• Waitlist

RT-C2E: Advanced Red Team C2 Infrastructure Engineering

  • Course
  • 66 Lessons
  • 365-day access
  • Includes 1 private space

RT-C2E is a deeply technical, hands-on red teaming course that gives you the practical skills, clear guidance, and ready-to-use tooling to build a production-ready, three-layer command-and-control (C2) infrastructure from scratch—ready to support professional red teaming engagements.

You’ll learn how to design an end-to-end C2 infrastructure around real operator workflows and the requirements that matter in practice: reliability, security, and cost control. You’ll start by defining the architecture and building a hardened, on-premises virtualization foundation. From there, you will implement the core infrastructure—including firewalls, secure remote access, and a centralized gateway—before deploying the vital engagement systems operators depend on, such as operator clients and teamservers running various C2 frameworks. From there, you’ll build the external cloud layer with multiple redirector options and a secure private overlay that links cloud and on-prem components, while keeping sensitive internal systems protected and limiting exposure of critical infrastructure.

As you progress through the modules, you’ll add the operational capabilities that make a C2 environment effective and sustainable: centralized logging, internal file sharing, and deployment automation through an integrated dashboard to reduce manual effort and improve efficiency. Every stage is backed by step-by-step implementation guidance, custom configuration files, templates, scripts, and automation components tailored for easy adaptation.

By the end of RT-C2E, you’ll have a robust, secure, and automated C2 infrastructure that is cost-effective, auditable, and reliable. With clear separation of engagement data, strong access controls, and comprehensive logging for accountability, you and your team can focus on executing red teaming engagements efficiently and professionally.

Includes 1 private space

  • RT-C2E-Support

Team Takeaways

Operational C2 Infrastructure

By the end of this hands-on course, you’ll have a secure, robust, flexible, and cost-efficient C2 infrastructure that’s fully operational and ready for real-world red teaming engagements.

Practical step-by-step Guidance

To get you there, we provide the tools and knowledge to either build the full environment from scratch or use individual modules to improve an existing setup—each lesson stands on its own while still fitting into the broader design. You’ll follow clear, step-by-step guidance—from designing and building the core platform to adding operator-focused capabilities like centralized logging and deployment automation.

Access to Custom C2 Control Dashboard

With access to the course, you’ll receive an attack-infrastructure control dashboard that runs on Proxmox VE. It enables your red team to deploy engagement-ready infrastructure in minutes and monitor its health. In addition, you’ll get a large set of custom configuration files, scripts and templates to support the workflows throughout this course.

The dashboard supports automated provisioning of teamservers, log servers, and VPS redirectors, including installation and configuration of the selected:

  • C2 framework (currently supported: Cobalt Strike)

  • Logging stack (currently supported: Grafana Loki with Alloy)

  • Redirector software (currently supported: RedWarden)

Deployed components are automatically connected to each other and integrated into the permanent C2 infrastructure you build throughout the course.

What You’ll Learn

By the end of this course, you will be able to:

  • Design a C2 infrastructure around real operator needs

  • Build a resilient, production-ready three-layer C2 environment

  • Set up a hardened virtualization foundation

  • Implement secure remote access and a centralized gateway

  • Deploy key engagement systems, including operator clients and teamservers

  • Set up C2 frameworks such as Cobalt Strike and Mythic

  • Implement centralized logging and an analysis dashboard

  • Build the external cloud layer and deploy multiple redirector options

  • Create a secure private overlay between cloud and on-prem components

  • Implement operator utilities, such as internal file sharing, to streamline daily tasks

  • Use an automation dashboard to deploy core systems (on-prem and cloud) and monitor environment health

Course Syllabus

The course is organized into six modules. Each module has clear outcomes, concise theory, and—most importantly—hands-on build-along instructions and assignments:


Module 1

Design the C2 architecture using a workflow-first approach and produce a three-layer blueprint (edge, on-prem core, cloud services) that balances robustness, scalability, and cost.


Module 2

Build the core platform using virtualization (with bare-metal installation instructions), then add secure remote access, network segmentation, and a fine-grained remote access gateway with auditing.


Module 3

Deploy the core on-prem components by setting up the Management Server, Operators Clients, and Teamservers while separating admin and operator roles.


Module 4

Build the external-facing layer by deploying cloud VPS redirectors, configuring domains, and securely connecting redirectors to on-prem teamservers via a private overlay network.


