SamyakComputer ClassesShakarpur

Course

Penetration Testing (CPTE)

Offensive security practised only on a lab you are authorised to attack, taught through a full engagement — scope, test, escalate, and write the report a client can act on.

  • Duration: 4 months
  • Classroom · Online live
  • Level: advanced

What you will be able to do

Who this course is for

Syllabus

7 modules · 4 months

  1. Module 1. Legal and ethical foundations

    • Authorisation, scope and rules of engagement
    • Indian law on unauthorised access, in plain terms
    • Responsible disclosure and what to do when you find something out of scope
    • Evidence handling and note taking
  2. Module 2. Reconnaissance and enumeration

    • Passive information gathering
    • Port scanning and service fingerprinting with Nmap
    • Enumerating SMB, SNMP, DNS and web services
    • Building an attack surface map from findings
  3. Module 3. Vulnerability assessment

    • Scanners, and why their output is a starting point
    • Verifying a finding manually before reporting it
    • False positives and the credibility cost of reporting one
    • Prioritising by real exploitability and business impact
  4. Module 4. Exploitation

    • Service exploitation with Metasploit and by hand
    • Password attacks, hashes and credential reuse
    • Pivoting through a compromised host
    • Post-exploitation and maintaining access within scope
  5. Module 5. Web application testing

    • Intercepting and manipulating requests with Burp Suite
    • Injection, authentication and session flaws
    • Access control testing and broken object level authorisation
    • The OWASP Top Ten as a working checklist
  6. Module 6. Privilege escalation

    • Linux escalation — permissions, SUID, cron and kernel
    • Windows escalation — services, tokens and misconfiguration
    • Enumeration scripts and reading their output critically
    • Hardening advice that follows from each finding
  7. Module 7. Reporting

    • Executive summary for people who will not read the detail
    • Findings with reproduction steps a developer can follow
    • Risk rating and honest prioritisation
    • Remediation advice that is actually implementable

Tools and technologies you will use

Projects you will build

Where this course can take you

  • Penetration Tester
  • Security Analyst
  • VAPT Consultant
  • Application Security Engineer
  • Security Operations Analyst

Duration, modes and fees

Duration
4 months
Delivery modes
Classroom · Online live
Fees
Share your details for the current fee
Fees vary by batch and delivery mode. Lab access is included. Any external certification you choose to pursue is booked and paid for separately with that body.

Placement assistance

Every student gets placement assistance — that is what 100% placement assistance means. It is support for all, not a job for all. We do not promise a specific salary, a specific number of interviews, or placement at any named company, and you should be wary of anyone who does.

What is included

  • A place in the monthly placement drive, held every third Saturday
  • The readiness programme every second Saturday — mock interviews and preparation
  • CV review against the specific roles you are targeting
  • Portfolio review, so your project work is presented the way a reviewer will read it
  • Access to the vacancy pool employers send directly to the Samyak network
  • Guidance on which roles realistically fit your background and which do not
  • A place in the next drive, with coaching, if you are not selected in this one

What is not included

  • Any guarantee of a job, an interview, or a particular salary
  • Placement at a named or partner company
  • Applying to jobs on your behalf
  • Support before you have completed the course and its project work
  • Visa, relocation or overseas placement assistance

Authorised targets only

The first module is law and scope, before any tool is opened.

Every technique in this course is practised on a lab built to be attacked. Using the same techniques against a system you do not have written authorisation to test is a criminal offence under the Information Technology Act, and the fact that it was easy is not a defence anybody has successfully run.

This is not a disclaimer bolted to the front. It is how professionals work — scope agreed, rules of engagement signed, findings kept inside the boundary — and it is the first thing a serious employer checks that you understand.

The report is the product

A client does not buy your access to their server. They buy a document.

An executive summary somebody with no technical background can act on. Findings with reproduction steps a developer can follow without ringing you. Risk ratings that reflect real business impact rather than a scanner’s severity field. Remediation advice that can actually be implemented by the team who has to do it.

Most candidates are weakest here and it is the most visible differentiator, so it gets a full module and the final project is the report itself.

Verify before you report

A scanner produces a list. Some of it is wrong.

Reporting an unverified finding costs you credibility with a client permanently, and it is the fastest way for a junior tester to lose the room. The assessment module trains manual verification of every finding before it goes anywhere near a document — slower, and the only professional option.

Where this fits

Take Ethical Hacking first if security is new to you. This course assumes that ground and goes to professional practice.

It converts best for people already in support, networking or development, where the underlying systems knowledge is present. If that is not you yet, we will say so and suggest the order that works rather than enrol you into a course that will outrun you.

Questions

Penetration Testing (CPTE) — frequently asked questions

Is everything in this course legal?

Everything taught here is practised on a lab environment built for it and on systems you are explicitly authorised to test. Running these techniques against a system you do not have written permission to test is a criminal offence in India under the Information Technology Act, and the first module covers that plainly. We will not teach anyone who intends otherwise.

How is this different from the Ethical Hacking course?

Ethical Hacking is the foundation — concepts, tooling and the landscape. This is the professional practice — a structured engagement methodology, deeper exploitation and privilege escalation, and above all the reporting. Take Ethical Hacking first if security is new to you; this assumes it.

Why does report writing get a whole module?

Because the report is the product. A client pays for a document their developers can act on, and a tester who finds twenty issues but writes them up unclearly delivers less value than one who finds twelve and explains each precisely. It is also the part most candidates are weakest at, which makes it a differentiator.

Will this get me a job in security?

It gives you a methodology, lab experience and a written report to show, which is what interviews probe. Security hiring generally wants some IT or networking grounding underneath, so it converts best for people already in support, networking or development. We will give you an honest read on your own position rather than a stock answer.

Enquire about Penetration Testing (CPTE)

Three details is all we need. A course advisor will call you back.

By submitting, you agree to be contacted about courses and accept our privacy policy.

Next step

Talk to a course advisor

Tell us what you want to learn and we will help you pick the right course, batch and mode.

Request a callback

Three details is all we need. A course advisor will call you back.

By submitting, you agree to be contacted about courses and accept our privacy policy.