Sign up for our free What in the Actual Cyber?! 2026 in Review Summit December 9 Register Here

Advanced Penetration Testing of Non-Western IT Infrastructures

Course Authored by .

This course has been designed for those charged with helping to secure non-western IT systems by way of penetration testing.

Course Length: 8 Hours

Includes a Certificate of Completion



Description

This course has been designed for those charged with helping to secure non-western IT systems by way of penetration testing.

Most offensive-related cybersecurity courses today are tailored to focus on western Information Technology systems. Primarily, English-based software and systems running on-premises or hosted in cloud infrastructure, owned by western-based companies, residing within US or EU borders. This course and associated labs will cover a range of technologies, languages, software, and services that a penetration tester may encounter while engaging various theoretical non-western organizations and the different challenges each may bring. Most importantly, this course will provide you with the necessary mindset and flexible TTP’s to efficiently and effectively assess the security of any non-western IT infrastructure.

  • Student/Lab Requirements
    • Students need to be able to run an Ubuntu Virtual Machine and connect laptop to my wifi.
    • Instructor provides an OVA / OVF to import.

Syllabus

  1. Introduction
    • Roll call
  2. Workshop Overview
    • Rules
    • Labs
      • Range overview
      • How to access the range
  3. Operational Setup
    • Attack stations
      • Operating systems
        • Linux
        • Windows
      • Operator Profiles
      • Operator tools
    • OPSEC considerations
      • Financing
      • Technical
        • Hostnames and usernames
        • Tooling OPSEC
        • LLM Usage
        • Networking/Traffic obfuscation
  4. Initial OSINT and Recon Activities
    • Overview
    • Scanning by Third-Party
      • What can we find?
      • Shodan
      • ZoomEye
      • Fofa
      • Honeypot Identification
      • SCADA Enumeration
      • Remote Access Point Enumeration
      • Camera and CCTV Enumeration
      • SSL/TLS Enumeration
    • Attack surface enumeration
      • Port scanning
      • Service enumeration
      • Web content enumeration
      • Cloud service discovery
      • IP/DNS Discovery
      • Certificate analysis and transparency search
      • User enumeration
    • Research unknown/unfamiliar technology stacks
  5. Detection Awareness
    • Setup and tooling
    • Identifying deception technologies
    • Detect being detected
  6. Post Exploitation
    • Host triage
      • Cohabitation checks
    • Persistence
    • Network enumeration
    • Data enrichment
    • Lateral movement
    • Data exfiltration
  7. After Action Review and Cleanup
    • Desired state status (cleanup)
    • Provide deliverables
    • AAR

FAQ

Who Should Attend:

Students or penetration testers interested in testing non-western networks.

Key Takeaways:

This course will provide you with the necessary mindset and flexible TTP’s to efficiently and effectively assess the security of any non-western IT infrastructure.

Applicable Business Skills:

Students will take back unique and advanced techniques to improve their business or clients’ computer systems through penetration testing and breaking assumptions of security.

About the Instructor

Pixel splash background
Bio

Steve Borosh is a proud U.S. Army Infantry veteran and security consultant at Black Hills Information Security. Since 2014 he has worked as a penetration tester, red team operator, and instructor for public, private, and federal law enforcement audiences.

His current focus is building practical, high-energy courses that teach operators how to develop realistic attack paths and custom tooling against non-Western IT environments. These courses cover systems such as AstraOS and ALDPro, as well as simulated Russian and Chinese network architectures—environments that most Western-centric training simply ignores. The goal is to give students the flexible TTPs and mindset needed to assess the security of any non-Western infrastructure they may encounter.

Steve regularly delivers this material at BSides Prague, BSides Krakow, and for private customers, in addition to speaking at Black Hat, Gartner, and other conferences. He maintains a blog and GitHub repository where he shares open-source offensive tools and research with the community.

He holds a B.S. in Computer and Information Science from ECPI University.

Shopping Cart

No products in the cart.