Entra ID (Azure AD) sync, pass-through authentication, hybrid AD attacks, and IAM policy auditing.
Module 20: Advanced Pivoting & SOCKS Proxies
  • Chisel reverse proxies, Ligolo-ng, multi-tier pivoting across isolated corporate enclaves.
Module 21: OT/ICS & SCADA Network Security Basics
  • Modbus, DNP3, Purdue model, PLC isolation, and identifying critical control system vulnerabilities.
Module 22: CIS Benchmarks & Enterprise Hardening
  • Applying Windows and Linux CIS baselines, disabling unneeded protocols (SMBv1, LLMNR), and GPO hardening.
Module 23: Threat Modeling & Risk Assessment Methodologies
  • STRIDE framework, DREAD scoring, NIST SP 800-30 risk assessment, and attack tree construction.
Module 24: Security Compliance & Audit Standards
  • PCI-DSS requirements, ISO/IEC 27001 ISMS, SOC 2 Type II controls, and mapping technical findings to audit frameworks.
Module 25: Comprehensive Enterprise VAPT Report Delivery
  • Writing for CISOs vs. SysAdmins, risk prioritization matrix, proof-of-concept documentation, and executive debriefs.
Module 26: Capstone Project & Enterprise Infrastructure Internship
  • Project: Full network penetration test of a multi-domain Active Directory forest protected by firewalls, segmented VLANs, and remote VPN users.
  • Internship: 4-week enterprise simulation - handling change management tickets, patching domain controllers, and conducting post-remediation re-scans.

Training Built, To Get You Hired

We don't just teach concepts we build job-ready security professionals through hands-on labs, certified mentors, and real career support.

Hands-On Labs

Every module is practiced in real lab environments, not just slides and theory.

Industry Mentors

Learn from CEH and CISSP-certified practitioners who work in security every day.

Certification-Aligned

Curriculum mapped directly to CEH, CISSP, and other industry-recognized exams.

Career Support

Resume, interview prep, and job placement support through our in-house career team.

0
Students Trained
0
Certification Pass Rate
0
Expert Mentors

Our Proven Training Journey

A structured 4 step path from beginner to certified, job-ready security professional.

01

Foundations & Assessment

We assess your starting point and build core security fundamentals before diving into labs.

02

Hands-On Lab Training

Guided, real-world labs across networking, web, mobile, and cloud security.

03

Certification Prep

Structured exam prep and mock tests aligned to CEH, CISSP, and other certifications.

04

Career Support & Placement

Resume building, interview prep, and job placement support for your first security role.

Let's Build Your Security Career

Book a free counselling call with our training team. No sales pitch just a clear path to your first cyber security role.

Contact Info
Email
support@glusvox.com
Address
30 N Gould St Ste N, Sheridan, WY 82801
Hours
Monโ€“Fri, 9:00 AM โ€“ 6:00 PM
Follow Us