Cybersecurity course catalogue
Choose the cybersecurity path that matches where you are now.
Learn to Elevate offers practical cybersecurity education for young learners, beginners, future practitioners and experienced learners who want specialised security skills.
Start by selecting the course that interests you. Where previous knowledge is required, we will use a practical starting-point assessment to understand your current skills and guide you towards the right course or prerequisite.
This is not a test to rate you. It helps us make sure that your chosen course will genuinely help you progress.
The Learn to Elevate promise
Learning that leads to real ability.
Every learner must leave an LTE course able to demonstrate something—not merely attend classes or collect lecture slides.
Depending on the course, that may be a safer device, a working Python program, a hardened virtual machine, a secure network design, a completed security assessment, an investigated set of logs, a threat model, a secure application or a professional security report.
Once you successfully complete our courses, you will be able to do the work, explain your decisions and show the result.
Explore your options
Cybersecurity learning pathways
Open a pathway to view its courses. Then open an individual course to see its complete curriculum, schedule, prerequisites, practical work, assessment method and October 2026 launch fee.
Young Cyber Explorers Practical digital-safety and introductory cybersecurity courses for children and teenagers.
Y1 Cyber Smart Start Build safer habits for passwords, privacy, online sharing and asking a trusted adult for help.
What this course is for
A child-first digital safety course that turns everyday situations—logging in, chatting, sharing photos, using apps and asking for help—into safe habits. It does not teach hacking tools. It teaches children to protect themselves, respect others and involve a trusted adult early.
- Who can join and required knowledge
- Ages 8–11. No prior knowledge required. Direct enrolment with no admission assessment.
- Course schedule
- 8 weeks · 2 sessions per week · 75 minutes per session
- Guided learning
- 20 hours
What you will be able to do
- Create and protect a strong passphrase and explain why multi-factor authentication helps.
- Recognise personal information, risky sharing and permanent digital footprints.
- Respond safely to unwanted contact, cyberbullying and account problems.
- Build a practical family digital-safety plan.
What the course covers
-
My digital world and trusted adults — 2.5 hours
Devices, accounts, online identity, private and public information, and when to pause and ask for help.
-
Passwords and account protection — 2.5 hours
Passphrases, password reuse, password managers, multi-factor authentication and account-recovery contacts.
-
Privacy and personal data — 2.5 hours
Names, photographs, location, school details, permissions and sharing only what is necessary.
-
Digital footprints — 2.5 hours
Posts, screenshots, forwarding, online reputation and thinking before publishing.
-
Social media and messaging safety — 2.5 hours
Known and unknown contacts, privacy settings, group chats and safe blocking and reporting.
-
Cyberbullying, consent and digital citizenship — 2.5 hours
Kind conduct, permission before sharing, safe bystander choices and preserving evidence.
-
Account recovery and asking for help — 2.5 hours
What to do after clicking something unsafe, losing a password or receiving an unexpected message.
-
Family safety plan and learner showcase — 2.5 hours
Scenario exercises, a home-safety checklist and a short learner-parent presentation.
Practical work and labs
- Passphrase-building activity and multi-factor authentication role-play.
- Practice-profile privacy check and app-permission sorting.
- Cyberbullying response scenarios and trusted-adult decision activity.
- Family device and account-safety checklist.
How your work will be assessed
Activity portfolio: 40%. Four scenario checks: 20%. Family safety plan and short learner showcase: 40%. There is no high-pressure written examination.
October 2026 Launch Fee
₹4,500
GST will be charged additionally at the applicable rate.
Y2 Scam, Gaming & Digital Trust Detectives Learn to spot scams, unsafe gaming interactions, fake links and misleading online content before acting on them.
What this course is for
An investigation-based course covering situations children commonly encounter, including fake links, game-chat manipulation, online marketplace offers, misinformation, deepfakes and unsafe prompts. Learners practise slowing down, checking evidence and reporting safely.
- Who can join and required knowledge
- Ages 9–13. No prior knowledge required. Direct enrolment with no admission assessment.
- Course schedule
- 8 weeks · 2 sessions per week · 75 minutes per session
- Guided learning
- 20 hours
What you will be able to do
- Spot common persuasion and phishing signals without depending on only one visual clue.
- Use safer gaming, chat and marketplace habits.
- Cross-check online claims, images and sources.
- Explain why AI-generated content can be convincing while still being incorrect or manipulated.
What the course covers
-
How scammers create urgency and trust — 2.5 hours
Fear, prizes, authority, friendship, urgency and the pause-check-tell method.
-
Phishing, fake links and QR-code traps — 2.5 hours
Checking senders, domains, shortened links, fake login pages and safe reporting.
-
Safe gaming and online communities — 2.5 hours
Voice and text chat, game trades, modifications, purchases, strangers and account recovery.
-
Browser, search and source verification — 2.5 hours
Search results, advertisements, source identity, supporting evidence, dates and context.
-
AI safety, deepfakes and safe prompting — 2.5 hours
AI-generated media, incorrect AI answers, prompt privacy and verification before sharing.
-
Marketplace and customer-support scams — 2.5 hours
Fake customer support, payment requests, OTPs, screen sharing and refund fraud.
-
Preserving evidence and reporting safely — 2.5 hours
Taking useful screenshots without spreading harmful material, blocking, reporting and involving trusted adults.
-
Digital-trust investigation — 2.5 hours
A controlled case combining messages, search results, images and account events.
Practical work and labs
- Controlled phishing-message investigation using fictional accounts.
- URL and domain inspection using mentor-prepared examples.
- Gaming trade and chat-safety simulations.
- Deepfake and context-verification worksheet with a final investigation board.
How your work will be assessed
Weekly detective notebook: 35%. Scenario decisions: 25%. Final digital-trust investigation and explanation: 40%.
October 2026 Launch Fee
₹4,800
GST will be charged additionally at the applicable rate.
Y3 Devices, Internet & Smart Technology Safety Lab Learn to check and improve the safety of devices, apps, downloads, home Wi-Fi and smart technology.
What this course is for
A hands-on defensive course that explains devices, apps, websites, downloads, home Wi-Fi and smart gadgets. Children learn what important settings do and practise making devices safer without touching real malware or third-party systems.
- Who can join and required knowledge
- Ages 10–14. No prior knowledge required. Direct enrolment with no admission assessment.
- Course schedule
- 8 weeks · 2 sessions per week · 90 minutes per session
- Guided learning
- 24 hours
What you will be able to do
- Review permissions, updates, screen locks, backups and download choices.
- Explain at a simple level how a browser reaches a website.
- Recognise unsafe files, USB behaviour and app sources.
- Draw and improve a home-network and smart-device safety map.
What the course covers
-
Device-security baseline — 3 hours
Screen locks, updates, backups, lost-device actions and safe use of shared devices.
-
Apps and permissions — 3 hours
Camera, microphone, contacts, location, notifications and allowing only necessary access.
-
Downloads, malware and USB safety — 3 hours
File sources, file extensions, security warnings, removable devices and controlled simulations.
-
Internet and website detectives — 3 hours
Routers, internet providers, DNS, addresses, browsers, servers and encrypted connections.
-
Browser-safety controls — 3 hours
Downloads, pop-ups, extensions, saved passwords, cookies and the limitations of private browsing.
-
Home Wi-Fi and guest access — 3 hours
Router administration, stronger Wi-Fi credentials, guest networks and update routines.
-
Smart-home and connected-device safety — 3 hours
Cameras, speakers, televisions and toys: default settings, collected data and safe device retirement.
-
Secure My Technology project — 3 hours
Audit a fictional household, prioritise security improvements and present a safer design.
Practical work and labs
- Practice-device security and permission audit.
- Safe and risky download classification with a controlled USB simulation.
- Physical packet-delivery model showing how browsers, DNS and servers communicate.
- Home-network diagram, guest-network plan and smart-device retirement checklist.
How your work will be assessed
Lab workbook: 45%. Safety-configuration check: 20%. Secure My Technology final project: 35%.
October 2026 Launch Fee
₹5,800
GST will be charged additionally at the applicable rate.
Y4 Codes, Encryption & Network Detectives Understand how encryption and networks work, then use controlled exercises to examine how information is protected and moved.
What this course is for
A practical introduction to how information is represented, protected and moved. Learners progress from classical ciphers to modern encryption, hashes, certificates, packets, IP addresses, DNS and ports using visual demonstrations and controlled labs.
- Who can join and required knowledge
- Ages 11–15. No prior knowledge required. Direct enrolment with no admission assessment.
