6 Month Mentorship Program in Cyber Security
Basic to Advanced. Six specializations, one a month, 40 hours each — Networking & Linux Security | Ethical Hacking & Penetration Testing | SOC & SIEM Operations | Cloud Security | DevSecOps & Application Security | AI Security, Threat Hunting & Automation. The progression runs Networking → Linux → Security Fundamentals → VAPT → SOC/SIEM → Cloud Security → DevSecOps → Application Security → Threat Hunting → AI Security → Security Automation, across 40+ hands-on labs, 100+ assignments, 25+ mini projects, 6 major capstones and an integrated enterprise capstone. No prior Linux experience is required, and every track ends in job scenarios, troubleshooting exercises, technical documentation and mock interviews.
6 Month Mentorship Program in Cyber Security
Basic to Advanced | 6 Specializations | 40 Hours Each
Tools you'll master
Enquire Now
Get course fees, batch dates & a callback
Why This Course?
Prerequisites
Programme Overview
6 cyber security tracks, one a month — Networking & Linux Security, Ethical Hacking & Penetration Testing, SOC & SIEM Operations, Cloud Security, DevSecOps & Application Security, and AI Security, Threat Hunting & Automation. Each track follows Learn → Demonstrate → Perform → Investigate → Troubleshoot → Document → Present → Interview.
Track 1 — Networking & Linux Security
Build the foundation required for almost every cybersecurity role by mastering networking, Linux administration and security hardening. Job focus: Network/Security Analyst, Linux Security.
Track 2 — Ethical Hacking & Penetration Testing
Develop practical skills for authorized vulnerability assessment and penetration testing. Job focus: VAPT Analyst, Ethical Hacker.
Track 3 — SOC & SIEM Operations
Develop practical SOC analyst capabilities covering monitoring, alert triage, SIEM, detection, investigation, incident response and threat hunting. Job focus: SOC Analyst L1/L2, SIEM Analyst.
Track 4 — Cloud Security
Develop practical cloud-security capabilities across AWS, Azure and GCP. Job focus: Cloud Security Analyst / Engineer.
Track 5 — DevSecOps & Application Security
Integrate application security throughout the software-development and cloud-deployment lifecycle. Job focus: DevSecOps, AppSec, Cloud Security.
Track 6 — AI Security, Threat Hunting & Automation
An advanced track combining AI/GenAI security, LLM security, threat hunting, detection engineering and cybersecurity automation. Job focus: Threat Hunter, Security Automation, AI Security.
Who is this programme for?
Whether you're a fresher, an IT or network administrator, a cloud or DevOps engineer or already working in support — this mentorship is built to take you into a Cybersecurity Analyst, SOC Analyst, VAPT Analyst, Cloud Security Engineer, DevSecOps Engineer, Threat Hunter or AI Security Analyst role.
Students & Freshers
No prior Linux experience needed — Track 1 starts at networking and Linux fundamentals and builds towards Cybersecurity Analyst and SOC Analyst L1 roles.
IT & Network Administrators
Move into Network Security Analyst, Security Operations Engineer and Junior Incident Response Analyst roles.
Aspiring Ethical Hackers
Train for VAPT Analyst, Penetration Tester and Application Security Analyst roles through authorized, methodology-driven testing.
Cloud & DevOps Engineers
Specialise as a Cloud Security Analyst, Cloud Security Engineer or DevSecOps Engineer across AWS, Azure and GCP.
SOC & Support Teams
Progress from alert triage into SIEM Analyst, Threat Hunter and Detection Engineer roles.
AI-Focused Engineers
Target AI Security Analyst and Security Automation Engineer roles with LLM, RAG and agent security plus Python automation.
Course Curriculum
6 tracks • 33 modules • 40 hours a track, with labs, assignments and a capstone in each
Build the foundation required for almost every cybersecurity role by mastering networking, Linux administration and security hardening.
