SamyakComputer ClassesShakarpur

Course

Ethical Hacking

The offensive counterpart to our cyber security course — methodology, exploitation and reporting, practised exclusively in isolated labs with written authorisation treated as a hard rule.

  • Duration: 4 months
  • Classroom · Online live
  • Level: intermediate

What you will be able to do

Who this course is for

Syllabus

8 modules · 4 months

  1. Module 1. Authorisation, scope and the law

    • Indian IT Act provisions relevant to security testing
    • What written authorisation must specify to be meaningful
    • Rules of engagement, scope boundaries and time windows
    • What to do when you find something outside the agreed scope
    • Responsible disclosure and why it matters commercially
  2. Module 2. Methodology

    • Why methodology beats tool knowledge
    • The phases of an engagement and what each produces
    • Note-taking and evidence capture during testing
    • Common frameworks and how practitioners actually use them
  3. Module 3. Reconnaissance and enumeration

    • Passive information gathering and its limits
    • DNS, WHOIS and public exposure
    • Port scanning with Nmap and reading the output properly
    • Service and version enumeration
    • Building an attack surface picture from findings
  4. Module 4. Vulnerability assessment

    • Scanning tools and their false positive rate
    • Verifying a finding manually before reporting it
    • CVSS scoring and its limitations
    • Prioritising by exploitability and business impact
  5. Module 5. Web application testing

    • Intercepting and modifying requests with Burp Suite
    • Injection flaws demonstrated in a vulnerable lab application
    • Broken authentication and session handling
    • Broken access control and privilege bypass
    • Cross-site scripting and request forgery
    • File upload and deserialisation issues
  6. Module 6. Exploitation in an isolated lab

    • Selecting and configuring an exploit
    • Payloads, listeners and what a shell actually is
    • Why exploitation happens only in an isolated lab
    • Post-exploitation enumeration
    • Privilege escalation on Linux and Windows hosts
    • Cleaning up and restoring a lab host
  7. Module 7. Passwords and network attacks

    • Hashing, salting and how cracking actually works
    • Offline cracking with Hashcat
    • Traffic capture and analysis
    • Man-in-the-middle concepts in a controlled environment
  8. Module 8. Reporting

    • Structuring a penetration test report
    • Writing an executive summary a non-technical reader will act on
    • Reproduction steps a developer can follow exactly
    • Recommending a fix rather than naming the flaw
    • Retesting and closing findings

Tools and technologies you will use

Projects you will build

Where this course can take you

  • Penetration Tester
  • Security Analyst
  • Vulnerability Assessment Analyst
  • Application Security Engineer
  • Security Consultant

Duration, modes and fees

Duration
4 months
Delivery modes
Classroom · Online live
Fees
Share your details for the current fee
Fees vary by batch and delivery mode. Share your details and an advisor will confirm the current fee.

Placement assistance

Every student gets placement assistance — that is what 100% placement assistance means. It is support for all, not a job for all. We do not promise a specific salary, a specific number of interviews, or placement at any named company, and you should be wary of anyone who does.

What is included

  • A place in the monthly placement drive, held every third Saturday
  • The readiness programme every second Saturday — mock interviews and preparation
  • CV review against the specific roles you are targeting
  • Portfolio review, so your project work is presented the way a reviewer will read it
  • Access to the vacancy pool employers send directly to the Samyak network
  • Guidance on which roles realistically fit your background and which do not
  • A place in the next drive, with coaching, if you are not selected in this one

What is not included

  • Any guarantee of a job, an interview, or a particular salary
  • Placement at a named or partner company
  • Applying to jobs on your behalf
  • Support before you have completed the course and its project work
  • Visa, relocation or overseas placement assistance

Methodology, not a tool tour

There is a version of this course that is a sequence of tool demonstrations. Run Nmap, run Nikto, run Metasploit, feel formidable.

It produces people who can operate tools and cannot conduct an engagement. Given a scope document and two weeks, they do not know where to start, what to record, or how to decide whether a scanner result is real.

So methodology comes second, immediately after authorisation, and everything after it follows a phase structure. Tools are introduced as instruments serving a step, which is also how they are used in practice.

Authorisation is module one

Not a warning slide. A module, with the Indian IT Act, what written permission must specify, what rules of engagement mean, and what you do when you find something outside the agreed scope.

Security professionals end careers by getting this wrong — usually not through malice but through enthusiasm, testing something adjacent to the target because it was interesting. Learning where the boundary sits, and that it is a legal boundary rather than a professional courtesy, is the first thing that separates a practitioner from a hobbyist.

Verify before you report

Scanners produce false positives at a rate that surprises beginners. A report that forwards them unverified damages your credibility with the client and wastes developer time on findings that do not exist.

One of the four projects is entirely about triage — taking scan output and sorting it into confirmed, false positive and needs-investigation, with manual evidence for each confirmation. It is less exciting than exploitation and it is closer to the actual job.

The report is the product

Clients do not buy access to your shell. They buy a document that tells them what is wrong, how bad it is, and what to do about it.

Reporting is where junior testers are consistently weakest, and it is the reason the final module and the final project are both about writing. An executive summary a manager will act on, reproduction steps a developer can follow exactly, and a remediation recommendation rather than a restatement of the flaw.

Honest positioning

This course is a strong second step, not an easy first job.

Penetration testing roles in India are far fewer at entry level than defensive ones, and most people arrive at them after time in a SOC, in systems administration or in development. If security is your goal and you are starting out, our cyber security course is the more realistic route in, and this one compounds on top of it.

Questions

Ethical Hacking — frequently asked questions

How is this different from your cyber security course?

The cyber security course is six months and defence-leaning — networking, Linux, SOC operations, alert triage and incident response, with offensive technique covered so you can recognise attacks. This is four months on the offensive side in depth, with methodology and reporting as substantial modules. Many people take the cyber security course first.

Is everything taught here legal to practise?

Everything is practised exclusively in isolated lab environments we provide, against systems we control. Running any of these techniques against systems you do not own or have written authorisation to test is a criminal offence under the Indian IT Act. Authorisation and scope is the first module, not a disclaimer slide.

Do you provide CEH certification?

No. CEH is an EC-Council certification with its own exam and authorised training partners, and we do not claim to be one. This course covers substantially overlapping technical ground and prepares you well for that subject matter, but it is not accredited CEH training. Ask us directly about our current accreditation status before enrolling on that basis.

Can I get a penetration testing job straight after this course?

Sometimes, but it is not the common path in India. Most penetration testers enter after a few years in defensive security, systems administration or development. Junior application security and vulnerability assessment roles are the more realistic first step, and this course targets those honestly.

Why is reporting a whole module?

Because it is the deliverable. A finding nobody acts on has produced no security benefit, and reports are where most junior testers are weakest. Clients pay for a document that a developer can follow and a manager can prioritise from, not for a tool output pasted into a template.

Enquire about Ethical Hacking

Three details is all we need. A course advisor will call you back.

By submitting, you agree to be contacted about courses and accept our privacy policy.

Next step

Talk to a course advisor

Tell us what you want to learn and we will help you pick the right course, batch and mode.

Request a callback

Three details is all we need. A course advisor will call you back.

By submitting, you agree to be contacted about courses and accept our privacy policy.