- Course schedule
- 10 weeks · 2 sessions per week · 90 minutes per session
- Guided learning
- 30 hours
What you will be able to do
- Explain the differences between encoding, encryption and hashing.
- Explain shared keys, public and private keys, digital signatures and certificates at an age-appropriate level.
- Identify the purposes of IP addresses, DNS, TCP, UDP and common ports.
- Interpret a simplified packet capture and recommend a safer connection.
What the course covers
-
Data, bits and representation — 3 hours
Text, numbers, images, binary concepts, metadata and why representing information is not the same as protecting it.
-
Classical codes and ciphers — 3 hours
Substitution, Caesar and transposition ciphers, pattern weaknesses and ethical puzzle-solving.
-
Encoding, encryption and hashing — 3 hours
Their different purposes, reversible and one-way operations, and integrity checks.
-
Symmetric encryption — 3 hours
Shared secrets, key handling, nonces, initialisation vectors and the danger of reusing keys.
-
Public-key encryption — 3 hours
Key pairs, key exchange, digital signatures and establishing trust without first sharing a secret.
-
Certificates and HTTPS — 3 hours
Certificate authorities, browser indicators, the purpose of TLS and certificate warnings.
-
Packets, addresses and protocols — 3 hours
MAC and IP addresses, TCP, UDP and protocol purposes explained through a delivery analogy.
-
DNS, ports and services — 3 hours
Name resolution, common services and why unnecessary services create additional risk.
-
Network observation — 3 hours
Mentor-provided packet captures, filters, normal patterns and privacy boundaries.
-
Secure-message and network project — 3 hours
Design, demonstrate and explain a protected message path and basic network controls.
Practical work and labs
- Paper-based cipher attack and defence challenges.
- Hash-change and digital-signature demonstrations.
- Certificate inspection on approved websites.
- Controlled Wireshark capture filtering and network-mapping exercise.
How your work will be assessed
Concept checks: 20%. Lab portfolio: 40%. Secure-message and network final project: 40%.
October 2026 Launch Fee
₹7,500
GST will be charged additionally at the applicable rate.
Y5 Python, Linux & Defensive Cyber Challenge Write small Python programs, work safely in Linux and solve supervised defensive cybersecurity challenges.
What this course is for
The technical final course in the Young Cyber Explorers pathway. Learners write Python programs, use a safe Linux command line, solve defensive investigation challenges and understand cybersecurity ethics and career paths. The course is intentionally longer so beginners are not rushed.
- Who can join and required knowledge
- Ages 12–16. No prior knowledge required. Direct enrolment with no admission assessment. Both Python and Linux are taught from the beginning.
- Course schedule
- 16 weeks · 2 sessions per week · 90 minutes per session
- Guided learning
- 48 hours
What you will be able to do
- Write and test small Python programs using variables, decisions, loops, functions and files.
- Navigate Linux, manage files and understand users, permissions, processes and logs.
- Solve controlled defensive challenges using evidence and proper documentation.
- Explain authorisation, responsible security testing and several cybersecurity career paths.
What the course covers
-
Python foundations I — 6 hours
Values, variables, input, output, data types and safe debugging.
-
Python foundations II — 6 hours
Conditions, loops, functions and breaking a problem into smaller parts.
-
Python data and files — 6 hours
Lists, dictionaries, text files, CSV files and simple log processing.
-
Defensive Python mini-tools — 6 hours
Password-policy checker, hash comparison, indicator lookup from a local file and report generation.
-
Linux command-line foundations — 6 hours
Navigating the filesystem, viewing and searching text, pipes and safe command habits.
-
Linux users, permissions and processes — 6 hours
Accounts, groups, file permissions, processes, services and why privileges matter.
-
Defensive cybersecurity challenges — 6 hours
Log clues, file integrity, suspicious messages, network evidence and documented reasoning.
-
Ethics, careers and final challenge — 6 hours
Authorisation, acceptable use, cybersecurity careers, teamwork and a supervised defensive project.
Practical work and labs
- Python exercises and defensive mini-tools.
- Disposable Linux virtual machine using safe snapshots and no public targets.
- Local log, file and packet-evidence investigations.
- Team defensive challenge with an incident note and oral explanation.
How your work will be assessed
Coding and lab portfolio: 40%. Linux practical assessment: 20%. Final defensive challenge and explanation: 40%. Learners must follow all ethical-lab rules.
October 2026 Launch Fee
₹12,500
GST will be charged additionally at the applicable rate.
Cybersecurity Foundations Beginner-friendly courses that build the computer, network, operating-system, programming, cloud and security knowledge needed to progress.
Focused Foundation Courses
Shorter courses that build one important foundation skill with a complete practical outcome.
F-S1 Computer, Hardware & Operating System Fundamentals Understand how computers and operating systems work, manage essential settings and troubleshoot common problems safely.
What this course is for
This course is for learners who use computers but have never fully understood computer components, storage, operating systems, files, users, processes or troubleshooting. It helps learners understand the systems they will eventually protect instead of simply following security-tool instructions.
- Who can join and required knowledge
- Age 15+. Suitable for beginners, non-IT learners and career changers. No prerequisite or admission assessment is required.
- Course schedule
- 4 weeks · 2 sessions per week · 2 hours per session
- Guided learning
- 16 hours
What you will be able to do
- Identify the main hardware and operating-system components of a computer.
- Work confidently with files, users, applications and essential computer settings.
- Follow a disciplined troubleshooting and device-security checklist.
What the course covers
-
Computer components and data — 4 hours
CPU, memory, storage, firmware, peripherals, files and units of data.
-
Operating systems and applications — 4 hours
The purpose of an operating system, Windows, Linux and macOS concepts, software installation, updates and trusted software sources.
-
Files, users and processes — 4 hours
Paths, file extensions, user accounts, permission concepts, running processes and services.
-
Troubleshooting and security baseline — 4 hours
Backups, updates, endpoint protection, identifying the source of an error and preparing a device-health report.
Practical work and labs
- Identify computer components using a demonstration computer or visual component set.
- Create users and folders and inspect running processes on lab systems.
- Troubleshoot prepared computer problems and complete a security-baseline checklist.
How your work will be assessed
Two practical checkpoints: 40%. Device-health mini-project: 60%.
October 2026 Launch Fee
₹4,200
GST will be charged additionally at the applicable rate.
F-S2 Web, HTTP & Browser Foundations Understand how a browser communicates with a website and inspect requests, responses, cookies and certificates.
What this course is for
This course explains how web pages, browsers and servers communicate. Learners use browser-development tools to observe requests, responses, cookies and certificates before progressing to web or API security courses.
- Who can join and required knowledge
- Age 15+. Suitable for beginners and future web or API security learners. No prerequisite or admission assessment is required.
- Course schedule
- 5 weeks · 2 sessions per week · 2 hours per session
- Guided learning
- 20 hours
What you will be able to do
- Trace what happens from entering a website address to receiving the webpage.
- Read the essential parts of web requests, responses and status codes.
- Explain cookies, sessions, HTTPS and browser storage at a foundation level.
What the course covers
-
Web architecture and URLs — 4 hours
Browsers, servers, domains, DNS, URLs, hosting and static and dynamic content.
-
HTTP requests and responses — 4 hours
Methods, headers, message bodies, status codes, content types and redirects.
-
HTML, JavaScript and browser execution — 4 hours
Page structure, scripts, browser-development tools and the basic purpose of same-origin protections.
-
Cookies, sessions and browser storage — 4 hours
Session identifiers, local storage, browser cache and their privacy and security effects.
-
HTTPS and observation lab — 4 hours
The purpose of TLS, website certificates, the concept of an inspection proxy and documenting a complete web-request flow.
Practical work and labs
- Inspect a webpage using browser-development tools.
- Build and observe a simple webpage running locally.
- Create a cookie and session-flow diagram and observe an approved local proxy demonstration.
How your work will be assessed
Request-flow lab book: 50%. Final explanation and practical demonstration: 50%.
October 2026 Launch Fee
₹5,000
GST will be charged additionally at the applicable rate.
F-S3 Cryptography Foundations Understand when to use encryption, hashing, signatures and certificates and recognise unsafe security choices.
What this course is for
This course explains encoding, encryption, hashing, digital signatures, certificates and password storage through practical examples. It focuses on choosing and using established security methods correctly without requiring advanced mathematics.
- Who can join and required knowledge
- Age 15+. Suitable for technical and non-technical cybersecurity learners. No prerequisite or admission assessment is required. Only basic arithmetic is needed.
- Course schedule
- 5 weeks · 2 sessions per week · 2 hours per session
- Guided learning
- 20 hours
What you will be able to do
- Choose the correct protection method for confidentiality, integrity and authenticity.