Course Content
Prerequisites:
- Basic computer knowledge
- No prior Linux experience required
- Basic mathematics and logical reasoning
Topics:
- CIA Triad
- Cybersecurity terminology
- OSI Model
- TCP/IP Model
- IP addressing
- Subnetting
- TCP/UDP
- DNS
- DHCP
- HTTP/HTTPS
- SSH
- FTP
- SMTP
- VPN
- Firewall fundamentals
Topics:
- IPv4/IPv6
- Subnetting
- Routing
- Switching
- VLANs
- NAT
- DNS
- DHCP
- ARP
- ICMP
- TCP/UDP
- Network troubleshooting
- Network segmentation
Topics:
- Linux architecture
- Filesystem
- Users and groups
- Permissions
- Processes
- Services
- Package management
- SSH
- Cron
- System logs
- Bash
- Networking commands
- Storage
- System monitoring
Topics:
- File permissions
- sudo security
- SSH hardening
- Firewall
- SELinux concepts
- Audit logs
- Secure services
- Patch management
- Security baselines
- Linux incident investigation
Labs:
- Linux Security Lab Setup
- TCP/IP Analysis Lab
- Subnetting Lab
- DNS Investigation Lab
- Wireshark Packet Analysis Lab
- Linux User & Group Security Lab
- Linux Permission Security Lab
- SSH Hardening Lab
- Linux Firewall Lab
- Linux Log Analysis Lab
- Process Investigation Lab
- Service Hardening Lab
- Bash Security Automation Lab
- Linux Incident Investigation Lab
Assignments:
- Design an enterprise network
- Perform subnetting exercises
- Analyze packets using Wireshark
- Configure Linux users/groups
- Implement secure permissions
- Harden SSH
- Configure firewall rules
- Analyze authentication logs
- Create Linux security checklist
- Prepare Linux security assessment report
Mini Projects:
- Linux Server Hardening
- Enterprise Network Security Assessment
- Secure SSH Server
- Linux Log Monitoring System
Deliverables:
- Network diagram
- Security architecture
- Linux hardening report
- Firewall configuration
- Log analysis
- Vulnerability findings
- Remediation report
Scenarios:
- Investigate suspicious SSH logins
- Troubleshoot network connectivity
- Identify an unauthorized Linux user
- Investigate failed authentication
- Analyze suspicious network traffic
- Harden an internet-facing Linux server
- Troubleshoot DNS failure
Troubleshooting:
- DNS resolution failure
- Routing problems
- SSH connection failure
- Firewall blocking legitimate traffic
- Permission denied
- Service failure
- High CPU/memory
- Disk full
- Network interface failure
- Incorrect routing
Tools:
- Linux
- Ubuntu
- Kali Linux
- Wireshark
- Nmap
- Netcat
- tcpdump
- iptables/nftables
- SSH
- Bash
- Syslog
- auditd
Best Practices:
- Least privilege
- SSH hardening
- Strong authentication
- Secure permissions
- Patch management
- Network segmentation
- Centralized logging
- Secure firewall configuration
- Regular security auditing
Mock Interviews
- › OSI/TCP-IP questions
- › Subnetting exercises
- › Linux troubleshooting
- › SSH/security scenarios
- › Firewall troubleshooting
- › Real-world Linux administration scenarios
Certifications:
- CompTIA Network+
- CompTIA Security+
- Linux+
- LPIC-1
- RHCSA
Develop practical skills for authorized vulnerability assessment and penetration testing.
Course Content
Prerequisites:
- Networking fundamentals
- Linux fundamentals
- Basic web concepts
Topics:
- Ethical hacking
- VAPT
- Attack surface
- Vulnerability vs exploit
- Black/White/Grey Box
- Rules of engagement
- OWASP methodology
- MITRE ATT&CK fundamentals
Topics:
- Passive reconnaissance
- Active reconnaissance
- OSINT
- DNS enumeration
- Subdomain discovery
Topics:
- Host discovery
- Port scanning
- Service enumeration
- Vulnerability assessment
Topics:
- Authentication
- Authorization
- SQL injection
- XSS
- CSRF
- File upload
- Path traversal
- SSRF
- API security
- Security misconfiguration
Topics:
- Exploitation fundamentals
- Metasploit
- Shell concepts
- Privilege escalation
- Post-exploitation fundamentals
Topics:
- Evidence
- CVSS
- Business impact
- Remediation
- Retesting
Labs:
- Kali Linux setup
- Nmap scanning
- DNS enumeration
- Web reconnaissance
- SMB enumeration
- Vulnerability scanning
- Burp Suite
- SQL injection lab
- XSS lab
- Authentication testing
- API security lab
- Metasploit lab
- Linux privilege escalation
- Windows privilege escalation
- VAPT reporting lab
Assignments:
- Reconnaissance report
- Nmap analysis
- Vulnerability classification
- Web application assessment
- SQL injection analysis
- XSS analysis
- API security assessment
- Linux privilege assessment
- Windows privilege assessment
- VAPT report
Mini Projects:
- Network VAPT
- Web Application VAPT
- API Security Assessment
- Linux Security Assessment
- Windows Security Assessment
Project Flow:
- Recon → Scan → Enumerate → Validate → Authorized Exploitation → Evidence → Report → Remediation
Scenarios:
- External VAPT
- Web application assessment
- Vulnerability validation
- Authentication testing
- API testing
- Privilege assessment
- Security report preparation
Troubleshooting:
- Nmap results
- Burp proxy problems
- Authentication issues
- False-positive vulnerabilities
- Scanner failures
- Lab connectivity
- Exploit validation issues
Tools:
- Kali Linux
- Nmap
- Burp Suite
- OWASP ZAP
- Metasploit
- Nessus
- OpenVAS/Greenbone
- Nuclei
- Wireshark
- SQLMap
- Hashcat
- John the Ripper
Best Practices:
- Written authorization
- Scope control
- Non-destructive testing
- Evidence preservation
- Manual validation
- Secure reporting
- Responsible disclosure
Mock Interviews
- › Nmap output analysis
- › OWASP questions
- › VAPT methodology
- › Burp Suite practical
- › Vulnerability-report analysis
- › Penetration-testing scenarios
Certifications:
- CEH
- eJPT
- PNPT
- CompTIA PenTest+
- OSCP
Develop practical SOC analyst capabilities covering monitoring, alert triage, SIEM, detection, investigation, incident response and threat hunting.
