Skip to main content

Core 3 · Cyber Warfare & Advanced Threat Defence

Cyber warfare training for security teams

Instructor-led courses that teach your team how state-linked groups break in, hide and prepare to disrupt, and how to catch them in your own environment.

  • From £1,995 per person, ex VAT
  • 2 to 10 days per course
  • Onsite worldwide or live online
Illustration. The pink line is the route Volt Typhoon took, per CISA advisory AA24-038A.
threat groups catalogued by MITRE ATT&CK
180
MITRE ATT&CK v19.2
nationally significant UK incidents, Sep 2024 to Aug 2025
204
NCSC Annual Review 2025
global median time attackers went undetected in 2025
14 days
Mandiant M-Trends 2026
courses in this track, Foundation to Expert
35

What it is

Cyber warfare takes five forms

Cyber warfare is the use of digital attacks by states, or groups acting for them, to spy on, disrupt or weaken another country. Each form below has a recent, publicly attributed example. Read the full guide to cyber warfare

  • Espionage

    Stealing secrets from governments and companies. The NCSC assessed that APT31 ran reconnaissance against UK parliamentarians.

    NCSC, 25 Mar 2024

  • Sabotage

    Breaking systems people rely on. Destructive commands knocked tens of thousands of Viasat KA-SAT broadband modems offline as Russia invaded Ukraine.

    Viasat, 30 Mar 2022

  • Pre-positioning

    Getting inside now to disrupt later. Volt Typhoon kept footholds in some US infrastructure networks for at least five years.

    CISA AA24-038A, 7 Feb 2024

  • Influence

    Shaping what a population believes. The US seized 32 domains used by Russia's "Doppelganger" campaign to pose as real news sites.

    US DoJ, 4 Sep 2024

  • State theft

    Stealing money to fund a state. The FBI attributed the theft of about US$1.5 billion from the Bybit exchange to North Korea.

    FBI, 26 Feb 2025

Anatomy of a real attack

How Volt Typhoon got in and stayed hidden

Six steps from the joint advisory by CISA, the NSA, the FBI, the UK NCSC and partners. For each one, the ATT&CK technique it maps to and a related course.

Source: CISA AA24-038A

ATT&CK® technique IDs © 2026 The MITRE Corporation. Reproduced with the permission of The MITRE Corporation.

  1. Reconnaissance

    Extensive research into the target's network, staff and security before any break-in.

    • T1590 Victim network information
    • T1591 Victim organisation information
  2. Initial access through edge devices

    Exploited known and zero-day flaws in internet-facing firewalls, VPNs and routers, including CVE-2022-42475 on an unpatched FortiGate. Traffic was routed through end-of-life Cisco and NETGEAR office routers infected with KV Botnet malware, so it appeared to come from ordinary home and small-office connections.

    • T1190 Exploit public-facing application
    • T1584.005 Compromise infrastructure: botnet

    Related course

    Cyber Defence Operations and Resilience CommandProfessional · 5 days
  3. Credential theft

    Used vssadmin to make a shadow copy of a domain controller, then ntdsutil to copy out the Active Directory database (NTDS.dit).

    • T1003.003 OS credential dumping: NTDS

    Related course

    APT Detection and Advanced Threat HuntingPractitioner · 4 days
  4. Living off the land

    Used Windows' own tools, such as wmic, netsh and PowerShell, so there was little malware to find. A netsh PortProxy change turned one internal server into a relay for their command traffic.

    • T1047 Windows Management Instrumentation
    • T1059.001 PowerShell
    • T1090.001 Internal proxy

    Related course

    APT Detection and Advanced Threat HuntingPractitioner · 4 days
  5. Lateral movement

    Moved between systems over Remote Desktop using stolen administrator accounts, which looks like normal admin work.

    • T1021.001 Remote Desktop Protocol
    • T1078 Valid accounts

    Related course

    Cyber Defence Operations and Resilience CommandProfessional · 5 days
  6. Pre-positioning for disruption

    Kept access for years, positioned to move from IT into operational technology and disrupt services if tensions escalate.

    Related course

    OT, ICS and SCADA Security OperationsPractitioner · 4 days

Case studies

What four major attacks teach defenders

AI-generated illustration: Idle gantry cranes over a container port at duskAI-generated illustration

2017 · attributed to the Russian military by the UK government

NotPetya

Disguised as a criminal attack, it was aimed mainly at Ukraine's financial, energy and government sectors, then spread to other businesses in Europe and Russia.

