Network VAPT of a five-host lab
Scope, scan, exploit and escalate across a segmented lab network, then deliver an executive summary and a technical report with CVSS-scored findings.
- Nmap
- Metasploit
- Reporting
Learn cyber security from the team that runs penetration tests and incident response for real clients. Six months, ten modules, four graded labs, one capstone audit, and placement support until you are hired.
Program snapshot
Admissions openFees from
₹49,000 incl. GST, full program
A cyber security course teaches you to protect networks, systems and data from attack: how attackers break in, how defenders detect them, and how organisations prove they are secure. This six-month program covers networking, Linux, ethical hacking, vulnerability assessment and penetration testing, SOC operations, cloud security and compliance, and ends with a supervised security audit of a real application.
Four kinds of people join this batch. If you recognise yourself in one of them, the syllabus was written with you in mind.
B.Tech, BCA, B.Sc and even non-IT graduates who want a cyber security career and need a structured path from zero to a first analyst role. No coding background is assumed; the first two modules build it.
Network engineers, system administrators and support engineers who already understand infrastructure and want to move into security roles that pay more and are harder to automate away.
Web and mobile developers who keep failing security reviews. The application security and VAPT modules teach you to find the bugs before the auditor does.
Anyone targeting CEH, CompTIA Security+ or an entry SOC certification who wants a practitioner to explain the concepts rather than a question bank to memorise.
We write outcomes as tasks a hiring manager would ask you to perform in your first month, because that is the standard your work is graded against.
Scope a target, enumerate services with Nmap, scan with Nessus and OpenVAS, validate findings manually, and write a report a CTO can act on, with severity, evidence and remediation.
Find and demonstrate SQL injection, XSS, broken authentication, IDOR and SSRF on lab applications with Burp Suite, then explain the code-level fix to a developer.
Read logs in Splunk and Wazuh, distinguish a real intrusion from noise, and escalate using a documented incident response playbook.
Configure firewalls, segment networks, apply CIS benchmarks and set up centralised logging so an attacker cannot move quietly.
Audit IAM, S3, security groups and CloudTrail, and fix the misconfigurations behind most real cloud breaches.
Map controls to ISO 27001, understand India's DPDP Act and CERT-In directions, and contribute to an audit instead of being afraid of one.
Ten modules over six months. Each one ends with a graded lab, and the last month is a supervised audit of a live application under the same rules our client engagements follow.
10
Modules
240
Guided hours
The CIA triad, threat actors and the kill chain, then the networking every security role depends on: TCP/IP, DNS, HTTP, TLS and how packets actually move.
Module outcome: You can read a Wireshark capture and explain what each layer is doing.
Command-line fluency on the two operating systems you will attack and defend, plus enough Bash and Python to automate the boring parts.
Module outcome: You can harden a fresh Ubuntu and Windows Server build and script a log parser in Python.
The attacker's workflow from footprinting to enumeration, run against deliberately vulnerable machines on our lab network.
Module outcome: You can take a target from an IP address to an initial foothold and document every step.
Where most real breaches happen. Every vulnerability is exploited by hand in Burp Suite and then fixed in code, because you will be asked to do both.
Module outcome: You can complete OWASP Juice Shop and write remediation guidance for each finding.
The engagement discipline we sell to clients: scoping, methodology, exploitation, privilege escalation and the report that gets remediation funded.
Module outcome: You deliver a full VAPT report on a multi-host lab environment, graded by our audit team.
The defender's side: collecting logs, writing detections and working alerts the way an L1 and L2 analyst does on shift.
Module outcome: You triage a simulated shift of 50 alerts and correctly escalate the three real intrusions.
What happens after the alert: containment, evidence handling, memory and disk analysis, and the post-incident report.
Module outcome: You reconstruct a ransomware incident timeline from disk and memory images.
Most of our clients run on AWS, so you learn to audit and fix the misconfigurations behind real cloud breaches.
Module outcome: You audit a deliberately misconfigured AWS account and remediate every critical finding.
The frameworks that decide budgets: ISO 27001, SOC 2, the DPDP Act and CERT-In directions, taught by the team that helps clients pass audits.
Module outcome: You produce a gap assessment against ISO 27001 Annex A for a sample organisation.
A supervised end-to-end audit of a live application with a written report, presented to our security lead, followed by mock interviews and portfolio review.
Module outcome: You leave with a graded audit report, a portfolio and a rehearsed interview story.
The same toolset our audit team uses on client engagements. Every tool is installed in your own lab in week one, and the licences you need are included in the fee.
Each project mirrors a deliverable we hand to paying clients. You keep the reports, the code and the write-ups, and we teach you how to talk about them in an interview.
Scope, scan, exploit and escalate across a segmented lab network, then deliver an executive summary and a technical report with CVSS-scored findings.
A full OWASP Top 10 assessment of a vulnerable e-commerce application, with proof-of-concept for every finding and code-level remediation for the developers.
Deploy Wazuh, ingest logs from Linux, Windows and AWS, write ten detection rules and work a simulated shift of alerts against a red-team exercise.
Audit an intentionally misconfigured AWS account: public buckets, over-privileged IAM, open security groups and missing logging. Remediate and document.
From disk and memory images, rebuild the attack timeline, identify the initial access vector and write the post-incident report a board would read.
Assess a sample organisation against Annex A controls, prioritise the gaps by risk and produce a remediation roadmap with owners and timelines.
Six steps. The first two cost nothing, and you can leave after either of them if the fit is wrong.
A 20-minute call with a security engineer, not a sales agent. We look at your background, tell you honestly whether this program or the shorter ethical hacking course fits better, and answer fee and batch questions.