Course Content
Prerequisites:
- Networking basics
- Linux/Windows basics
- Cybersecurity fundamentals
Topics:
- SOC architecture
- SOC L1/L2/L3
- Event vs alert vs incident
- Incident lifecycle
- Security monitoring
- Logs
- IOCs
- IOAs
- MITRE ATT&CK
Topics:
- Windows logs
- Linux logs
- Firewall logs
- DNS logs
- VPN logs
- Endpoint logs
Topics:
- SIEM architecture
- Log ingestion
- Parsing
- Correlation
- Detection rules
- Alert triage
- False positives
- Threat intelligence
- Threat hunting
- Incident response
- MITRE ATT&CK
- Security reporting
- SOAR fundamentals
Labs:
- Windows Event Log Analysis
- Linux Log Analysis
- Firewall Log Analysis
- DNS Investigation
- SIEM Setup
- Log Ingestion
- SIEM Queries
- Dashboard Creation
- Alert Creation
- Correlation Rules
- Brute-Force Detection
- PowerShell Detection
- Phishing Investigation
- Compromised Account Investigation
- Threat Hunting
- MITRE ATT&CK Mapping
- Incident Timeline
- SOC Incident Report
Assignments:
- SOC architecture
- Log analysis
- SIEM queries
- Dashboard creation
- Detection rule
- Brute-force investigation
- Phishing investigation
- IOC analysis
- MITRE mapping
- Incident report
Mini Projects:
- Failed Login Detection
- Phishing Investigation
- Windows Threat Monitoring
- Network Security Monitoring
- MITRE ATT&CK Detection Project
Project Flow:
- Collect → Detect → Triage → Investigate → Correlate → Respond → Report
Scenarios:
- Brute-force attack
- Phishing alert
- Compromised account
- Suspicious PowerShell
- Malware alert
- Impossible travel
- Suspicious DNS
- Data-exfiltration indicators
- Lateral-movement indicators
Troubleshooting:
- Missing logs
- Incorrect parsing
- SIEM query problems
- False positives
- Missing alerts
- Agent offline
- Dashboard problems
- Detection rule failures
Tools:
- Microsoft Sentinel
- Splunk
- Elastic Security
- QRadar
- Defender for Endpoint
- CrowdStrike
- SentinelOne
- Wireshark
- Zeek
- Suricata
- Sigma
- KQL
- SPL
Best Practices:
- Alert validation
- Evidence preservation
- Detection tuning
- MITRE mapping
- Incident documentation
- Proper escalation
- Continuous monitoring
- Shift handover
Mock Interviews
- › SIEM query exercises
- › Alert-triage scenarios
- › Phishing investigation
- › MITRE ATT&CK
- › Incident-response questions
- › L1/L2 SOC scenarios
Certifications:
- SC-200
- CompTIA CySA+
- Splunk certifications
- EC-Council CSA
- GSEC
- GCIH
Develop practical cloud-security capabilities across AWS, Azure and GCP.