Lesson: Supplier update channels are an attack path, and recovery plans need testing.

UK government attribution, Feb 2018

Related courseSupply Chain and Third-Party Cyber Threat Management

AI-generated illustration: A telecoms mast beside an open fibre street cabinet at night in the rainAI-generated illustration

2024 to 2025 · attributed to China

Salt Typhoon

Compromised telecoms providers' backbone and edge routers worldwide to feed an espionage operation.

Lesson: Routers and network devices need the same monitoring as servers.

CISA AA25-239A

Related courseAPT Detection and Advanced Threat Hunting

Sample exercise

Sample exercise: spot living-off-the-land activity

Eight process events from a made-up network. Four look like routine admin. Four follow the Volt Typhoon pattern. Can you find them before the scan does?

process_eventsSample course exercise · synthetic data
  1. Time 09:12:03, host FS02, command robocopy.exe \\FS02\share D:\bak /MIR
  2. Time 09:14:41, host DC01, command vssadmin.exe create shadow /for=C:Flagged as suspicious: Shadow copy of a domain controller's system drive: one way to read NTDS.dit while it is in use.
  3. Time 09:15:02, host DC01, command ntdsutil.exe "ac i ntds" "ifm" "create full C:\Windows\Temp\pro" q qFlagged as suspicious: ntdsutil "ifm" is a second, self-contained way to copy out the Active Directory database. The same account tried both.
  4. Time 09:15:40, host WS114, command outlook.exe
  5. Time 09:18:06, host WS114, command teams.exe --system-initiated
  6. Time 09:21:55, host JUMP1, command mstsc.exe /v:HMI-GW01Flagged as suspicious: Remote Desktop from the jump host to an OT gateway, outside any change window.
  7. Time 09:26:30, host FS02, command wevtutil.exe qe Application /c:5
  8. Time 09:30:08, host HMI-GW01, command netsh.exe interface portproxy add v4tov4 listenport=9999 connectaddress=10.20.5.14 connectport=3389Flagged as suspicious: A port proxy on the OT gateway quietly forwards traffic to another host's Remote Desktop port (ATT&CK T1090.001).

Sample detection rules (Sigma)

title: NTDS.dit copied with ntdsutil IFM
logsource: { product: windows, category: process_creation }
detection:
  sel:
    Image|endswith: '\ntdsutil.exe'
    CommandLine|contains|all: ['ac i ntds', 'ifm']
  condition: sel
tags: [attack.credential_access, attack.t1003.003]
level: high
---
title: Shadow copy created on a domain controller
logsource: { product: windows, category: process_creation }
detection:
  sel:
    Image|endswith: '\vssadmin.exe'
    CommandLine|contains|all: ['create', 'shadow']
  condition: sel
tags: [attack.credential_access, attack.t1003.003]
level: high
---
title: Port proxy added through the registry
logsource: { product: windows, category: registry_set }
detection:
  sel:
    TargetObject|contains: '\Services\PortProxy\v4tov4\'
  condition: sel
tags: [attack.command_and_control, attack.t1090.001]
level: high

Wevtutil also appears in the advisory's tool list. Here it reads five application events, which on its own is routine. Deciding when a normal tool is suspicious is the skill being taught.

The programme

Cyber warfare courses by role

Pick a role to see a suggested three-course pathway, with total days and list price per person. Team pricing on request.

All 35 courses in this track

CourseLevelDaysList price per person, ex VAT
Cyber Warfare FoundationsFoundation2From £1,995
Hybrid Warfare and Kinetic-Cyber OperationsFoundation2From £2,195
Nation-State Threat Actor ProfilesFoundation2From £2,195
AI-Powered Social Engineering and CEO Fraud DefencePractitioner2From £2,495
Financial Cyber Warfare and Sanctions Evasion DefencePractitioner2From £2,495
SIGINT Awareness and Spectrum Warfare DefencePractitioner2From £2,495
State-Sponsored Ransomware: Attribution, Response and National PolicyPractitioner2From £2,495
Synthetic Identity, Biometric Fraud and Digital Trust DefencePractitioner2From £2,495

Showing 8 of 35 courses. Prices are per person, excluding VAT.