- Explain symmetric encryption, asymmetric encryption, hashes, digital signatures and public-key infrastructure.
- Recognise dangerous encryption-design and key-management mistakes.
What the course covers
-
Purpose and terminology — 4 hours
Plaintext, ciphertext, keys, algorithms, threats and the different properties information may need.
-
Symmetric cryptography — 4 hours
Shared keys, block and stream concepts, modes, nonces, initialisation vectors and safe key handling.
-
Asymmetric cryptography — 4 hours
Public and private key pairs, key exchange, encryption and digital signatures.
-
Hashes, passwords and integrity — 4 hours
Hash properties, salts, password-strengthening functions, file integrity and unsafe password-storage practices.
-
Certificates, TLS and applied choices — 4 hours
Certificate trust chains, certificate-revocation concepts and choosing suitable protection for different situations.
Practical work and labs
- Encoding and encryption comparison demonstrations.
- Hashing, file-integrity and password-storage exercises using safe sample data.
- Certificate-chain inspection and a security-design review.
How your work will be assessed
Security-concept scenarios: 40%. Applied cryptography design review: 60%.
October 2026 Launch Fee
₹5,000
GST will be charged additionally at the applicable rate.
F-S4 Identity & Access Management Foundations Understand how organisations verify identity, grant access and remove access when it is no longer needed.
What this course is for
This course explains who should receive access, how identity is verified, what a user should be allowed to do and how access must change when someone joins an organisation, changes roles or leaves.
- Who can join and required knowledge
- Age 15+. Suitable for technical, operations, governance, risk and compliance learners. No prerequisite or admission assessment is required.
- Course schedule
- 4 weeks · 2 sessions per week · 2 hours per session
- Guided learning
- 16 hours
What you will be able to do
- Explain identification, authentication, authorisation and accountability.
- Apply multi-factor authentication, least privilege, role-based access and identity-lifecycle concepts.
- Review a simple access table and identify users who have unnecessary access.
What the course covers
-
Identity and access concepts — 4 hours
Human identities, devices, automated identities, authentication, authorisation and audit records.
-
Authentication and multi-factor authentication — 4 hours
Password risks, authentication factors, account recovery, phishing-resistant methods and access decisions based on risk.
-
Authorisation and least privilege — 4 hours
Role-based access, attribute-based access, separation of duties and service accounts.
-
Identity lifecycle and governance — 4 hours
Joining, changing roles and leaving, access requests, access reviews, single sign-on, federation and access tables.
Practical work and labs
- Multi-factor authentication and account-recovery scenario analysis.
- Map job roles to the permissions they require.
- Create a joiner, role-change and leaver workflow and complete an access-review exercise.
How your work will be assessed
Access-design exercises: 50%. Final access review and oral explanation: 50%.
October 2026 Launch Fee
₹4,500
GST will be charged additionally at the applicable rate.
F-S5 Cyber Law, Privacy, Governance & Ethics Learn how to work within permission, privacy, cyber-law and professional-ethics boundaries.
What this course is for
This course explains authorisation, responsible security testing, Indian cyber-law and privacy concepts, governance responsibilities, evidence preservation and honest professional conduct. The legal portion of the course will be reviewed regularly so it remains current.
- Who can join and required knowledge
- Age 15+. Suitable for learners entering any cybersecurity pathway. No prerequisite or admission assessment is required.
- Course schedule
- 4 weeks · 2 sessions per week · 2 hours per session
- Guided learning
- 16 hours
What you will be able to do
- Know when written authorisation is required and what an approved testing scope must contain.
- Recognise important Indian privacy, cybercrime and incident-reporting considerations.
- Apply ethical decision-making, responsible disclosure and basic security-governance responsibilities.
What the course covers
-
Authority, permission, scope and ethics — 4 hours
Permission, testing boundaries, rules of engagement, conflicts, confidentiality and responsible disclosure.
-
Indian cyber-law foundations — 4 hours
Important Information Technology Act concepts, unauthorised access, cybercrime reporting and evidence basics.
-
Privacy and data protection — 4 hours
Personal data, purpose, minimum necessary collection, retention, children’s data and data-breach response.
-
Governance and professional conduct — 4 hours
Policies, responsibilities, third parties, incident escalation, documentation and ethical decision-making.
Practical work and labs
- Draft a plain-language security-testing rules document.
- Classify privacy situations and identify the correct evidence-handling steps.
- Participate in a controlled ethical-review exercise.
How your work will be assessed
Scenario analysis: 50%. Written rules document and ethical decision explanation: 50%.
October 2026 Launch Fee
₹4,000
GST will be charged additionally at the applicable rate.
Comprehensive Foundation Programmes
Longer programmes for learners who want deeper preparation and sustained practical work.
F-L1 Cybersecurity Essentials & Career Foundations Build a complete beginner-level understanding of cybersecurity, common threats, essential controls and career directions.
What this course is for
A complete introduction to cybersecurity covering valuable information and systems, threats, vulnerabilities, security controls, risk, incident response, professional ethics and realistic career paths. It helps learners understand the field before choosing a technical or governance pathway.
- Who can join and required knowledge
- Age 15+. Suitable for complete beginners and learners exploring a cybersecurity career. No prerequisite or admission assessment is required.
- Course schedule
- 8 weeks · 2 sessions per week · 2 hours per session
- Guided learning
- 32 hours
What you will be able to do
- Correctly explain assets, threats, vulnerabilities, controls and risk.
- Explain essential protections for identities, networks, devices, applications, cloud systems, data and people.
- Examine simple security incidents and create a realistic cybersecurity learning and career plan.
What the course covers
-
Security mindset and valuable assets — 4 hours
Information, systems, people, confidentiality, integrity, availability and business impact.
-
Threats, vulnerabilities and attack paths — 4 hours
Attackers, motives, exposure, social engineering and common stages of an attack.
-
Risk and selecting security controls — 4 hours
Likelihood, impact, preventive controls, detective controls, corrective controls and remaining risk.
-
Identity, cryptography and data — 4 hours
Access control, multi-factor authentication, encryption, data classification and safe data handling.
-
Network, device and application security — 4 hours
Layered security, system hardening, updates and secure-development concepts.
-
Cloud, mobile and third-party risk — 4 hours
Cloud responsibility, online services, suppliers and personal-device risks.
-
Detection and incident response — 4 hours
Events, alerts, initial investigation, containment, recovery and learning from incidents.
-
Ethics, careers and final security plan — 4 hours
Authorisation, cybersecurity job families, learning portfolios, certifications and a final security-improvement plan.
Practical work and labs
- Create a threat model for a small business.
- Complete security-control mapping and incident-response exercises.
- Prepare a personal, household or small-business security-improvement plan.
How your work will be assessed
Module checks: 25%. Practical exercises: 35%. Final security plan and career-path explanation: 40%.
October 2026 Launch Fee
₹7,500
GST will be charged additionally at the applicable rate.
F-L2 Networks & the Internet for Security Build, explain, troubleshoot and secure a working computer network instead of simply memorising network terms.
What this course is for
A from-the-beginning networking programme created for cybersecurity learners. Students calculate, configure, capture and troubleshoot network traffic. The programme provides sufficient practice with addressing, routing and packet analysis instead of rushing through these subjects.
- Who can join and required knowledge
- Age 15+. Suitable for beginners preparing for security operations, security testing, cloud security or identity security. No prerequisite or admission assessment is required.
- Course schedule
- 12 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 72 hours
What you will be able to do
- Design and troubleshoot a small routed network.
- Explain Ethernet, IP addressing, TCP, UDP, DNS, DHCP, web traffic, encrypted connections and VPN behaviour.
- Capture and explain normal network traffic and apply basic firewall and network-separation controls.
What the course covers
-
Network models, media and frames — 6 hours
Network layers, local and wide-area networks, Ethernet, MAC addresses and switching.
-
IPv4 addressing — 8 hours
Binary concepts, subnet masks, CIDR notation, private and public addresses and subnet calculation.
-
Routing and address translation — 6 hours
Gateways, routing tables, routing concepts and network-address translation.
-
ARP, ICMP and network troubleshooting — 6 hours
Neighbour discovery, ping, traceroute and command-line troubleshooting.
-
TCP, UDP and ports — 8 hours
Network connections, reliability, handshakes, sessions and common services.
-
DNS and DHCP — 6 hours
Name resolution, DNS records, address leases and common security and reliability problems.
-
Web, email and encrypted traffic — 6 hours
HTTP, HTTPS, email concepts, certificate flow and the visibility limitations of encrypted traffic.