Course Content
Prerequisites:
- Networking
- Linux
- Security fundamentals
- Basic cloud knowledge
Topics:
- Cloud computing
- IaaS/PaaS/SaaS
- Shared Responsibility Model
- Cloud attack surface
- IAM
- Encryption
- Zero Trust
- Cloud networking
Topics:
- AWS IAM
- Entra ID
- Azure RBAC
- GCP IAM
- MFA
- Least privilege
- Managed identities
- Privileged access
Topics:
- VPC/VNet
- Subnets
- Security Groups
- NSGs
- Firewalls
- WAF
- Private endpoints
- VPN
- Network segmentation
Topics:
- KMS
- Key Vault
- Cloud KMS
- Secrets management
- Encryption
- Storage security
Topics:
- CloudTrail
- Azure Activity Logs
- GCP Audit Logs
- GuardDuty
- Defender for Cloud
- Security Command Center
- SIEM integration
Topics:
- Misconfiguration
- Vulnerability management
- Compliance
- CIS Benchmarks
Labs:
- AWS IAM
- Azure Entra/RBAC
- GCP IAM
- Least-Privilege Lab
- VPC Security
- VNet Security
- Security Group/NSG
- Cloud Firewall
- WAF
- Storage Security
- KMS
- Secrets Manager
- VM Hardening
- CloudTrail
- Azure Activity Logs
- GCP Audit Logs
- CSPM Assessment
- Cloud Incident Investigation
Assignments:
- Secure cloud architecture
- IAM assessment
- VPC/VNet security
- Storage security
- Encryption
- Cloud logging
- CSPM assessment
- Cloud incident-response plan
Mini Projects:
- Secure Cloud Landing Zone
- Cloud IAM Assessment
- Cloud Network Security Assessment
- Cloud Storage Security
- Cloud SIEM Monitoring
Coverage:
- IAM
- Network
- Compute
- Storage
- Encryption
- Logging
- Monitoring
- Compliance
- Incident response
Scenarios:
- Public storage exposure
- Compromised cloud credentials
- Excessive IAM privileges
- Public database
- Open security group
- Suspicious API calls
- Cryptomining
- Cloud audit-log investigation
Troubleshooting:
- IAM denial
- Cross-account access
- Security-group blockage
- Private endpoint failure
- DNS problems
- Missing audit logs
- WAF false positives
- KMS access problems
Tools:
- AWS IAM
- AWS Security Hub
- GuardDuty
- CloudTrail
- AWS KMS
- Microsoft Entra ID
- Defender for Cloud
- Sentinel
- Azure Key Vault
- GCP IAM
- Security Command Center
- Wiz
- Prisma Cloud
- Checkov
Best Practices:
- Least privilege
- MFA
- Zero Trust
- Centralized logging
- Encryption
- Secure secrets
- Network segmentation
- Continuous posture management
- Secure cloud architecture
Mock Interviews
- › IAM scenarios
- › Cloud architecture
- › Cloud incident response
- › Security-group troubleshooting
- › Cloud misconfiguration scenarios
Certifications:
- AWS Certified Security – Specialty
- AZ-500
- Google Cloud Professional Cloud Security Engineer
- CCSP
- Security+
Teach students how to integrate application security throughout the software-development and cloud-deployment lifecycle.
Course Content
Prerequisites:
- Linux
- Git
- Basic programming
- Basic cloud concepts
Topics:
- DevSecOps
- Secure SDLC
- Shift Left
- Shift Right
- OWASP
- Threat modeling
- Security as Code
- Policy as Code
Topics:
- OWASP Top 10
- API Security
- Authentication
- Authorization
- Secure coding
Topics:
- SonarQube
- Semgrep
- CodeQL
Topics:
- Dependency scanning
- CVE/CVSS
- SBOM
- Supply-chain security
Topics:
- Gitleaks
- TruffleHog
- Secret management
Topics:
- Jenkins
- GitHub Actions
- GitLab
- Azure DevOps
- Security gates
Topics:
- Docker security
- Trivy
- Image signing
Topics:
- RBAC
- Network Policies
- Pod Security
- Falco
Topics:
- Terraform
- Checkov
- OPA
- Policy-as-Code
Topics:
- Burp Suite
- OWASP ZAP
Labs:
- Secure SDLC
- Threat Modeling
- Git Security
- Gitleaks
- SonarQube
- Semgrep
- CodeQL
- Dependency scanning
- SBOM
- Jenkins Security Pipeline
- GitHub Actions Security
- Docker Security
- Trivy
- Container Signing
- Kubernetes RBAC
- Kubernetes Network Policies
- Terraform Security
- Checkov
- DAST
- API Security
- End-to-End DevSecOps Pipeline
Assignments:
- Secure SDLC
- OWASP assessment
- Git security
- Secret detection
- SAST analysis
- SCA assessment
- SBOM
- CI/CD security
- Docker security
- Kubernetes security
- IaC security
- DAST assessment
Mini Projects:
- Secure CI/CD Pipeline
- Application Security Assessment
- Container Security
- Kubernetes Security