Booking

How a private cohort works

  1. Step 1: Enquire

    Tell us your team size and the topics you need.

  2. Step 2: Scoping call

    We agree the courses, format and any tailoring to your environment.

  3. Step 3: X-Ray skills check

    A free assessment shows where your team is starting from.

  4. Step 4: Dates confirmed

    Dates, group size and terms are confirmed in writing before you book.

  5. Step 5: Delivery

    Onsite at your premises anywhere in the world, or live online.

  6. Step 6: Certificate and debrief

    Each person gets a certificate anyone can check at xcademia.com/verify.

Three ways to deliver it

AI-generated illustration: An instructor at a whiteboard with a small team at laptops, seen from behindAI-generated illustration

Onsite, anywhere

We come to your premises, in any country.

AI-generated illustration: A laptop on a desk showing a live online class slide, with a notebook and coffeeAI-generated illustration

Live online

Instructor-led in real time, not pre-recorded, for teams in any time zone.

AI-generated illustration: Hands pointing at printed timelines and network diagrams spread across a tableAI-generated illustration

Crisis wargame

A facilitated exercise in which your team works through a simulated state-linked intrusion.

Public reporting

What state-linked attackers have been doing

Government-attributed campaigns. Not a live feed.

  • Salt Typhoon · attributed to China

    State-sponsored actors compromised telecoms providers' backbone and edge routers worldwide to support espionage.

    Sectors: Telecoms, government, transport, military · CISA, NSA, FBI and partners including the UK NCSC, AA25-239A (opens in a new tab)

  • APT28 (GRU unit 26165) · attributed to Russia

    Russian military intelligence targeted organisations involved in delivering foreign assistance to Ukraine.

    Sectors: Logistics, defence, maritime, air traffic management, IT services · CISA, NSA, FBI, UK NCSC and partners, AA25-141A (opens in a new tab)

  • TraderTraitor (Lazarus) · attributed to North Korea

    The FBI attributed the theft of about US$1.5 billion in virtual assets from the Bybit exchange to North Korea.

    Sectors: Finance, cryptocurrency · FBI (opens in a new tab)

  • Iranian cyber actors · attributed to Iran-based actors

    Used brute force and MFA push-bombing to get into accounts at critical infrastructure organisations. The advisory says they likely sold the access on to cybercriminals.

    Sectors: Healthcare, government, IT, engineering, energy · FBI, CISA, NSA and partners, AA24-290A (opens in a new tab)

  • APT31 · attributed to China

    The NCSC assessed that APT31 conducted reconnaissance against UK parliamentarians, and that a China state-affiliated actor highly likely compromised the Electoral Commission.

    Sectors: Government, democratic institutions · UK NCSC (opens in a new tab)

  • Volt Typhoon · attributed to China

    State-sponsored actors pre-positioned inside US critical infrastructure networks and maintained persistent access.

    Sectors: Communications, energy, transport, water · CISA, NSA, FBI and partners including the UK NCSC, AA24-038A (opens in a new tab)

Cyber warfare training: your questions

What is cyber warfare?

Cyber warfare is the use of digital attacks by states, or groups acting for them, to spy on, disrupt or weaken another country. It takes five main forms: espionage, sabotage, pre-positioning, influence and state-backed theft.

Who are these courses for?

Security teams in organisations that state-linked groups target: government and defence, critical national infrastructure, healthcare, finance, telecoms and their suppliers. Courses run from Foundation to Expert level.

Can you deliver at our site?

Yes. We deliver onsite at your premises anywhere in the world, and live online for teams in any time zone. If your site has security clearance or vetting requirements for visitors, tell us when you enquire and we will confirm whether we can meet them before you book.

How long are the courses and what do they cost?

Courses in this track run from 2 to 10 days depending on the subject. Each course page shows its length and list price per person, excluding VAT. Team pricing is available on request.

Do the courses make us compliant with NIS2 or the NCSC CAF?

Each course page lists the frameworks the course refers to, such as MITRE ATT&CK, NCSC CAF, NIS2 and NIST CSF 2.0. Training can help you evidence parts of these frameworks, but completing a course does not by itself make an organisation compliant.

Get a cohort quote

Tell us about your team. Someone from Xcademia will reply by email or phone.

Delivery