-
Wireless networks, VPNs and remote access — 6 hours
Wi-Fi security, encrypted tunnels and safer remote connections.
-
Firewalls and network separation — 6 hours
Connection state, access rules, security zones, blocking by default and firewall logging.
-
Packet capture and traffic analysis — 8 hours
Wireshark filters, network conversations, normal patterns and identifying unusual behaviour.
-
Secure-network final project — 6 hours
Build, document, test and defend a small-business network design.
Practical work and labs
- Build working networks using Packet Tracer or an equivalent lab platform.
- Complete subnetting exercises connected to practical network designs.
- Capture and examine authorised lab traffic using Wireshark.
- Design firewall rules and network separation and troubleshoot prepared problems.
How your work will be assessed
Practical lab work: 45%. Two timed troubleshooting checks: 20%. Secure-network final project: 35%.
October 2026 Launch Fee
₹17,500
GST will be charged additionally at the applicable rate.
F-L3 Windows & Linux Operating Systems for Cybersecurity Use, administer and harden Windows and Linux systems and examine their processes, services, permissions and logs.
What this course is for
One combined operating-systems programme because cybersecurity professionals regularly work with evidence from both Windows and Linux. Learners study administration, users, permissions, processes, services, networking, logs, basic scripting and system hardening on both platforms.
- Who can join and required knowledge
- Age 15+. Suitable for beginners preparing for security operations, testing, cloud security, identity security or DevSecOps. No prerequisite or admission assessment is required. Both operating systems are taught from the beginning.
- Course schedule
- 14 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 84 hours
What you will be able to do
- Administer users, files, permissions, processes, services and networking in Windows and Linux.
- Find and understand important system and security logs.
- Apply and verify essential security-hardening controls on both operating systems.
What the course covers
-
Lab preparation and operating-system architecture — 6 hours
Virtual machines, snapshots, kernels, filesystems and safe administration.
-
Linux filesystem and command line — 8 hours
Paths, files, help commands, text-processing tools, pipes and redirection.
-
Linux users and permissions — 8 hours
Accounts, groups, administrative access, file permissions, ownership and access reviews.
-
Linux processes, services and software — 8 hours
Processes, services, software packages, scheduled tasks and recognising persistence.
-
Linux networking, logs and hardening — 10 hours
Interfaces, network connections, system logs, firewall controls, SSH and security baselines.
-
Windows architecture and administration — 8 hours
Filesystem, registry concepts, services, Task Manager and essential administration tools.
-
Windows users and permissions — 8 hours
Local and domain concepts, groups, file permissions, User Account Control and access reviews.
-
PowerShell and Windows administration — 8 hours
PowerShell objects, pipelines, files, processes, services and safe automation basics.
-
Windows logs, networking and hardening — 10 hours
Event logs, endpoint protection, firewall controls, remote access and security baselines.
-
Cross-platform final project — 10 hours
Investigate, harden and document one Windows system and one Linux system.
Practical work and labs
- Use disposable Windows and Linux virtual machines.
- Complete permission and service troubleshooting exercises.
- Perform Bash and PowerShell administration tasks.
- Investigate Windows and Linux logs and complete a two-system hardening project.
How your work will be assessed
Weekly practical checks: 30%. Linux practical assessment: 20%. Windows practical assessment: 20%. Cross-platform final project: 30%.
October 2026 Launch Fee
₹20,500
GST will be charged additionally at the applicable rate.
F-L4 Python Programming & Secure Coding Foundations Learn Python from the beginning and finish by building, testing and explaining a securely written Python application.
What this course is for
A complete beginner-to-secure-programmer pathway rather than a short introduction to Python syntax. Learners first build programming ability and then work with files, APIs, testing and Git before learning input validation, authentication, secrets management, safe use of cryptography, logging, dependency security and secure application design.
- Who can join and required knowledge
- Age 15+. Suitable for beginners preparing for security automation, application security, DevSecOps or secure code review. No prerequisite or admission assessment is required. Python is taught from the beginning.
- Course schedule
- 20 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 120 hours
What you will be able to do
- Design, write, debug and test readable Python programs.
- Work with files, structured data, web APIs and version control.
- Identify and correct common secure-coding mistakes.
- Build, test and explain a small security-focused Python application.
What the course covers
-
Programming foundations — 12 hours
Data types, expressions, input, output, conditions and debugging.
-
Loops, functions and problem-solving — 12 hours
Iteration, functions, variable scope and breaking a problem into smaller steps.
-
Collections and text processing — 12 hours
Lists, dictionaries, sets, strings and processing structured and unstructured text.
-
Files, errors and reusable modules — 12 hours
Text, CSV and JSON files, error handling, reusable code and program environments.
-
Object-oriented and data-modelling basics — 8 hours
Classes where appropriate, data classes and maintainable program structure.
-
Web APIs and security automation — 12 hours
Web requests, JSON, authentication concepts, timeouts and safer automation.
-
Testing, Git and code quality — 12 hours
Unit testing, code checking, commits, branches and peer review.
-
Input validation and injection prevention — 12 hours
Trust boundaries, allowlists, SQL injection, command injection and safer programming interfaces.
-
Authentication, sessions and authorisation — 8 hours
Password storage, session concepts, access checks and common security mistakes.
-
Secrets, cryptography, logging and errors — 8 hours
Configuration, safe storage of keys and tokens, established cryptographic libraries, safe logs and secure error handling.
-
Dependencies and secure delivery — 6 hours
Virtual environments, fixed dependency versions, vulnerability checks and release integrity.
-
Secure Python application project — 6 hours
Build, test, review, correct and present a small Python application, service or security utility.
Practical work and labs
- Complete regular graded programming exercises.
- Build a log-processing program and an API client.
- Create a local database application using parameterised queries.
- Complete peer code review, dependency analysis and a secure Python final project.
How your work will be assessed
Programming portfolio: 35%. Two practical programming assessments: 20%. Secure-code review and correction: 15%. Final secure application project: 30%.
October 2026 Launch Fee
₹28,000
GST will be charged additionally at the applicable rate.
F-L5 Cloud Computing & Cloud Security Foundations Understand how cloud systems are built and practise securing cloud identities, networks, data and services.
What this course is for
A from-the-beginning cloud programme using Microsoft Azure as the main lab platform while teaching concepts that also apply to other cloud providers. Learners deploy basic resources and then secure cloud identities, networks, data, secrets, logs, configurations and recovery processes.
- Who can join and required knowledge
- Age 15+. Suitable for beginners preparing for cloud operations, identity security or DevSecOps. No prerequisite or admission assessment is required. The necessary networking and identity concepts are introduced in the programme.
- Course schedule
- 14 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 84 hours
What you will be able to do
- Explain cloud-service models, deployment models and shared security responsibilities.
- Deploy and secure basic cloud identity, computing, network and storage resources.
- Collect cloud logs, examine security configurations and respond to a simple cloud incident.
What the course covers
-
Cloud concepts, services and costs — 6 hours
Infrastructure, platform and software services, regions, availability, subscriptions and shared responsibility.
-
Cloud identity — 8 hours
Users, groups, roles, automated identities, multi-factor authentication and least privilege.
-
Cloud virtual networks — 10 hours
Addressing, subnets, routes, security groups, firewalls and private access.
-
Computing and managed services — 8 hours
Virtual machines, managed services, serverless concepts and update responsibilities.
-
Storage, databases and data protection — 10 hours
Access control, encryption, public exposure, backups and data lifecycle.
-
Keys, secrets and certificates — 6 hours
Secure vaults, rotation and safe access for applications and automated services.
-
Cloud logging and monitoring — 10 hours
Activity, identity, network and application logs and basic alerts.
-
Security configuration and vulnerability management — 8 hours
Configuration assessment, security recommendations, patching and documented exceptions.
-
Recovery and cloud-incident response — 8 hours
Backup, restoration, isolation, credential resets and preserving evidence.
-
Secure-cloud final project — 10 hours
Deploy, harden, monitor and document a small cloud environment.
Practical work and labs
- Use a guided cloud sandbox with controlled spending limits.
- Configure cloud identities and network-security controls.
- Find and correct an unsafe cloud-storage configuration.
- Examine cloud logs and complete a secure-cloud deployment project.
How your work will be assessed
Cloud lab work: 45%. Configuration practical assessments: 20%. Secure-cloud final project: 35%.
October 2026 Launch Fee
₹22,000
GST will be charged additionally at the applicable rate.
F-L6 Logs, SIEM & Security Monitoring Foundations Collect, search and understand security logs, create useful alerts and complete a guided investigation.