- Terraform Security
Project Flow:
- Git → SAST → SCA → Secret Scan → Build → Container Scan → IaC Scan → DAST → Kubernetes → Cloud → Monitoring
Scenarios:
- Secret committed to Git
- Critical dependency
- Vulnerable Docker image
- Kubernetes privilege issue
- Terraform misconfiguration
- DAST vulnerability
- CI/CD security gate
- Compromised build pipeline
Troubleshooting:
- SAST failure
- False positives
- Pipeline credential failure
- Docker build failure
- Kubernetes RBAC failure
- NetworkPolicy blocking traffic
- Terraform policy failure
- DAST authentication failure
Tools:
- GitHub
- GitLab
- Jenkins
- Azure DevOps
- SonarQube
- Semgrep
- CodeQL
- Snyk
- Gitleaks
- Trivy
- Docker
- Kubernetes
- Falco
- Terraform
- Checkov
- OPA
- Burp Suite
- OWASP ZAP
Best Practices:
- Security by design
- Shift-left
- Automated security testing
- Secrets protection
- Dependency management
- SBOM
- Container hardening
- IaC scanning
- Secure CI/CD
- Security gates
- Continuous monitoring
Mock Interviews
- › SAST vs DAST
- › SCA
- › SBOM
- › CI/CD security
- › Docker/Kubernetes
- › IaC security
- › OWASP
- › DevSecOps architecture
Certifications:
- Security+
- AWS Security Specialty
- AZ-500
- CKS
- OSWE
- GIAC application-security certifications
- DevSecOps certifications
An advanced security track combining AI/GenAI security, LLM security, threat hunting, detection engineering and cybersecurity automation.
Course Content
Prerequisites:
- Cybersecurity fundamentals
- Networking
- Linux
- SOC concepts
- Basic Python
- Basic cloud concepts
Topics:
- AI/ML security fundamentals
- GenAI security
- LLM fundamentals
- Threat hunting
- Detection engineering
- Security automation
- MITRE ATT&CK
- IOC/IOA
- Security analytics
Topics:
- AI security architecture
- LLM security
- Prompt security
- Prompt injection
- Indirect prompt injection
- Data leakage
- Sensitive-data exposure
- Model abuse
- Model access control
- AI supply-chain security
- AI application security
- RAG security
- Vector database security
- Agent security
- Tool/API security for AI agents
Topics:
- Hunting methodology
- Hypothesis-driven hunting
- IOC hunting
- Behavioral hunting
- Identity hunting
- Endpoint hunting
- Network hunting
- Cloud hunting
- MITRE ATT&CK mapping
- Detection engineering
Topics:
- Python for security
- API integration
- IOC enrichment
- Automated investigation
- SOAR concepts
- Automated alert triage
- Security reporting
- Threat-intelligence automation
Labs:
- AI Security Lab Setup
- Prompt Injection Testing Lab
- LLM Data-Leakage Lab
- RAG Security Lab
- AI Agent Security Lab
- AI API Security Lab
- IOC Enrichment Lab
- Threat-Hunting Lab
- MITRE ATT&CK Hunting Lab
- Authentication Hunting Lab
- Endpoint Hunting Lab
- Network Threat Hunting Lab
- Cloud Threat Hunting Lab
- Detection Engineering Lab
- Sigma Rule Lab
- Python Security Automation Lab
- Threat Intelligence API Lab
- Automated Alert Enrichment Lab
- SOC Automation Lab
- AI-Assisted Security Investigation Lab
Assignments:
- AI threat model
- LLM security assessment
- Prompt-injection analysis
- RAG security assessment
- AI data-leakage assessment
- Threat-hunting hypothesis
- MITRE ATT&CK mapping
- Detection rule creation
- IOC enrichment script
- Security automation script
- Automated incident report
- AI security assessment report
Assess a simulated GenAI application for:
- Prompt injection
- Data leakage
- Access control
- Unsafe tool usage
- Insecure API integration
Hunting Workflow:
- Logs → Queries → IOC Enrichment → Detection → MITRE Mapping → Report
Build Python automation for:
- IOC enrichment
- IP/domain reputation
- Hash analysis
- Alert enrichment
- Automated reporting
Workflow assists analysts in:
- Alert summarization
- IOC extraction
- Log analysis
- MITRE mapping
- Investigation documentation
Students Create:
- Threat-hunting hypotheses
- Data sources
- Hunting queries
- Detection rules
- MITRE ATT&CK mapping
- Investigation workflow
- Final threat-hunting report
Assessment Path:
- User → Application → LLM → RAG → Vector DB → Tools/APIs → Cloud
Assess
- › Identity
- › Prompt security
- › Data security
- › RAG security
- › Agent security
