Full black-box network pentest
Given only a scope, compromise a five-host lab from recon to root and deliver a client-grade report.
- Nmap
- Metasploit
- Reporting
Learn offensive security the way it is actually practised: scope a target, break in, escalate, and write the report that gets the hole fixed. Four months, CEH-aligned, every technique run against live lab machines you are authorised to attack.
Program snapshot
Admissions openFees from
₹35,000 incl. GST, full program
An ethical hacking course teaches you to attack systems the way a malicious hacker would, but with written permission and a report at the end. You learn reconnaissance, scanning, exploitation, web application attacks, privilege escalation and post-exploitation, and you practise every step on deliberately vulnerable machines in a controlled lab. The goal is to find weaknesses before criminals do.
This is a hands-keyboard course. It suits people who want to break things to understand them, not memorise definitions.
Students and graduates who want to become penetration testers or bug bounty hunters and need a structured path with real targets, not scattered YouTube tutorials.
SOC and blue-team analysts who defend systems and want to think like the attacker to write better detections.
Web and mobile developers who want to find the OWASP bugs in their code before an auditor or attacker does.
Anyone preparing for CEH, eJPT or OSCP who wants a practitioner to run the labs alongside the theory.
Outcomes are written as things you will demonstrate on a live lab, because that is how the modules are graded.
Footprint a target with OSINT, Shodan and DNS enumeration, then map the attack surface with Nmap and service fingerprinting.
Use Metasploit and manual exploits to get an initial foothold on Windows and Linux targets.
Find and exploit SQL injection, XSS, IDOR, SSRF and authentication flaws in Burp Suite without relying on automated scanners alone.
Enumerate misconfigurations, kernel exploits and credential reuse to move from a low-privilege shell to full control.
Tunnel through a compromised host to reach internal networks the way a real intrusion spreads.
Score findings with CVSS and produce an executive summary and technical report that a client can act on.
Eight modules over four months, CEH-aligned and lab-heavy. Every module ends with machines you must compromise and document.
8
Modules
160
Guided hours
Hacking phases, attacker types, rules of engagement and the legal boundaries that separate ethical hacking from a crime.
Module outcome: You can define a legal scope and set up a working attack lab.
Gathering everything about a target before touching it: passive OSINT then active enumeration.
Module outcome: You produce a full recon report on an authorised target domain.
Turning a list of hosts into a map of services, versions and likely vulnerabilities.
Module outcome: You enumerate a lab network and shortlist exploitable services.
Gaining the first shell with Metasploit and manual exploits on Windows and Linux targets.
Module outcome: You get an initial shell on three lab machines and record how.
The attack surface behind most real breaches, exploited by hand in Burp Suite.
Module outcome: You root OWASP Juice Shop and DVWA and document each exploit.
From a low shell to full control, and what to do once you own the box.
Module outcome: You escalate to root and administrator on graded targets.
Moving deeper into a network and attacking the layers below the application.
Module outcome: You pivot from a DMZ host into an internal subnet.
A full capstone engagement plus report, and structured preparation for CEH and eJPT exams.
Module outcome: You deliver a graded capstone pentest report and CTF write-up.
Industry-standard tools installed in your own lab in week one. Licences you need for the labs are included in the fee.
You keep every write-up. These are the deliverables that get a junior pentester hired.
Given only a scope, compromise a five-host lab from recon to root and deliver a client-grade report.
Exploit the full OWASP Top 10 on a vulnerable app and write proof-of-concept and remediation for each bug.
A multi-machine CTF where you chain vulnerabilities, pivot and escalate to capture every flag, then publish a write-up.
Audit a WPA2 network, capture and crack a handshake in the lab and document the fix.
Find a valid vulnerability in a practice target and write a submission that would be accepted by a real program.
From a foothold, enumerate and abuse an AD misconfiguration to reach domain admin and map the path.
Six steps from enquiry to certificate. The first two are free.
A 20-minute call with a penetration tester who tells you honestly whether this course or the broader cyber security course fits your goal.
A short check on logic and basic networking that decides which foundation sessions you need, not whether you get in.
In week one we set up Kali and a network of vulnerable machines you are authorised to attack for the whole program.