What this course is for
A practical introduction to security monitoring. Learners understand what logs contain, how logs are collected and organised, how analysts search them and how alerts become investigation cases. The programme develops investigation ability instead of teaching only how to navigate dashboards.
- Who can join and required knowledge
- Age 15+. Suitable for beginners preparing for security-operations and security-monitoring courses. No prerequisite or admission assessment is required. Log analysis is taught from the beginning.
- Course schedule
- 12 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 72 hours
What you will be able to do
- Read important fields in Windows, Linux, network, web, identity and cloud logs.
- Import, search and visualise security data using an open or trial security-monitoring platform.
- Investigate a simple alert and write a case note suitable for escalation.
What the course covers
-
Events, logs and time — 6 hours
Log sources, timestamps, time zones, severity, event identifiers and protecting log integrity.
-
Windows and Linux logs — 8 hours
Authentication, processes, services and security-audit events.
-
Network, DNS, firewall and proxy logs — 8 hours
Connections, firewall actions, names, website addresses and normal behaviour.
-
Web, application and identity logs — 6 hours
Requests, errors, sessions, sign-in activity and access events.
-
Cloud and online-service logs — 6 hours
Administrative activity, identity events and cloud-service logs.
-
Log collection and organisation — 8 hours
Agents, syslog, APIs, parsing, common data formats, retention and data-quality problems.
-
Security search and query foundations — 10 hours
Filtering, grouping, combining related information and writing reliable queries.
-
Dashboards and normal behaviour — 6 hours
Useful measurements, normal patterns and recognising misleading charts.
-
Alerts, initial investigation and case notes — 8 hours
Alert rules, false positives, additional evidence, severity and escalation.
-
Security-monitoring final project — 6 hours
Import a small dataset, create one alert and investigate a prepared security event.
Practical work and labs
- Identify and compare different log sources.
- Import and search safe datasets using a security-monitoring platform.
- Review dashboards and improve an unreliable alert.
- Investigate a prepared event and write a professional case note.
How your work will be assessed
Search-query and lab portfolio: 45%. Alert-investigation practical: 20%. Security-monitoring final project: 35%.
October 2026 Launch Fee
₹18,000
GST will be charged additionally at the applicable rate.
Security Practitioner Core Bridge courses that turn foundation knowledge into the practical working ability required for advanced cybersecurity training.
P1 Cyber Lab Readiness & Professional Workflow Bootcamp Set up and use a safe cybersecurity lab while following professional documentation, evidence and authorisation practices.
What this course is for
A short safety and workflow course for learners who understand cybersecurity concepts but have not worked inside a controlled cyber lab. It develops safe testing habits before the learner enters advanced practical courses.
- Who can join and required knowledge
- Age 16+. Requires F-S1 and F-L1, or equivalent skills confirmed through a practical starting-point assessment.
- Course schedule
- 4 weeks · 2 sessions per week · 2 hours per session
- Guided learning
- 16 hours
What you will be able to do
- Create, isolate, snapshot and restore lab virtual machines.
- Use command-line help, organise evidence and maintain a repeatable lab notebook.
- Apply authorisation, testing scope and data-handling rules before beginning any security exercise.
What the course covers
-
Authorised lab design — 4 hours
Testing scope, acceptable use, isolated networks, ownership of targets and safe data handling.
-
Virtual machines and snapshots — 4 hours
Virtual-machine images, system resources, isolated networking, restoration and troubleshooting.
-
Professional commands and evidence workflow — 4 hours
Command-line help, file transfers, hashing, screenshots, timestamps and professional notes.
-
Repeatable mini-investigation — 4 hours
Prepare the lab, perform the exercise, record the work, clean the environment and submit a defensible evidence package.
Practical work and labs
- Build an isolated two-virtual-machine laboratory.
- Practise snapshots, restoration and connectivity troubleshooting.
- Create an evidence folder, command log and repeatability checklist.
How your work will be assessed
Safety assessment: 20%. Lab-setup practical: 30%. Repeatable mini-investigation: 50%.
October 2026 Launch Fee
₹5,000
GST will be charged additionally at the applicable rate.
P2 Web Applications, APIs & SQL Foundations Understand how web applications, APIs and databases work well enough to test and review them responsibly.
What this course is for
This course teaches how modern web applications and APIs work before learners begin testing their security. Database and SQL knowledge is included so learners can understand how information enters, moves through and is stored by an application.
- Who can join and required knowledge
- Age 16+. Requires F-S2 Web, HTTP & Browser Foundations, or equivalent skills confirmed through a practical starting-point assessment. F-L2 Networks is strongly recommended.
- Course schedule
- 10 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 60 hours
What you will be able to do
- Build and trace the operation of a small web application and API.
- Work with web requests, forms, sessions, JSON, REST and SQL queries.
- Explain trust boundaries, user-input paths and access-control decisions.
What the course covers
-
Application architecture — 6 hours
Browsers, user interfaces, servers, databases, supporting services and trust boundaries.
-
HTML, forms and JavaScript behaviour — 6 hours
User inputs, webpage events, requests and the responsibilities of browsers and servers.
-
Server-side request handling — 6 hours
Routes, parameters, input validation and generating responses.
-
Sessions and authentication flow — 6 hours
Cookies, tokens, login, logout, session state and access checks.
-
REST and JSON APIs — 8 hours
Resources, request methods, status codes, data structures and safe error handling.
-
API authentication concepts — 6 hours
API keys, bearer tokens, OAuth and OpenID Connect orientation, and safe token storage.
-
SQL and relational databases — 10 hours
Tables, keys, creating and changing records, joins, parameters and transactions.
-
Logging, errors and safer application design — 6 hours
Useful application logs, safe failures, secret values and software-dependency awareness.
-
Application-mapping final project — 6 hours
Build or inspect an application and document its components, data movement and trust boundaries.
Practical work and labs
- Complete exercises using a local web application and API.
- Observe application behaviour using browser-development tools and an approved proxy.
- Complete SQLite or PostgreSQL query exercises using parameterised code.
- Produce a data-flow and trust-boundary application map.
How your work will be assessed
Application-building and observation labs: 45%. SQL and API practical: 20%. Application map and demonstration: 35%.
October 2026 Launch Fee
₹16,000
GST will be charged additionally at the applicable rate.
P3 Vulnerability Assessment & Professional Reporting Carry out an authorised vulnerability assessment and turn the findings into a clear professional report.
What this course is for
This course provides the assessment and reporting method required before entering LTE security-testing pathways. Learners discover systems, safely verify vulnerabilities, assess risk, preserve evidence, recommend practical corrections and write reports that technical teams and managers can use.
- Who can join and required knowledge
- Age 17+. Requires F-L2 Networks, F-L3 Windows & Linux Operating Systems and P1 Lab Readiness, or equivalent skills confirmed through a combined practical starting-point assessment.
- Course schedule
- 10 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 60 hours
What you will be able to do
- Plan an authorised security assessment and remain within its approved scope.
- Run and verify discovery and vulnerability checks without treating automated results as automatically correct.
- Prioritise findings and produce repeatable evidence and practical correction guidance.
- Deliver management and technical reports and verify completed corrections.
What the course covers
-
Rules of engagement and assessment method — 6 hours
Objectives, systems, testing scope, timing, contacts, stop conditions and clean-up.
-
System discovery and attack-surface inventory — 6 hours
Hosts, services, applications, software versions, ownership and supporting evidence.
-
Vulnerability information and scanning — 8 hours
Security advisories, vulnerability identifiers, severity concepts, authenticated and unauthenticated scans and tool limitations.
-
Manual verification of findings — 8 hours
Reproducing results, identifying false positives, understanding the environment and producing safe proof.
-
Risk and prioritisation — 6 hours
Severity, likelihood, exposure, exploitability, organisational impact and existing protections.
-
Evidence and repeatability — 6 hours
Screenshots, web requests, commands, timestamps, minimum necessary data and clear reasoning.
-
Correction guidance and retesting — 6 hours
Root causes, practical corrections, verification and closure requirements.
-
Professional security-report writing — 8 hours
Management summary, scope, method, findings, limitations and technical supporting information.
-
Authorised assessment final project — 6 hours
Assess a controlled multi-service target and present a defensible professional report.
Practical work and labs
- Prepare a security-testing rules-of-engagement document.
- Perform network, service and local-application scanning inside an isolated environment.
- Verify false positives and review the quality of collected evidence.
- Prepare a complete report, deliver a client-style presentation and write a retest note.
How your work will be assessed
Lab and evidence portfolio: 35%. Individual finding write-ups: 25%. Final authorised assessment report and presentation: 40%.
