
In this four-hour, hands-on workshop, you will build a video deepfake yourself, using the same kinds of open-source and commercial-grade tools a real attacker would use.
Course Length: 4 Hours
Includes a Certificate of Completion
Next scheduled date: November 17th, 2026 @ 12:00 PM ET
Description
Seeing is no longer believing, and hearing isn’t either. In this four-hour, hands-on workshop, you will build a video deepfake yourself, using the same kinds of open-source and commercial-grade tools a real attacker would use. You’ll retrieve source footage of a consenting target and clone their voice from a short sample. You’ll sync that voice to their face and generate brand-new talking video from a single still photo. Each step saves a file that feeds the next part of the process.
By the end, you’ll have built the full fabrication chain: a synthetic face and a synthetic voice, synced together. Then you’ll watch a live, real-time face swap on a video call, the same class of attack that cost one multinational firm roughly $25 million.
Building it is how you learn where it breaks. At each stage, you’ll look for the audio and visual tells that detection depends on, and you’ll see why a detector alone won’t save you. We finish by turning what you built into a scoped, authorized social-engineering test, and into the verification controls that can stop these attacks.
Walk out with your own deepfake artifacts, a working cloud toolchain you can reuse, and first-hand evidence for your leadership, not vendor projections.
Who Should Take This Workshop
Security practitioners who need to answer the question “Could this happen to us?” with evidence and not a vendor slide.
- Red team operators, penetration testers, and social-engineering assessors who want to add deepfake pretexts to authorized engagements
- Security awareness and human risk management leads who need to show, not tell, what employees are up against
- Incident responders, SOC analysts, and fraud or threat-intel teams who need to recognize synthetic media when it shows up in a case
- Security leaders, GRC staff, or business leaders who brief executives and design verification procedures
No AI or machine-learning background is needed. If you work in security and can find your way around a web app and a file system, you should be good to go.
What You’ll Learn
By the end of the workshop, you will be able to:
- Explain how the modern video-deepfake attack chain works, from source retrieval to finished fake, and what each stage really costs an attacker in time and money.
- Retrieve and assess source media, and determine whether a target’s public footage is good enough to fake.
- Clone a voice from a short reference sample and hear where the clone falls apart.
- Lip-sync a cloned voice onto real video footage.
- Generate talking video from a single still image, then sync it to the cloned voice.
- Plan an authorized deepfake social-engineering test: pretext, delivery channel, scope and consent, evidence capture, and safe-abort criteria.
- Recommend out-of-band verification controls that hold up against voice and video impersonation.
-
System Requirements
- There are two ways the students can create the synthetic media: locally or in the cloud. Locally will require a gaming-style laptop, preferably with an NVIDIA GPU with 16-24GB NVRAM running on Windows.
-
Cloud path (recommended for everyone):
- Any modern laptop or desktop (8 GB RAM or more) with a current Chrome, Edge, or Firefox browser
- Stable broadband internet since you’ll move video and audio files between your machine and the cloud
- A MimicPC account with about $10 in credit (details below). No local software installs or GPU required.
- Optional: a webcam and microphone if you want to use your own likeness as source material
-
Local path (optional; for experienced users):
- NVIDIA GPU with 24 GB+ VRAM (RTX 3090 / 4090 / 5090 class or equivalent)
- Windows 11 or Linux, 32 GB+ system RAM, 100 GB+ free SSD space
- Python 3.10+, git, and ffmpeg installed. Local setup guidance is shared before class.
- Apple Silicon Macs are not supported for the labs due to the limitations of the tools. Mac users should use the cloud path.
- Live support during class goes to the cloud path first. If your local setup breaks mid-lab, switch to a cloud instance.
Syllabus
Each lab block ends by saving a file the next segment of the workshop will use.
Block 1: Threat Frame and Reconnaissance (55 min)
Why deepfakes moved from novelty to commodity fraud tool, and how attackers find usable source material.
- Case study: a real-time, multi-participant deepfake video call and the loss that followed
- Ground rules: consent, scope, and the authorized-use boundary
- What makes source footage usable, and why capture quality caps output quality
- Lab: Retrieve source video and clean audio with a command-line media tool, and collect metadata as OSINT
Save point: Source video + clean audio file.
Break: 5 min
Block 2: Voice Cloning (50 min)
Turn a short audio sample into a voice that says whatever you type.
- Lab: Load your reference sample, write a plausible pretext line, generate several takes, and pick the best one
- Listening for the tells: odd vowels, flat emotion, unnatural pacing
Save point: Cloned-voice audio file.
Break: 10 min
Block 3: Lip-Sync (55 min)
Make the target’s mouth match the cloned voice.
