Network analysis exercise
Deliverable: A written analysis of a supplied packet capture identifying the protocols in use, the anomalous behaviour present, and the evidence supporting each conclusion.
Course
Networking and Linux foundations, then web application security, SOC monitoring and incident response — practised exclusively in isolated labs, with authorisation treated as a hard rule.
7 modules · 6 months
Deliverable: A written analysis of a supplied packet capture identifying the protocols in use, the anomalous behaviour present, and the evidence supporting each conclusion.
Deliverable: A findings report against a deliberately vulnerable lab application, with each issue rated by severity, reproduced step by step, and paired with a concrete remediation recommendation.
Deliverable: Triage decisions across a set of simulated alerts, with a written rationale for each true or false positive call and a tuning proposal for the noisiest rule.
Deliverable: A full investigation of a simulated incident from log evidence, producing a timeline, an impact assessment and an incident report suitable for management.
Every student gets placement assistance — that is what 100% placement assistance means. It is support for all, not a job for all. We do not promise a specific salary, a specific number of interviews, or placement at any named company, and you should be wary of anyone who does.
There is a version of this course that opens with Kali Linux and an exploitation demo in week one. It is more exciting and it produces people who can run tools without understanding what the tools are doing — which is both professionally limited and genuinely dangerous.
We spend the first two modules on networking and Linux. If you cannot read a packet capture and say what the exchange is doing, a scanner’s output is just a list of words. If you cannot reason about Linux permissions, privilege escalation is a magic trick rather than a consequence of a misconfiguration.
That grounding is also what interviewers probe. Candidates who can explain a TCP handshake and a permission model do well; candidates who can only name tools do not.
Every technique here is practised inside isolated lab environments we provide, against systems we control.
We treat scope and authorisation as a substantive subject: what written permission needs to specify, what rules of engagement mean, what happens when you find something outside the agreed scope, and what the Indian IT Act actually says. Security professionals get this wrong in ways that end careers, and it is not covered by a warning slide.
Offensive security gets the attention. SOC and defensive analysis is where most entry-level hiring in India actually happens, and it is where this course puts the weight in the second half — log analysis, alert triage, tuning and incident response.
The offensive modules exist because you cannot triage an alert well without understanding what the attack looks like from the other side. That is the argument for teaching both, and it is why the two halves are sequenced the way they are.
Questions
Everything taught here is practised exclusively in isolated lab environments we provide, against systems we control. Running any of these techniques against systems you do not own or have written authorisation to test is a criminal offence under the Indian IT Act. Authorisation and scope are covered as a dedicated module, not a disclaimer.
CEH is an EC-Council certification with its own exam and authorised training partners. This course covers overlapping technical ground and prepares you well for that subject matter, but it is not an accredited CEH training programme and we do not claim otherwise. Ask us directly about our current accreditation status before enrolling on that basis.
SOC analyst roles are far more numerous at entry level in India, and are the common way in. Penetration testing tends to be entered after a few years of defensive or systems experience. This course covers both sides deliberately, because understanding attack technique is what makes someone good at defence.
No — the first two modules build networking and Linux from scratch, and they are the longest in the course for good reason. Security work without networking fundamentals becomes tool operation without comprehension, which is exactly the profile that struggles in interviews and in the job.
Three details is all we need. A course advisor will call you back.
Front end, back end, databases and deployment taught as one connected system, ending with applications you have shipped to a public URL and can walk an interviewer through.
Python taught as a working tool rather than a syntax tour — you finish able to read unfamiliar code, automate real tasks, call APIs and write tests that catch your own mistakes.
Next step
Tell us what you want to learn and we will help you pick the right course, batch and mode.