
Advanced Security Practice (SecurityX / CASP+ aligned)
StationX Advanced
Advanced, labs-led security practice aligned to the SecurityX (CASP+) domains — architecture, enterprise risk and advanced operations. Hands-on practice, not exam preparation: we have no SecurityX course, so this path proves skills rather than coaching you through CAS-005.
The path
Step 1 — Security architecture at scale
Design controls across a complex enterprise estate.
22 labs
Practise
- Labs+CASP+ / SecurityX - Cybersecurity Advanced Security Practitioner — 11 labs 🔒 StationX Labs+
- Can You Analyze Network Evidence by Using Wireshark and Autopsy? [Advanced]
- Can You Configure Trusts, Remote Connections and Network Data Analysis? [Expert]
- Can You Secure Windows Server with Security Templates, Domain Trusts, and Nmap Scanning? [Advanced]
- Can You Unify Windows and Linux by Using the Power of Remote Desktop, VNC, and SSH? [Advanced]
- Evaluate SSH Remote Management Security [Guided]
- Evaluate Security Policy, Guides and Templates [Guided]
- Implement Domain Trusts [Guided]
- Implement Network Security Solutions for Data Flow [Guided]
- Implement Remote Assistance [Guided]
- Perform Forensic Analysis on a Suspect's System [Guided]
- Use Security Assessment Tools [Guided]
- Labs+Security Architect Introduction — 11 labs 🔒 StationX Labs+
- Can You Establish Secure Communications by Using SSH and Security Templates? [Advanced]
- Can You Manage Code Security? [Advanced]
- Can You Perform Inside Exploitation, Remote Commands, and Gain Remote Access? [Advanced]
- Can You Use Security Templates, Remote Access Exploits, and PE Analysis to Manage a Windows Server Configuration? [Expert]
- Debug Code [Guided]
- Detect Windows Network Vulnerabilities [Guided]
- Manage a Server by Using a Security Template [Guided]
- Perform Application Source Code Verification to Install New Software [Guided]
- Use Metasploit and Netcat to Gain Remote Access to a Windows System [Guided]
- Use Metasploit to Test Network Security [Guided]
- Use SSH to Configure Connections Between Systems [Guided]
Free resources
Step 2 — Enterprise risk and governance
Make defensible risk decisions and evidence them.
1 course · 22 labs
Learn
- CourseISACA - Certified Risk and Information Systems Control- CRISC 🔒 StationX Unlimited
5 sections · 43 lectures
- Introduction 7
- Domain 1 – Risk Management 18
- Domain 2 – IT Risk Assessment 8
- Domain 3 – Risk Response and Mitigation 10
- Domain 4 – Risk and Control Monitoring and Reporting 0
Practise
- LabsCritical Security Controls — 22 labs 🔒 StationX Unlimited
- Auditing Service Accounts and Setting Up Automated Log Collection
- BitLocker Setup
- CIRP Creation and Disaster
- Centralized Monitoring
- Comparing Controls
- Creation of Standard Operating Procedures for Recovery
- Data Backup to Prep for Recovery
- Data Downloads and Validation
- Force Point: DLP Email Overview
- Force Point: DLP Network Overview
- Identifying Key Assets
- Leveraging Internal Intelligence Resources
- Log Correlation & Analysis to Identify Potential IOC
- Monitoring and Verifying Management Systems
- Open and Close Ports on Windows 7
- Phishing (2026)
- Phishing
- Post Incident Service Restoration
- Ransomware
- Recover from SQL Injection Attack
- Sensitive Information Identification
- Vulnerability Identification and Remediation
Step 3 — Advanced operations
Lead detection, response and assurance activity.
53 labs
Practise
- LabsCyber Security Professional — 35 labs 🔒 StationX Unlimited
- Analyze DoomJuice Infection to Identify Attack Vector and Payload
- Analyze SQL Injection Attack
- Analyze Structured Exception Handler Buffer Overflow Exploit
- Analyze and Update a Company BCP/BIA/DRP/CIRP
- Applying Filters to TCPDump and Wireshark
- Baseline Systems in Accordance with Policy Documentation
- Conduct Baseline Comparison for Indicators of Compromise
- Creating a Baseline Using Autopsy
- Creating a List of Installed Programs, Services and User Accounts from a WIN2K12 Server
- Creating a Secondary Baseline and Conducting Comparison
- Creation of Standard Operating Procedures for Recovery
- Data Backup to Prep for Recovery
- Firewall Setup and Configuration
- Identify Access to a LINUX Firewall Through SYSLOG Service
- Identify Whether High-Risk Systems Were Affected
- Identifying System Vulnerabilities with OpenVAS
- Implementing Least-Privilege on Windows (2026)
- Implementing Least-Privilege on Windows
- Intro To Linux - Users and Groups
- Log Correlation & Analysis to Identify Potential IOC
- Manual Vulnerability Assessment
- Manually Analyze Malicious PDF Documents
- Manually Analyze Malicious PDF Documents 2
- Microsoft Baseline Security Analyzer
- Monitoring Network Traffic for Potential IOA/IOC
- Monitoring and Verifying Management Systems
- Network Segmentation (FW/DMZ/WAN/LAN)
- Parse Files Out of Network Traffic
- Patch Installation and Validation Testing
- Performing Incident Response in a Windows Environment
- Scanning and Enumeration
- Scanning and Mapping Networks
- Securing Linux for System Administrators
- Use pfTop to Analyze Network Traffic
- Vulnerability Identification and Remediation
- LabsThreat Intelligence & Defense — 18 labs 🔒 StationX Unlimited
- Analyze Various Data Sources to Confirm Suspected Infection
- Assessing Vulnerabilities Post Addressal
- BitCoin Mining Web Application on Corporate Network
- Check for Indicators of Other Attack Activity (Debug PE File)
- Cyber Security Evaluation Tool (CSET)
- Entering Information into a CMDB
- Event Logs with Autopsy
- Internet History
- MITRE - Defend
- Nexpose: Red Team Exploitation
- Overview of Kibana
- Performing an Initial Attack Analysis
- Preparing Target Media
- Recover from Illegal Bitcoin Mining Incident
- Recover from Web-Based Flashpack Incident
- Report Writing for Presentation to Management
- Respond to and Validate Alerts from Antivirus Software
- WMI Event Persistence