October 2026 Launch Fee
₹18,500
GST will be charged additionally at the applicable rate.
P4 Cyber Defence Operations Core Investigate security alerts, decide what needs attention and document the response as a defence professional would.
What this course is for
This course moves learners from searching logs to performing practical defensive-security work. Learners verify alerts, connect evidence from devices, networks and identities, assign severity, make safe containment decisions and document their work using repeatable procedures.
- Who can join and required knowledge
- Age 17+. Requires F-L2 Networks, F-L3 Windows & Linux Operating Systems and F-L6 Logs, SIEM & Security Monitoring, or equivalent skills confirmed through a combined practical starting-point assessment.
- Course schedule
- 10 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 60 hours
What you will be able to do
- Follow a complete alert-to-investigation workflow.
- Connect evidence from devices, networks, email and identity systems.
- Map suspicious behaviour, recommend containment and write a case suitable for escalation.
What the course covers
-
Security-operations workflow and case quality — 6 hours
Alert queues, priorities, response targets, escalation, handover and documentation.
-
Device-security information — 8 hours
Processes, related processes, persistence, files and user context.
-
Network and DNS evidence — 8 hours
Connections, domains, protocols, normal behaviour and suspicious patterns.
-
Email and phishing investigation — 6 hours
Email headers, links, attachments, sender infrastructure and affected users.
-
Identity and cloud sign-in activity — 6 hours
Failed access, multi-factor authentication, location, device context and risky sign-in patterns.
-
Threat information and behaviour mapping — 6 hours
Indicators, attacker behaviour, confidence levels, evidence enrichment and MITRE ATT&CK orientation.
-
Containment and evidence preservation — 6 hours
Device, account and network containment, required approvals and possible side effects.
-
Improving detection and response procedures — 6 hours
Root causes, false positives, alert improvement and lessons learned.
-
Defensive-security final project — 8 hours
Complete a multi-stage incident exercise involving investigation, escalation, containment and explanation.
Practical work and labs
- Complete device, network and email investigation exercises.
- Perform behaviour mapping and evidence-enrichment exercises.
- Use a simulated case-management workflow and containment-decision table.
- Complete a timed defensive-security shift simulation.
How your work will be assessed
Investigation-case portfolio: 35%. Two alert-investigation practicals: 25%. Defensive-security final project: 40%.
October 2026 Launch Fee
₹17,500
GST will be charged additionally at the applicable rate.
P5 Cloud Administration & Automation Lab Administer cloud resources and use scripts and templates to perform repeatable cloud tasks safely.
What this course is for
This course prepares learners to operate cloud resources through both a management portal and command or API workflows before they enter advanced cloud-security training. Microsoft Azure is used as the primary lab platform while the underlying concepts remain applicable elsewhere.
- Who can join and required knowledge
- Age 17+. Requires F-L5 Cloud Computing & Cloud Security, F-L2 Networks and F-S4 Identity & Access Management, or equivalent skills confirmed through a cloud-focused practical starting-point assessment.
- Course schedule
- 10 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 60 hours
What you will be able to do
- Administer cloud identities, networks, computing, storage and logs.
- Use command-line tools, PowerShell or templates to create repeatable cloud configurations.
- Troubleshoot access and connectivity while controlling spending and preserving useful evidence.
What the course covers
-
Cloud account and resource organisation — 6 hours
Accounts, subscriptions, resource groups, naming, tags and cost controls.
-
Cloud-identity administration — 8 hours
Users, groups, roles, automated identities and testing access.
-
Cloud-network administration — 8 hours
Virtual networks, subnets, routes, network-security groups, DNS and private access.
-
Computing and platform operations — 6 hours
Virtual-machine lifecycle, system images, updates and managed services.
-
Storage and data services — 6 hours
Access models, encryption, data lifecycle and backup.
-
Command line, PowerShell and templates — 10 hours
Authentication, repeatable commands, variables, outputs and safer automation.
-
Logging and monitoring operations — 6 hours
Enable log sources, search administrative activity and create a basic alert.
-
Troubleshooting and recovery — 4 hours
Access, networking, service limits, spending and restoration problems.
-
Cloud-automation final project — 6 hours
Deploy and document a repeatable, monitored cloud environment.
Practical work and labs
- Administer resources inside a controlled cloud sandbox.
- Create cloud deployments using command-line tools or PowerShell.
- Complete cloud-identity and networking troubleshooting exercises.
- Build an automated and monitored cloud environment.
How your work will be assessed
Cloud-administration labs: 45%. Troubleshooting practical: 20%. Cloud-automation final project: 35%.
October 2026 Launch Fee
₹20,000
GST will be charged additionally at the applicable rate.
P6 Enterprise Identity & Directory Services Manage organisational users, groups, permissions and identity lifecycles using directory-service concepts and labs.
What this course is for
This course moves learners from identity-security terminology to operating an organisational directory. Learners manage users, groups, policies, sign-on concepts, automated identities, audit records and processes for people joining, changing roles and leaving.
- Who can join and required knowledge
- Age 17+. Requires F-S4 Identity & Access Management, F-L3 Windows & Linux Operating Systems and F-L2 Networks, or equivalent skills confirmed through an identity-focused practical starting-point assessment.
- Course schedule
- 8 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 48 hours
What you will be able to do
- Administer users, groups, roles and policies inside a directory laboratory.
- Trace authentication and single-sign-on flows and troubleshoot common failures.
- Implement identity-lifecycle and access-review controls with usable evidence.
What the course covers
-
Directory architecture — 6 hours
Domains, tenants, objects, attributes, groups, synchronisation concepts and trust.
-
Users, groups and delegated administration — 6 hours
Creating accounts, group strategy, role assignment and administrator boundaries.
-
Authentication and access policy — 6 hours
Passwords, multi-factor authentication, conditional-access concepts, device and user context and recovery.
-
Single sign-on and federation foundations — 8 hours
Kerberos orientation, SAML, OAuth, OpenID Connect and examining tokens and claims.
-
Service and automated identities — 6 hours
Service accounts, managed identities, secrets, certificates and ownership.
-
Identity lifecycle and provisioning — 6 hours
Joining, role changes, leaving, approvals, automation and removing access.
-
Audit, access review and incident response — 6 hours
Identity logs, outdated access, privileged changes and containing identity incidents.
-
Identity-operations final project — 4 hours
Implement and explain a small organisation’s identity design.
Practical work and labs
- Administer users, groups and other directory objects.
- Examine sign-in logs, tokens and identity claims.
- Build an identity lifecycle and access-review workflow.
- Complete an identity-operations final project.
How your work will be assessed
Identity laboratory work: 45%. Troubleshooting and lifecycle practical: 20%. Identity-operations final project: 35%.
October 2026 Launch Fee
₹15,000
GST will be charged additionally at the applicable rate.
P7 Git, DevOps, Containers & CI/CD Foundations Use Git, automated delivery pipelines and containers and understand how modern software moves from code to deployment.
What this course is for
This course explains collaborative source control, automated building and testing, software packages, containers, registries, infrastructure-as-code concepts and delivery pipelines. Security concepts are introduced here before the learner progresses to advanced DevSecOps training.
- Who can join and required knowledge
- Age 17+. Requires F-L3 Windows & Linux Operating Systems and F-L4 Python Programming & Secure Coding, or equivalent skills confirmed through a coding-and-Linux practical starting-point assessment.
- Course schedule
- 12 weeks · 3 sessions per week · 2 hours per session
- Guided learning
- 72 hours
What you will be able to do
- Use Git branches, code reviews and recovery features safely.
- Build, test and package a small service through an automated delivery pipeline.
- Build, run and troubleshoot containers and explain essential Kubernetes objects.
- Identify where security checks and approvals belong inside software delivery.
What the course covers
-
Software-delivery lifecycle — 6 hours
Source code, building, testing, packaging, releases, deployment and operation.
-
Git foundations — 8 hours
Commits, branches, merges, remote repositories, ignored files and recovery.
-
Collaborative development workflow — 6 hours
Pull requests, reviews, version tags, releases and protected branches.
-
Automated building, testing and packaging — 8 hours
Dependencies, unit tests, build outputs and creating repeatable builds.
-
Automated delivery-pipeline foundations — 10 hours
Jobs, agents, variables, secrets, stages and approvals.
-
Container foundations — 10 hours
Images, layers, Dockerfiles, storage volumes, container networks and registries.
-
Kubernetes orientation — 8 hours
Pods, deployments, services, configurations, namespaces and essential commands.
-
Infrastructure-as-code concepts — 6 hours
Declarative configuration, proposed changes, variables and reviewing changes.