- › API security
- › Logging
- › Monitoring
- › Abuse scenarios
Project Flow:
- SIEM Alert → Python/API → IOC Enrichment → Threat Intelligence → MITRE Mapping → Analyst Decision → Report
Scenarios:
- Investigate an advanced persistent threat hypothesis
- Hunt for suspicious authentication patterns
- Identify abnormal PowerShell activity
- Hunt for suspicious DNS behavior
- Investigate unusual cloud API activity
- Develop a detection rule for a MITRE ATT&CK technique
- Enrich suspicious IP addresses automatically
- Automate IOC reputation checks
- Build an automated SOC report
- Investigate prompt injection against an LLM application
- Investigate sensitive information leakage from an AI application
- Assess an AI agent's access to external tools
- Identify insecure RAG data access
- Investigate suspicious API calls made by an AI application
Troubleshooting:
- Threat-hunting query returns excessive results
- Detection rule generates false positives
- IOC enrichment API fails
- Threat-intelligence feed is unavailable
- Python automation fails
- SIEM API authentication fails
- AI model returns unsafe/unexpected output
- Prompt-injection defense fails
- RAG retrieves unauthorized information
- AI agent accesses an unintended tool
- Security automation creates duplicate incidents
Tools:
- Microsoft Sentinel
- Splunk
- Elastic Security
- KQL
- SPL
- Sigma
- MITRE ATT&CK
- VirusTotal
- AbuseIPDB
- AlienVault OTX
- MISP
- OWASP GenAI Security resources
- LLM security testing frameworks
- Python
- REST APIs
- PowerShell
- SOAR platforms
- Microsoft Logic Apps
- Splunk SOAR
- Cortex XSOAR
Best Practices:
- Treat AI output as untrusted
- Apply least privilege to AI agents
- Never expose secrets to models unnecessarily
- Protect sensitive training/RAG data
- Validate tool/API access
- Log AI security events
- Apply human approval to high-impact actions
- Continuously test AI applications
- Use threat-informed detection
- Automate repetitive tasks while maintaining analyst oversight
- Validate automated security actions before production use
Mock Interviews
- › Threat-hunting scenarios
- › MITRE ATT&CK
- › Detection engineering
- › Python automation
- › AI security
- › Prompt injection
- › RAG security
- › AI-agent security
- › SOC automation scenarios
Certifications:
- GIAC Cyber Threat Intelligence (GCTI)
- GIAC Certified Detection Engineer (GCDE)
- GIAC Certified Incident Handler (GCIH)
- CompTIA CySA+
- Microsoft SC-200
- Relevant cloud-security certifications
- Vendor-specific AI/security certifications as available
Tools & Technologies
Every tool and library listed here is installed, configured and used in a hands-on lab session.
Wireshark
Packet Analysis
Nmap
Host & Port Scanning
tcpdump
Traffic Capture
Netcat
Network Utility
Zeek
Network Security Monitoring
Suricata
IDS / IPS
Ubuntu
Linux Distribution
Kali Linux
Security Testing Distribution
Bash
Security Automation
SSH
Secure Remote Access
auditd
Audit Logging
SELinux
Mandatory Access Control
Burp Suite
Web Application Testing
OWASP ZAP
DAST Scanning
Metasploit
Exploitation Framework
Nessus
Vulnerability Scanning
Nuclei
Template-Based Scanning
SQLMap
SQL Injection Testing
Microsoft Sentinel
Cloud-Native SIEM
Splunk
SIEM & Analytics
Elastic Security
Log Analytics & Detection
QRadar
Enterprise SIEM
Defender / CrowdStrike
Endpoint Detection & Response
Sigma, KQL & SPL
Detection Rules & Queries
AWS Security Hub
Security Posture
GuardDuty
Threat Detection
CloudTrail
Audit Logging
Defender for Cloud
Azure Posture & Protection
Entra ID
Identity & Access
Wiz / Prisma Cloud
CSPM
GitHub / GitLab
Source & Pipelines
Jenkins
CI/CD with Security Gates
SonarQube / Semgrep / CodeQL
SAST
Snyk & Gitleaks
SCA & Secret Scanning
Trivy & Docker
Container Security
Terraform, Checkov & OPA
IaC Security & Policy as Code
MITRE ATT&CK
Adversary Framework
VirusTotal & AbuseIPDB
IOC Reputation
AlienVault OTX & MISP
Threat Intelligence Sharing
Python & REST APIs
Security Automation
LLM Security Testing
Prompt, RAG & Agent Security
SOAR / Cortex XSOAR
Automated Response
Six specializations, six capstones — and a security portfolio you can walk an interviewer through.