- How mouth-region lip-sync models work, and where their limits become detection tells
- Lab: Combine your Block 1 video with your Block 2 cloned voice to produce a talking deepfake
- Looking for the tells: face-region seams, head turns, non-frontal frames
- Why audio tells plus video tells still don’t add up to a reliable detector
Save point: Lip-synced deepfake video. If your run fails, Block 4 includes a second attempt.
Break: 5 min
Block 4: Synthetic Video, Real-Time Demo, and Turning It into an Assessment (60 min)
Go from editing real footage to generating new footage, close the loop, and turn the skill into a test plan.
- Lab: Generate a short talking-head clip from a single still image and a text prompt
- Lab: Re-sync the generated clip to your cloned voice, a fully synthetic face and voice together (and a second chance for anyone whose Block 3 run failed)
- Instructor demo: Real-time face swap on a live video call, with failure modes narrated as they happen
- From artifact to assessment: pretext design, delivery channel, scope and consent, evidence capture, safe-abort criteria
- The defensive answer: out-of-band callback verification, and where detection fits as supporting evidence
- Wrap-up, take-home resources, and Q&A
Save point: Final artifact: generated video re-synced to the cloned voice.
FAQ
All synthetic media generation can run on the student’s Windows-based machine with an NVIDIA graphics card and 24GB NVRAM. If the student does not have this type of high-end system, they will need to use MimicPC, which is a browser-based cloud GPU platform capable of running the resource-intensive applications to create the AI generated synthetic media.
For MimicPC, each student uses their own account. You’ll use a Large-tier instance (24 GB GPU, L4/A10 class). The instructor will provide a pre-built workflow files and step-by-step setup instructions before the session.
Estimated cost: Budget about $10 in MimicPC credit, which covers setup, the four-hour class, and some practice afterward. The Large tier is currently listed at about $0.99/hour on-demand (as of September 2026; check MimicPC’s pricing page, since rates change). The free trial credit is not enough to complete the labs.
Please note: MimicPC purchases are non-refundable.
Students should sign up and pay for the MimicPC cloud instance directly. Compute cost is not included in the workshop price.
Beginner to Intermediate
No AI, machine-learning, or coding background is needed.
Labs run on a cloud GPU platform you manage yourself. The ability to troubleshoot simple setup issues (logging in, launching an instance, uploading and downloading files) matters more than technical depth.
If you are running your own local machine, you will need to preload applications and materials prior to the workshop.
Pre-class setup checklist (complete before start of workshop):
- Create a MimicPC account and add credit. (preferably $10)
- Download the workshop setup guide and workflow files (provided on the Discord server and/or emailed to attendees the week before the event)
- Launch a Large-tier instance and follow the setup guide to load the workshop workflows. The first launch downloads large model files, so doing this ahead of time keeps class time for building.
- Run the setup check in the guide to confirm everything loads, then shut the instance down.
Optional: if you want to use your own likeness, record a clean, front-facing video of yourself (about 60 seconds, speaking naturally, good light, quiet room) and take one clear front-facing photo.
Ethics and authorization
All hands-on work uses a consented people pack provided by the instructor, or your own face and voice. No public figures, coworkers, or other third parties.
This is a skills course for authorized assessment and defense, not a fraud tutorial.
About the Instructor
James McQuiggan
Bio
James McQuiggan spent 18 years in operational technology security at Siemens Energy, where the stakes of a misconfiguration aren’t a news headline: they’re a power grid outage. That background informs how he thinks about risk and how he communicates it to leadership.
He now works as an Advisory CISO focused on Human Risk Management, helping organizations move beyond checkbox security awareness training toward programs that measurably change behavior. He’s also working with clients on emerging threats from agentic AI systems and polymorphic attacks.
James holds a CISSP, leads an ISC2 chapter, teaches Cyber Threat Intelligence at Full Sail University, and hosts the Simply Secured podcast. He has a background in musical theatre, which tends to show in how he delivers a session — he is equal parts educator and entertainer.
Register for Upcoming
Workshop: Build a Deepfake Learn the Defense
Live Training James McQuiggan
- Certificate of participation
- Six months access to class recordings
- Our appreciation
Related products
-
Patterson CakeLive4 Hrs
Workshop: Investigating M365 Business Email Compromise
View Course This product has multiple variants. The options may be chosen on the product page -
Tim MedinLive4 Hrs
Workshop: Hands on Kerberos
View Course This product has multiple variants. The options may be chosen on the product page -
Hayden CovingtonLive4 Hrs
Workshop: SOC Detection Engineering Crash Course
View Course This product has multiple variants. The options may be chosen on the product page -
Hal DentonLive4 Hrs
Workshop: Telemetry to Tactics: A Hands-On Detection Engineering Workshop with Hal Denton
View Course This product has multiple variants. The options may be chosen on the product page