Module 5

Add operational services by deploying centralized logging and shared file storage to support auditing, analysis, and collaboration within the environment.


Module 6

Bring everything together by implementing the automation dashboard provided in this course and integrating it into your C2 infrastructure. You’ll use it to enable repeatable, fast deployment of engagement-ready attack infrastructure, run infrastructure health checks, and manage operator accounts.


Bonus Content

Integrate Quality of Life (QoL) enhancements to your environment like C2 notifications.

Module 0 - Course Introduction

What is this course about?
What you will learn
Requirements
How the rest of this course is structured

Module 1 - C2 Infrastructure Design

Module introduction
1.1 Hosting the infrastructure
1.2 Operator workflow
1.3 Design principles
1.4 Infrastructure blue print
Assignment

Module 2 - Build the Core Platform

Module introduction
2.1 Virtualization platform
2.2 Debian VM template
2.3 OPNsense platform
2.4 Management server (P1)
2.5 Remote access VPN
2.6 Network firewall
2.7 Remote access gateway
2.8 Fine-grained access control
Assignment

Module 3 - On-prem essentials

Module introduction
mgmt-server-package.zip
3.1 Management server (P2)
3.2 Operator Clients
3.3 Client deployment
3.4 Teamservers
3.5 Cobalt Strike
3.6 Cobalt Strike connectivity
3.7 Mythic
3.8 Mythic logging
3.9 Mythic connectivity
Assignment

Module 4 - Cloud essentials & Connectivity

Module Introduction
4.1 Redirectors
4.2 Providers & registrars
4.3 VPS deployment
4.4 Restricted VPS access
4.5 RedWarden
4.6 HAProxy
4.7 Nebula
4.8 Lighthouse
4.9 Listener
4.10 Forward C2 traffic
Assignment

Module 5 - Expand the Infrastructure

Module Introduction
5.1 Centralized logging
5.2 Grafana Loki
5.3 Grafana Alloy C2 logs
5.4 Grafana Alloy CLI logs
5.5 Grafana data analytics
5.6 Edge collectors
5.7 Internal file sharing
5.8 Secure data storage
5.9 Operational attack infrastructure
Assignment

Module 6 - C2 Automation

Module Introduction
dashboard-package.zip
6.1 Management dashboard
6.2 Automated deployment
6.3 Deployment flow
6.4 User management
6.5 Deployment cleanup
6.6 Health monitor
Assignment

Bonus Content

B.1 Notifications via aggressor script

Closing Remarks

Course Wrap-Up

Things You Need To Know

What are the prerequisites for this course?

To get the most out of this course, you should have the following prerequisites.

Technical requirements

  • Hosting Platform: Ideally, you have a dedicated bare-metal system to install a fresh virtualization platform on (which we cover as the first step in the course) or access to an existing enterprise virtualization environment (preferably Proxmox VE). For learning and lab demonstration purposes, a desktop hypervisor (such as VMware Workstation) is sufficient.

  • Workstation: A laptop or desktop computer to connect to your environment and follow along with the training materials.

  • Internet Access: A reliable internet connection to download operating system images, pull container images, retrieve package updates, and access course resources.

  • Domain & DNS Control: The ability to register a new domain name or fully manage DNS records (A and AAAA) for an existing domain.

  • Cloud Infrastructure Access: The ability to provision and administer Virtual Private Servers (VPS) with a public cloud provider (preferably DigitalOcean).

Recommended knowledge

  • Red teaming fundamentals: Basic familiarity with red-teaming and the associated terminology.

  • Systems and networking: Working knowledge of Linux/Windows administration, networking fundamentals, and basic scripting.

Does the course include any paid software licenses?

No. This course does not include licenses for paid third-party software such as Cobalt Strike.

Most of the software used in the course is open source. The course does include setup and installation guidance for commercial products—most notably Cobalt Strike—because they are widely used in professional environments and make useful examples. However, these products are never required to complete the training: you can use your own preferred commercial tooling or an open-source alternative.

If I need support, who should I contact?

If you have questions about the course content or need help with any part of the course, you can reach us via:

  • Community Spaces: Practitioners enrolled in our courses receive exclusive access to our private Community Spaces for active technical support.

  • Email: support@westerntactics.com

Cyber Security Solutions for Organisations

Equip your teams with the world-class cybersecurity training and capabilities they need to proactively defend your organisation against emerging threats.