A major capstone in every track, three in Track 6, and one integrated enterprise capstone — from a Linux and network security assessment and an authorized penetration test to a SOC investigation, a multi-cloud security assessment, a DevSecOps pipeline, a threat-hunting program and an AI security assessment.
Enterprise Linux & Network Security Assessment
→Network Diagram → Security Architecture
→Linux Hardening → Firewall Configuration
→Log Analysis → Findings → Remediation
Job focus: Network / Security Analyst, Linux Security
Map and assess an enterprise network and its Linux estate, then document what you hardened, what you found and how it should be fixed.
Enterprise Network + Web Application Penetration Test
→Recon → Scan → Enumerate
→Validate → Authorized Exploitation
→Evidence → Report → Remediation
Job focus: VAPT Analyst, Ethical Hacker
A full authorized engagement, from reconnaissance through validated exploitation to an evidence-backed report and remediation guidance.
Enterprise SOC & SIEM Investigation
→Collect → Detect → Triage
→Investigate → Correlate
→Respond → Report
Job focus: SOC Analyst L1/L2, SIEM Analyst
Run the full SOC lifecycle on a simulated environment — collect the logs, build the detections, triage the alerts and take an incident through to a written report.
Enterprise Multi-Cloud Security Assessment
→IAM → Network → Compute → Storage
→Encryption → Logging → Monitoring
→Compliance → Incident Response
Job focus: Cloud Security Analyst / Engineer
Assess a multi-cloud estate end to end, from identity and network through to compliance and incident response.
Enterprise DevSecOps Security Pipeline
→Git → SAST → SCA → Secret Scan
→Build → Container Scan → IaC Scan → DAST
→Kubernetes → Cloud → Monitoring
Job focus: DevSecOps, AppSec, Cloud Security
Security gates at every stage of delivery — source, dependencies, secrets, images, infrastructure and the running application.
Enterprise Threat Hunting Program
→Hypotheses → Data Sources → Hunting Queries
→Detection Rules → MITRE ATT&CK Mapping
→Investigation Workflow → Report
Hypothesis-driven hunting, mapped to MITRE ATT&CK
Define the hypotheses and data sources, write the hunting queries and detection rules, then work an investigation through to a threat-hunting report.
AI Security Assessment
→User → Application → LLM
→RAG → Vector DB → Tools / APIs
→Cloud → Logging → Monitoring
Assess an enterprise GenAI application end to end
Work the whole path from user to cloud — identity, prompt security, data and RAG security, agent and API security, logging, monitoring and abuse scenarios.
Automated SOC Investigation
→SIEM Alert → Python / API
→IOC Enrichment → Threat Intelligence
→MITRE Mapping → Analyst Decision → Report
Python and APIs doing the enrichment, the analyst making the call
Take a SIEM alert through automated IOC enrichment and threat intelligence to a MITRE mapping, leaving the decision — and the report — with the analyst.
Enterprise Cyber Defense & Security Operations Platform
→Users → Network → Linux/Windows → Web App
→Cloud → Containers → Kubernetes → CI/CD
→AI Application → SIEM
All six tracks combined into one simulated enterprise
Users, network, Linux and Windows servers, a web application, cloud, containers, Kubernetes, CI/CD, an AI application and a SIEM — assessed, monitored, hunted and reported across network security, Linux security, penetration testing, SOC/SIEM, cloud security, DevSecOps, AI security, threat hunting and automation.
All 9 projects go directly into your portfolio & resume — reviewed by mentors before you graduate.
