Enrollment options

(Lab) Step into the role of Sandworm Team and recreate the December 23, 2015 cyberattack that cut power to roughly 225,000 Ukrainian customers, the first confirmed cyberattack to cause a large-scale blackout. Starting from a single phishing email, establish a foothold on an IT workstation, pivot into the OT network over VPN, and use the operators' own HMI to open breakers across a simulated substation. Then carry out the same anti-recovery playbook the real attackers used — bricking serial-to-ethernet gateways, cutting UPS power, and deploying a KillDisk-style wiper — to understand firsthand why the real outage lasted hours instead of minutes.

After completing this course, users will be able to:
 • Gain and persist a foothold on an IT network through phishing, C2, and credential theft
 • Pivot from IT to OT through VPN infrastructure and enumerate a segmented control network
 • Access and operate an HMI to manipulate breakers and cause a physical outage
 • Execute anti-recovery techniques — firmware sabotage, UPS shutdown, and disk wiping — to disable a defender's recovery tools
 • Map each stage of the attack to real-world ATT&CK for ICS techniques and evaluate the defenses and recovery procedures that would blunt it

Hours: 2.0
Self enrollment (Student)
Self enrollment (Student)