Full lab engagement
Deliverable: A structured test of a supplied lab network from reconnaissance to privilege escalation, with contemporaneous notes and evidence captured throughout.
Course
The offensive counterpart to our cyber security course — methodology, exploitation and reporting, practised exclusively in isolated labs with written authorisation treated as a hard rule.
8 modules · 4 months
Deliverable: A structured test of a supplied lab network from reconnaissance to privilege escalation, with contemporaneous notes and evidence captured throughout.
Deliverable: A findings report against a deliberately vulnerable application, each issue verified manually, rated by severity, reproduced step by step and paired with a specific remediation.
Deliverable: A vulnerability scan output triaged into confirmed, false positive and needs-investigation, with the manual verification evidence for each confirmed finding.
Deliverable: A complete penetration test report with executive summary, methodology, findings, evidence and remediation plan, written for a reader who will not read the appendix.
Every student gets placement assistance — that is what 100% placement assistance means. It is support for all, not a job for all. We do not promise a specific salary, a specific number of interviews, or placement at any named company, and you should be wary of anyone who does.
There is a version of this course that is a sequence of tool demonstrations. Run Nmap, run Nikto, run Metasploit, feel formidable.
It produces people who can operate tools and cannot conduct an engagement. Given a scope document and two weeks, they do not know where to start, what to record, or how to decide whether a scanner result is real.
So methodology comes second, immediately after authorisation, and everything after it follows a phase structure. Tools are introduced as instruments serving a step, which is also how they are used in practice.
Not a warning slide. A module, with the Indian IT Act, what written permission must specify, what rules of engagement mean, and what you do when you find something outside the agreed scope.
Security professionals end careers by getting this wrong — usually not through malice but through enthusiasm, testing something adjacent to the target because it was interesting. Learning where the boundary sits, and that it is a legal boundary rather than a professional courtesy, is the first thing that separates a practitioner from a hobbyist.
Scanners produce false positives at a rate that surprises beginners. A report that forwards them unverified damages your credibility with the client and wastes developer time on findings that do not exist.
One of the four projects is entirely about triage — taking scan output and sorting it into confirmed, false positive and needs-investigation, with manual evidence for each confirmation. It is less exciting than exploitation and it is closer to the actual job.
Clients do not buy access to your shell. They buy a document that tells them what is wrong, how bad it is, and what to do about it.
Reporting is where junior testers are consistently weakest, and it is the reason the final module and the final project are both about writing. An executive summary a manager will act on, reproduction steps a developer can follow exactly, and a remediation recommendation rather than a restatement of the flaw.
This course is a strong second step, not an easy first job.
Penetration testing roles in India are far fewer at entry level than defensive ones, and most people arrive at them after time in a SOC, in systems administration or in development. If security is your goal and you are starting out, our cyber security course is the more realistic route in, and this one compounds on top of it.
Questions
The cyber security course is six months and defence-leaning — networking, Linux, SOC operations, alert triage and incident response, with offensive technique covered so you can recognise attacks. This is four months on the offensive side in depth, with methodology and reporting as substantial modules. Many people take the cyber security course first.
Everything is practised exclusively in isolated lab environments we provide, against systems we control. Running any of these techniques against systems you do not own or have written authorisation to test is a criminal offence under the Indian IT Act. Authorisation and scope is the first module, not a disclaimer slide.
No. CEH is an EC-Council certification with its own exam and authorised training partners, and we do not claim to be one. This course covers substantially overlapping technical ground and prepares you well for that subject matter, but it is not accredited CEH training. Ask us directly about our current accreditation status before enrolling on that basis.
Sometimes, but it is not the common path in India. Most penetration testers enter after a few years in defensive security, systems administration or development. Junior application security and vulnerability assessment roles are the more realistic first step, and this course targets those honestly.
Because it is the deliverable. A finding nobody acts on has produced no security benefit, and reports are where most junior testers are weakest. Clients pay for a document that a developer can follow and a manager can prioritise from, not for a tool output pasted into a template.
Three details is all we need. A course advisor will call you back.
Networking and Linux foundations, then web application security, SOC monitoring and incident response — practised exclusively in isolated labs, with authorisation treated as a hard rule.
Python taught as a working tool rather than a syntax tour — you finish able to read unfamiliar code, automate real tasks, call APIs and write tests that catch your own mistakes.
AWS taught by building and breaking infrastructure rather than by memorising service names, ending with an architecture you have deployed, secured, costed and can defend.
Next step
Tell us what you want to learn and we will help you pick the right course, batch and mode.