See Sample Project ReportsUpcoming Batches
| Start Date | Time | Day | Mode | Enroll |
|---|---|---|---|---|
| 10/08/2026 | 08:00 PM – 09:30 PM | Weekday | Online | Enroll Now |
Why Radical Technologies
- Highly practical oriented training
- Installation support on your system
- 24/7 Email and Phone support
- 100% Placement Assistance
- Global Certification Preparation
- Trainer-Student Interactive Portal
- Assignments and Projects by Mentors
- Weekend / Weekdays / Morning / Evening batches
- 80:20 Practical and Theory ratio
- Real-life Case Studies
- Easy make-up for missed sessions
- PSI | Kryterion | Certification Test Centers
- Lifetime Video Classroom Access (coming soon)
- Resume Prep and Mock Interviews
- Learn 300+ courses at your own time
- 50,000+ Satisfied Learners
- Course Completion Certificate
- Practical Labs available
- Mentor Support available
- Doubt Clearing Session available
- 10% Discounted Global Certification
Like the Curriculum? Let's Get Started
Join 50,000+ students already enrolled at Radical Technologies
Global Certification
Radical Technologies is the leading IT certification institute in Pune, offering globally recognized certifications across various domains. With expert trainers and comprehensive materials, we ensure students gain in-depth knowledge and hands-on experience to excel in their careers. Our certification programs are tailored to meet industry standards — this mentorship follows a certification roadmap from CompTIA Network+ and Security+ through CEH, OSCP, SC-200, CySA+, AWS Security Specialty, AZ-500 and CKS to GCIH, GCTI and GCDE, empowering individuals to stay ahead in the ever-evolving cyber security landscape.
Career Services
Our dedicated Placement Support Team works with you from day one — resume forwarding, technical interview preparation, HR interview preparation, career guidance, soft skills training, mock interviews and internship assistance, with access to 850+ Hiring Partners and placement assistance until you get hired.
Career Support
Join our Brush-up Session & get support until you find a job!
Get StartedRadical Learning Eco-System
Exam Simulator
Cloud SandBox
Hands-on Cloud Lab
Developer Coding Ground
Student Reviews
Course Rating
Our Alumni Work At
Related Courses
PG DIPLOMA — CYBER SECURITY WITH AI
350+ hrsPG DIPLOMA — CYBER SECURITY WITH AI
The full-length PG Diploma — Cyber Security with Cloud, DevSecOps and AI across a multi-course programme.
6 MONTH MENTORSHIP — PLATFORM ENGINEERING
240 hrs6 MONTH MENTORSHIP — PLATFORM ENGINEERING
The companion mentorship track — Linux, Cloud, DevOps & Python, Kubernetes, Infrastructure as Code and SRE with AIOps over six months.
6 MONTH MENTORSHIP — DATA ENGINEERING
240 hrs6 MONTH MENTORSHIP — DATA ENGINEERING
Python & SQL, Big Data, Cloud Data Engineering, Databricks, Pipelines and GenAI & Agentic AI over six months.
DEVOPS ENGINEERING
70 hrsDEVOPS ENGINEERING
End-to-end DevOps toolchain — Git, Jenkins, Docker, Kubernetes, Terraform and GitOps, the base DevSecOps builds on.
Mentorship Programme In Other Cities
Online Batches Available For These Areas
Ambegaon Budruk | Aundh | Baner | Bavdhan Khurd | Bavdhan Budruk | Balewadi | Shivajinagar | Bibvewadi | Bhugaon | Bhukum | Dhankawadi | Dhanori | Dhayari | Erandwane | Fursungi | Ghorpadi | Hadapsar | Hingne Khurd | Karve Nagar | Kalas | Katraj | Khadki | Kharadi | Kondhwa | Koregaon Park | Kothrud | Lohagaon | Manjri | Markal | Mohammed Wadi | Mundhwa | Nanded | Parvati Hill | Panmala | Pashan | Pirangut | Shivane | Sus | Undri | Vishrantwadi | Vitthalwadi | Vadgaon Khurd | Vadgaon Budruk | Vadgaon Sheri | Wagholi | Wanwadi | Warje | Yerwada | Akurdi | Bhosari | Chakan | Charholi Budruk | Chikhli | Chimbali | Chinchwad | Dapodi | Dehu Road | Dighi | Dudulgaon | Hinjawadi | Kalewadi | Kasarwadi | Maan | Moshi | Phugewadi | Pimple Gurav | Pimple Nilakh | Pimple Saudagar | Pimpri | Ravet | Rahatani | Sangvi | Talawade | Tathawade | Thergaon | Wakad
6 Month Mentorship Program in Cyber Security
Basic to Advanced | 6 Specializations | 40 Hours Each
Tools you'll master