-
Monitoring and release operations — 4 hours
Logs, measurements, rollback and learning from incidents.
-
Software-delivery final project — 6 hours
Version, test, containerise and deploy a small service through an automated pipeline.
Practical work and labs
- Resolve Git conflicts and recover prepared repository problems.
- Build an automated pipeline with tests and stored build outputs.
- Complete container-building, networking and storage exercises.
- Deploy a local Kubernetes application and complete the software-delivery project.
How your work will be assessed
Development-workflow labs: 45%. Git and container practical: 20%. Software-delivery final project: 35%.
October 2026 Launch Fee
₹20,000
GST will be charged additionally at the applicable rate.
P8 Risk, Controls & Audit Preparation Turn organisational and technology risks into controls, evidence and documents that can support a security audit.
What this course is for
This course turns governance language into practical work involving valuable assets, risks, security controls, evidence and findings. It prepares learners who prefer non-coding cybersecurity work for advanced risk, compliance and security-audit training.
- Who can join and required knowledge
- Age 17+. Requires F-L1 Cybersecurity Essentials and F-S5 Cyber Law, Privacy, Governance & Ethics, or equivalent knowledge confirmed through a case-based starting-point assessment.
- Course schedule
- 8 weeks · 2 sessions per week · 2.5 hours per session
- Guided learning
- 40 hours
What you will be able to do
- Build a properly scoped risk register and explain the selected treatment decisions.
- Turn requirements into security controls that can be tested and supported with evidence.
- Interview a control owner and write a fair finding based on the available evidence.
What the course covers
-
Governance, scope and accountability — 5 hours
Objectives, responsibilities, policies, valuable assets and organisational boundaries.
-
Risk identification and analysis — 5 hours
Threats, vulnerabilities, likelihood, impact and writing clear risk statements.
-
Risk treatment and acceptance — 5 hours
Reducing, transferring, avoiding and accepting risks, assigning owners and tracking actions.
-
Security controls and frameworks — 5 hours
Preventive, detective and corrective controls and mapping between common frameworks.
-
Evidence and control testing — 5 hours
Control design, whether controls operate correctly, selecting samples and maintaining traceability.
-
Third-party and privacy risk — 5 hours
Supplier checks, contracts, personal information and ongoing monitoring.
-
Findings and corrective actions — 5 hours
Current condition, expected requirement, cause, effect, recommendation and management response.
-
Mini-audit final project — 5 hours
Plan, test, report and close a small security-control review.
Practical work and labs
- Write risk statements and build a risk register.
- Map security controls to required evidence.
- Conduct a simulated interview and test prepared evidence samples.
- Prepare a mini-audit report and conduct a closing meeting.
How your work will be assessed
Risk and control exercises: 30%. Evidence-testing practical: 25%. Mini-audit final project: 45%.
October 2026 Launch Fee
₹12,000
GST will be charged additionally at the applicable rate.
Advanced Cybersecurity Pathways Specialised, lab-led courses for learners who already have the required foundation and practitioner skills.
A1 Web Application Security Testing Plan and perform an authorised web-application security assessment and produce evidence-based findings.
What this course is for
Learn a structured method for testing web applications safely and legally. You will identify vulnerabilities, confirm their impact, explain their cause, recommend practical fixes and prepare a professional security report instead of merely running an automated scanner.
- Who can join and required knowledge
- Age 18+. Required knowledge: P3 Vulnerability Assessment & Professional Reporting, P2 Web Applications, APIs & SQL Foundations, F-L2 Networks & the Internet for Security and F-L3 Windows & Linux Operating Systems for Cybersecurity—or equivalent skills confirmed through a practical starting-point assessment.
- Course schedule
- 12 weeks; 3 sessions/week × 2 hours
- Guided learning
- 72 hours
What you will be able to do
- Test authentication, sessions, access control, input handling and business logic in an isolated environment.
- Use proxy-assisted manual testing and collect clear, reproducible evidence.
- Prioritise vulnerabilities and explain their business and technical impact.
- Recommend practical fixes and verify that vulnerabilities have been corrected.
- Complete an authorised web-application security assessment and professional report.
What the course covers
-
Scope, mapping and test strategy (6 hours)
Rules of engagement, content discovery, technology mapping and attack-surface inventory.
-
Authentication and account recovery (6 hours)
Login controls, multi-factor authentication, password resets and account-enumeration risks.
-
Session management (6 hours)
Cookies, tokens, session fixation, session invalidation and secure storage.
-
Access control (8 hours)
Object-level, function-level and role-based access checks using controlled multi-user testing.
-
Injection and server-side input (8 hours)
SQL, command and template-injection concepts, safe validation and root-cause analysis.
-
Client-side security (6 hours)
Cross-site scripting, browser-side data flow, content security policies and browser controls.
-
Server-side requests and file handling (6 hours)
Server-side request forgery, file uploads, downloads, path traversal and parser risks.
-
Business logic and workflow abuse (6 hours)
Application states, process limits, race-condition concepts and unsafe trust assumptions.
-
Configuration, components and logging (6 hours)
Security headers, error handling, third-party components, secrets and security-event logging.
-
Reporting, remediation and retesting (6 hours)
Severity ratings, evidence, developer guidance and verification of completed fixes.
-
Web-application assessment project (8 hours)
Complete an end-to-end authorised assessment and present the findings in a client-style review.
Practical work and labs
- Testing of purpose-built vulnerable web applications in an isolated environment.
- Manual testing using an approved web-security proxy and browser tools.
- Authentication, session, access-control and input-validation exercises.
- Finding review and remediation-verification exercises.
- Complete web-application assessment and professional report.
How your work will be assessed
Lab evidence: 35%; vulnerability reports: 25%; final authorised web-application assessment: 40%.
October 2026 Launch Fee
₹26,000
GST will be charged additionally at the applicable rate.
A2 API Security Testing Assess an API for authentication, access-control and data-handling weaknesses and report the results clearly.
What this course is for
Learn how to test REST APIs, JSON services, token-based authentication and selected GraphQL and webhook implementations. You will examine API inventory, access control, resource limits, sensitive-data exposure and machine-to-machine trust.
- Who can join and required knowledge
- Age 18+. Required knowledge: P3 Vulnerability Assessment & Professional Reporting, P2 Web Applications, APIs & SQL Foundations, F-S4 Identity & Access Management Foundations and F-L2 Networks & the Internet for Security—or equivalent skills confirmed through a practical starting-point assessment.
- Course schedule
- 10 weeks; 3 sessions/week × 2 hours
- Guided learning
- 60 hours
What you will be able to do
- Discover and document an API attack surface.
- Test API authentication, tokens and access controls.
- Identify object-level, function-level and property-level authorisation weaknesses.
- Assess rate limits, configuration, versions and third-party API trust.
- Complete an API-specific security assessment, report and retest.
What the course covers
-
API architecture and inventory (6 hours)
REST, JSON, schemas, OpenAPI, API versions, gateways and endpoint discovery.
-
Authentication and tokens (6 hours)
API keys, JSON Web Tokens, OAuth, OpenID Connect and secure token handling.
-
Object and function authorisation (8 hours)
Object-level and function-level access testing using repeatable multi-user scenarios.
-
Property-level authorisation (6 hours)
Mass assignment, excessive data exposure and schema-based controls.
-
Input, injection and server-side requests (6 hours)
Parameters, content types, parsers, injection risks and unsafe downstream requests.
-
Resource consumption and automated abuse (6 hours)
Rate limits, quotas, pagination and protection of sensitive business processes.
-
Inventory, configuration and third-party APIs (6 hours)
Old API versions, debugging endpoints, TLS, cross-origin controls and supplier trust.
-
GraphQL, webhooks and asynchronous APIs (4 hours)
GraphQL introspection, query costs, callbacks, event messages and signature verification.
-
API security assessment project (12 hours)
Prepare a test plan, assess an API, recommend fixes and verify remediation.
Practical work and labs
- API requests and testing using Postman, curl and an approved security proxy.
- Token, claim and authentication testing exercises.
- Multi-user API authorisation testing.
- Rate-limit, API inventory and configuration exercises.
- Complete API security assessment and professional report.
How your work will be assessed
Lab portfolio: 35%; API vulnerability findings: 25%; final API assessment project: 40%.
October 2026 Launch Fee
₹22,000
GST will be charged additionally at the applicable rate.
A3 Network Penetration Testing Plan and perform an authorised network penetration test in a controlled environment and document the results.
What this course is for
Learn how to assess an internal network safely and legally. You will progress from scoping and network discovery to service analysis, vulnerability validation, segmentation testing, credential-risk assessment, controlled exploitation, restoration and reporting.