Live sessions plus graded labs every fortnight. You compromise machines and write them up the way a real engagement requires.
A supervised multi-host CTF and report presented to a review panel, which becomes your portfolio centrepiece.
CEH and eJPT exam preparation, resume and portfolio review, mock interviews and referrals into pentest roles.
Offensive security roles are among the hardest to automate and the fastest growing in India. They hire on demonstrated skill, which is why the capstone matters more than the certificate.
| Role | Typical salary (India) | What the job involves |
|---|---|---|
| Penetration Tester | ₹4.5 to 11 LPA | Run authorised attacks on networks, apps and cloud and write the findings report. The direct target role for this course. |
| VAPT Analyst | ₹4 to 9 LPA | Perform vulnerability assessments and validation for a security services firm or in-house team. |
| Bug Bounty Hunter | Variable / bounty | Find and responsibly disclose vulnerabilities on public programs; some do it full time, most alongside a job. |
| Red Team Operator | ₹8 to 18 LPA | Simulate real adversaries end to end. Usually reached after a few years as a pentester. |
| Application Security Engineer | ₹6 to 15 LPA | Embed in development teams to find and fix bugs before release. |
| Security Researcher | ₹6 to 16 LPA | Analyse vulnerabilities, write exploits and publish findings for a security company. |
Salary bands are indicative for India in 2026 and vary by skill, city and employer. Bug bounty income is highly variable. Placement support is active help until you are hired, not a guarantee.
Same labs and syllabus in every format. Live contact and speed of help are what differ.
| Criterion | Online live | Classroom, Aligarh | Self-paced | Corporate batch |
|---|---|---|---|---|
| Live sessions per week | 3, evening or weekend | 3 at our Aligarh centre | Recorded only | Scheduled with your team |
| Attack lab | Personal cloud lab | Lab + centre network | Personal cloud lab | Your scope or ours |
| Doubt clearing | Saturday clinic + chat | Daily, in person | Weekly office hours | Dedicated trainer |
| Graded labs & capstone | Yes | Yes | Self-submitted | Tailored |
| CEH / eJPT prep | Included | Included | Included | Optional |
| Best for | Anyone in India | Aligarh students | Budget self-starters | Security teams |
| Typical duration | 4 months | 4 months | Up to 8 months access | 2 to 6 weeks |
Corporate red-team and awareness batches are scoped through corporate training.
One fee, everything included: lab access, tool licences, CEH preparation and placement support.
Next batches
New batches on the first Monday of every month, evening and weekend options.
Pay in instalments
Pay in 3 monthly instalments at no extra cost; the first confirms your seat.
Scholarships
Up to 25% merit scholarship based on the aptitude check.
Ethical Hacking Course · full program
₹35,000incl. GST, full program
Fees are indicative for the current cycle. Refunds follow our refund policy: full refund before the second live session.
Your instructors break into systems for a living. The techniques you learn are the ones they used on last month's VAPT engagement, anonymised.
Not academics. The people grading your shells run real authorised attacks for clients.
You attack a full lab network under a written scope, learning the legal discipline alongside the technical skill.
Employers pay for the report, not the shell. You practise writing findings in every module.
Structured preparation that maps the course to the certifications employers recognise.
In-person lab days in Aligarh and live online batches for the rest of the country.
Capped at 25, with an ongoing CTF community so your practice does not stop at graduation.
Every track in the Cyber Warrior programs catalogue shares the same faculty and project standard, so stacking two is common.
Job-ready security training with placement support.
Explore programBlue-team training on SIEM, detection and incident response.
Explore programPython programming from first script to automation and APIs.
Explore programCloud Practitioner to Solutions Architect on live AWS accounts.
Explore programHTML, CSS, JavaScript, React and PHP on real client briefs.
Explore programPaid and certificate internships on live agency projects.
Explore programThe questions every applicant asks on the first counselling call.
Book a call with a working penetration tester. We will tell you whether the ethical hacking course or the full cyber security course fits your goal, and when the next lab batch starts.
Prefer WhatsApp or email? Contact the admissions team and we reply in under 3 minutes during working hours.