A short online assessment on logic, basic networking and English comprehension. It does not reject anyone; it tells us which foundation sessions you need in week one.
We walk you through a personal virtual lab with Kali, a vulnerable Windows domain and an AWS free-tier account, so every later module runs on infrastructure you control.
Three live sessions per week with a practitioner, recorded for revision, plus graded labs due every fortnight. Doubt-clearing sessions run on Saturdays.
In month six you audit a live staging application under our rules of engagement and present findings to the security lead. This report becomes your portfolio centrepiece.
Resume and LinkedIn review, mock interviews with our engineers, referrals into our client network and priority consideration for the Cyber Warrior internship.
India has a well-documented shortage of security professionals, and entry roles are not going to freshers who only hold a certificate. They go to candidates who can show a report they wrote and a lab they broke into.
| Role | Typical salary (India) | What the job involves |
|---|---|---|
| Security Analyst (SOC L1/L2) | ₹3.5 to 7 LPA | Monitor SIEM alerts, triage incidents, escalate real intrusions and tune detections. The most common first role for graduates of this course. |
| Penetration Tester / VAPT Analyst | ₹4.5 to 10 LPA | Run authorised attacks on networks and applications and write the findings report. Our own audit team hires from this pool. |
| Cyber Security Engineer | ₹6 to 14 LPA | Design and maintain firewalls, endpoint protection, IAM and logging. Usually the second role after 18 months as an analyst. |
| Cloud Security Engineer | ₹7 to 16 LPA | Secure AWS or Azure environments, automate posture checks and respond to cloud incidents. Demand is outpacing supply fastest here. |
| GRC / Compliance Analyst | ₹4 to 9 LPA | Run ISO 27001 and SOC 2 programs, manage audits, vendor risk and policies. Suits people who prefer structure to exploitation. |
| Incident Responder / Forensics Analyst | ₹5 to 12 LPA | Contain and investigate breaches, preserve evidence and write post-incident reports. Often reached via SOC experience. |
Salary bands are indicative ranges for India in 2026 and vary by city, employer and prior experience. Placement support means active help until you are hired; it is not a guarantee of employment, and we will say so on the counselling call.
The syllabus is identical across formats. What changes is how much live contact you get and how quickly a stuck lab gets unstuck.
| Criterion | Online live | Classroom, Aligarh | Self-paced | Corporate batch |
|---|---|---|---|---|
| Live sessions per week | 3 sessions, evening or weekend | 3 sessions at our Aligarh centre | Recorded sessions only | Scheduled with your team |
| Lab environment | Personal cloud lab | Personal lab + centre network | Personal cloud lab | Your infrastructure or ours |
| Doubt clearing | Saturday clinic + chat | Daily, in person | Weekly office hours | Dedicated trainer |
| Graded labs and capstone | Yes, all ten | Yes, all ten | Yes, self-submitted | Tailored to your systems |
| Placement support | Included | Included | Add-on | Not applicable |
| Best for | Working professionals anywhere in India | Students in Aligarh and western UP | Self-starters on a budget | Security teams and IT departments |
| Typical duration | 6 months | 6 months | Up to 12 months access | 4 to 12 weeks |
Most learners choose online live. The classroom batch in Aligarh is popular with students from Aligarh Muslim University and nearby engineering colleges who want the in-person lab days. Corporate batches are scoped through our corporate training program.
One fee, everything included. No separate charges for lab access, tool licences, exam preparation or placement support.
Next batches
New batches start on the first Monday of every month. Weekday evening (7 to 9 pm IST) and weekend (10 am to 2 pm IST) options.
Pay in instalments
Pay in 3 or 6 monthly instalments at no extra cost. The first instalment confirms your seat.
Scholarships
Up to 25% merit scholarship based on the readiness check, plus a women-in-security scholarship for two seats per batch.
Cyber Security Course · full program
₹49,000incl. GST, full program
Fees shown are indicative for the current admission cycle and may be revised for future batches. Refunds follow our refund policy: full refund before the second live session, pro-rated until the end of module one.
We are not a training institute that added a security course. We are a security services company that opened its methodology to learners.
Your instructors run VAPT engagements and incident response for clients during the day. The examples in class are last month's findings, anonymised.
We hold the certification we teach you to audit against. The GRC module uses our own policies and risk register as the worked example.
Sixty percent of contact hours are hands-on. Every module ends in a graded lab and the program ends in a real audit, not a multiple-choice exam.
We have delivered 153+ projects for clients in finance, healthcare and manufacturing. Those relationships are where our referrals go.
The only practitioner-led cyber security course with a physical classroom in Aligarh, and live online batches that draw learners from every state.
Batches are capped at 25 so the instructor knows your lab work by name. Doubts are answered in chat within the day, not in a forum next week.
Every track in the Cyber Warrior programs catalogue shares the same faculty and project standard, so stacking two is common.
Offensive security, CEH-aligned, on real lab targets.
Explore programBlue-team training on SIEM, detection and incident response.
Explore programCloud Practitioner to Solutions Architect on live AWS accounts.
Explore programLinux, Docker, Kubernetes, CI/CD and Terraform in production.
Explore programPython programming from first script to automation and APIs.
Explore programPaid and certificate internships on live agency projects.
Explore programThe questions every applicant asks on the first counselling call.
Book a 20-minute counselling call with a security engineer. We will tell you honestly whether this course, the ethical hacking course or the SOC analyst course fits your goal, and what the next batch looks like.
Prefer WhatsApp or email? Contact the admissions team and we reply in under 3 minutes during working hours.