Free tools Windows power users keep installed
One-click scans. No signup required.
Pluralsight announced Volt Typhoon-focused cybersecurity training on August 22, 2024. Its original release described seven expert-led courses and six hands-on lab experiences; the broader APT Campaigns learning path currently listed by Pluralsight includes both Volt Typhoon and Sandworm material, along with practice in emulation and detection. It is a training resource for cybersecurity professionals—not a security control or a guarantee of protection.
What courses did Pluralsight release to help defend against Volt Typhoon?
Pluralsight’s August 22, 2024 announcement described an expert-led series intended to help learners understand, detect, and defend against Volt Typhoon and similar advanced persistent threat actors. The release counted seven courses and six hands-on lab experiences. Named lab examples involved emulating command and scripting interpreter activity, credential dumping, and indicator removal. Pluralsight’s announcement said the aim was to build tactics, skills, and procedures and help learners implement controls to reduce risk; that is the company’s stated goal, not an independently measured outcome.
The release framed the training as a response to concern about state-sponsored groups targeting critical infrastructure. It did not establish that completing the courses prevents an intrusion or protects an organization. No independent evaluation of the series’ effectiveness is documented in the available sources.
What does the Pluralsight Volt Typhoon learning path cover?
Pluralsight’s APT Campaigns catalog page, accessed September 30, 2026, showed a broader path of 13 courses, 10 labs, and 12 hours. Those figures describe the catalog snapshot on that date, not the original 2024 series alone, and the page may change.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsThe Volt Typhoon portion covers reconnaissance of networks and devices, credential dumping from domain controllers, indicator removal, detection, blocking, and preventative controls. The page lists both emulation and detection courses for command and scripting interpreters, credential dumping, and indicator removal, with associated hands-on labs, as well as a preventative-control course and a Volt Typhoon brief. The current path also contains Sandworm material, so it is broader than the Volt Typhoon-specific announcement.
#1 Best Overall
How does Volt Typhoon target critical infrastructure?
A joint advisory from CISA, the NSA, and the FBI assessed that PRC state-sponsored actors were seeking to pre-position on U.S. critical-infrastructure IT networks for possible disruptive or destructive attacks during a major crisis or conflict. The agencies said they had confirmed compromises of multiple organizations, primarily in communications, energy, transportation, and water and wastewater, including U.S. territories. See the joint advisory for the agencies’ assessment.
This high-level context explains why training on detection and defensive practice may be relevant to infrastructure defenders. It does not, by itself, establish an organization’s current exposure or provide technical indicators or remediation instructions. CISA’s Volt Typhoon fact sheet is described as guidance for critical-infrastructure leaders on defensive action and potential national-security impacts; the source information available here does not support attributing specific technical recommendations to it.
Who is the path for, and what access does it require?
Pluralsight lists foundational knowledge of networking, operating systems, cryptography, and common attack vectors, plus hands-on experience with basic security tools. That makes the path a better fit for learners with cybersecurity fundamentals than for complete beginners. Its practical exercises may also suit practitioners who want to rehearse attacker behavior and detection concepts in a training setting.
Rank #2
- Matt-laminated and greaseproof pages ensure glare-free reading and long life
- The outside covers are made from a new rubberized material for better Handling and Grip
- All the Tool Holder Identification Sections now include a full INCH section along with a METRIC section
- Updated and Improved Index Searching
The catalog page says access is limited to specified Pluralsight libraries and requires a license for the corresponding library. Check the live page and your organization’s subscription before planning to take the path; the access terms and catalog can change.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should organizations evaluate the training?
Consider whether the path matches the team’s existing skills and learning goals. It is threat-focused rather than a substitute for broad foundational instruction, and it combines course material with emulation and detection practice rather than offering only passive lessons. Organizations should also confirm library access and consider how they will keep training aligned with changing threat reporting and defensive guidance.
Pluralsight announced SecureReady on April 7, 2026, as a separate, broader enterprise security-skills offering combining on-demand content, labs, and expert-led seminars. The announcement says it maps training to frameworks including NIST NICE and DCWF and describes enterprise labs with adversary emulation. SecureReady is distinct from the APT Campaigns path; its announcement does not establish that it replaces or expands the Volt Typhoon courses. Pluralsight’s statements about either offering are vendor claims, not independent evaluations.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