- Who can join and required knowledge
- Age 18+. Required knowledge: P3 Vulnerability Assessment & Professional Reporting, F-L2 Networks & the Internet for Security, F-L3 Windows & Linux Operating Systems for Cybersecurity and P1 Cyber Lab Readiness & Professional Workflow Bootcamp—or equivalent skills confirmed through a practical starting-point assessment.
- Course schedule
- 12 weeks; 3 sessions/week × 2 hours
- Guided learning
- 72 hours
What you will be able to do
- Plan and perform an authorised internal-network assessment.
- Discover hosts, services, trust relationships and network boundaries.
- Validate service, configuration, segmentation and credential-related risks.
- Perform controlled vulnerability validation without damaging systems.
- Produce a prioritised report and verify completed remediation.
What the course covers
-
Rules of engagement and lab operations (6 hours)
Scope, authorisation, safety, communication, stop conditions and system restoration.
-
Discovery and network mapping (6 hours)
Hosts, routes, services, system ownership and assessment coverage.
-
Service enumeration (8 hours)
Analysis of common Windows, Linux and network services using evidence-led methods.
-
Vulnerability validation (8 hours)
Security advisories, software versions, configuration context and false-positive elimination.
-
Segmentation and firewall testing (6 hours)
Network paths, trust boundaries, firewall behaviour and evidence collection.
-
Credential and authentication assessment (6 hours)
Password policies, credential exposure, authentication controls and safe password-audit limitations.
-
Controlled exploitation (8 hours)
Minimal proof of impact, system stability, logging and clearly defined limitations.
-
Post-access validation and cleanup (6 hours)
Privilege context, lateral-movement risks, evidence handling and system restoration.
-
Remediation and retesting (6 hours)
System hardening, segmentation, patching, configuration improvements and verification.
-
Network penetration-testing project (12 hours)
Complete an authorised assessment of an isolated enterprise network and prepare a professional report.
Practical work and labs
- Isolated network containing multiple Windows and Linux systems.
- Network discovery, service enumeration and segmentation exercises.
- Controlled vulnerability-validation exercises with restoration checkpoints.
- Credential and authentication-control assessment.
- Complete network penetration test, report and findings presentation.
How your work will be assessed
Method and lab portfolio: 35%; validated vulnerability findings: 25%; final network assessment: 40%.
October 2026 Launch Fee
₹26,000
GST will be charged additionally at the applicable rate.
A4 SOC Analyst Level 1 Handle an entry-level SOC alert queue, investigate suspicious activity and record defensible incident notes.
What this course is for
Prepare for entry-level Security Operations Centre work through realistic alert and shift simulations. You will validate alerts, connect evidence, determine severity, recommend containment and communicate findings across endpoint, email, network, identity and cloud-security cases.
- Who can join and required knowledge
- Age 17+. Required knowledge: P4 Cyber Defence Operations Core, F-L2 Networks & the Internet for Security, F-L3 Windows & Linux Operating Systems for Cybersecurity and F-L6 Logs, SIEM & Security Monitoring Foundations—or equivalent skills confirmed through a practical starting-point assessment.
- Course schedule
- 12 weeks; 3 sessions/week × 2 hours
- Guided learning
- 72 hours
What you will be able to do
- Operate an entry-level SOC alert queue using clear investigation procedures.
- Investigate endpoint, phishing, network, identity and cloud alerts.
- Separate false positives from events that require escalation.
- Record investigation evidence and prepare clear incident notes.
- Complete a simulated SOC shift and professional handover.
What the course covers
-
SOC operations and service quality (6 hours)
SOC responsibilities, alert queues, response times, handovers, severity and escalation.
-
Endpoint alert investigation (8 hours)
Process trees, files, persistence, malware indicators and user context.
-
Phishing and email incidents (8 hours)
Email headers, attachments, URLs, mailboxes and user impact.
-
Network and DNS alerts (8 hours)
Connections, suspicious communication patterns, domains, protocols and normal baselines.
-
Identity and access alerts (6 hours)
Password-spray indicators, unusual travel, multi-factor authentication and privilege events.
-
Cloud and software-service alerts (6 hours)
Cloud configuration changes, storage exposure and risky sign-in activity.
-
Threat intelligence and ATT&CK (6 hours)
Source confidence, indicator enrichment, attacker behaviour and investigation use.
-
Containment, escalation and communication (6 hours)
Response authority, evidence, affected stakeholders and high-quality incident tickets.
-
Detection improvement and lessons learned (6 hours)
False positives, alert-tuning requests and investigation knowledge articles.
-
SOC shift simulation (12 hours)
Complete a timed multi-alert shift, escalate an incident and deliver an oral handover.
Practical work and labs
- Safe SIEM and endpoint-security datasets with a simulated alert queue.
- Email, endpoint, network and identity investigation exercises.
- Evidence collection and incident-ticket documentation.
- Timed alert-triage exercises.
- Complete simulated SOC shift and handover.
How your work will be assessed
Investigation portfolio: 30%; two timed alert-triage practicals: 30%; final SOC shift simulation: 40%.
October 2026 Launch Fee
₹23,000
GST will be charged additionally at the applicable rate.
A5 SIEM Operations & Log Investigation Write useful SIEM searches and detections, connect events across logs and complete a structured investigation.
What this course is for
Develop deeper practical skills in security logging, SIEM searches, detection rules, alert tuning and multi-source investigations. Microsoft Sentinel and KQL may be used as the primary lab platform, while the investigation methods remain applicable to other SIEM technologies.
- Who can join and required knowledge
- Age 17+. Required knowledge: F-L6 Logs, SIEM & Security Monitoring Foundations, P4 Cyber Defence Operations Core and working knowledge of networks and operating systems—or equivalent skills confirmed through a practical starting-point assessment.
- Course schedule
- 10 weeks; 3 sessions/week × 2 hours
- Guided learning
- 60 hours
What you will be able to do
- Collect and validate useful security telemetry.
- Write clear and maintainable SIEM investigation queries.
- Create and test useful detection rules.
- Tune noisy alerts and reduce avoidable false positives.
- Complete a structured investigation using multiple log sources.
What the course covers
-
SIEM architecture, log sources and data quality (6 hours)
Collection paths, schemas, delays, completeness, retention and operational costs.
-
SIEM query skills I (8 hours)
Filtering, selecting fields, parsing values and summarising events.
-
SIEM query skills II (8 hours)
Joins, lookups, time windows, event sequences and reusable query functions.
-
Detection engineering fundamentals (8 hours)
Detection ideas, attacker behaviour, rule logic, thresholds and test data.
-
Alert tuning and lifecycle management (6 hours)
False positives, suppression, exceptions, ownership and scheduled reviews.
-
Dashboards and operational measurements (4 hours)
Detection coverage, alert quality, queue health and useful visual reporting.
-
Investigation and evidence enrichment (8 hours)
Connecting identity, endpoint, network and threat-intelligence evidence into a timeline.
-
Detection versioning and change control (4 hours)
Peer review, testing, controlled deployment and rollback of security content.
-
SIEM investigation project (8 hours)
Onboard data, create and tune a detection rule, and investigate a staged security event.
Practical work and labs
- KQL-style SIEM search and investigation exercises.
- Log-parser and data-quality troubleshooting.
- Detection-rule creation, testing and alert tuning.
- Multi-source event correlation and timeline development.
- Complete SIEM investigation and findings presentation.
How your work will be assessed
SIEM query portfolio: 35%; detection and tuning practical: 25%; final investigation project: 40%.
October 2026 Launch Fee
₹21,000
GST will be charged additionally at the applicable rate.
A6 Cloud Security Operations Secure and monitor cloud systems and respond to common cloud-security problems through practical labs.
What this course is for
Learn how to protect cloud identities, networks, workloads, storage and secrets. Azure will be used as the primary lab platform, with AWS comparisons where useful. You will also investigate cloud activity and respond safely to security incidents.
- Who can join and required knowledge
- Age 18+. Required knowledge: F-L5 Cloud Computing & Cloud Security Foundations, P5 Cloud Administration & Automation Lab, F-S4 Identity & Access Management Foundations and F-L2 Networks & the Internet for Security—or equivalent skills confirmed through a practical starting-point assessment.
- Course schedule
- 12 weeks; 3 sessions/week × 2 hours
- Guided learning
- 72 hours
What you will be able to do
- Secure cloud identities, networks, workloads, storage and sensitive data.
- Apply least-privilege access and privileged-access controls.
- Identify and correct cloud-security configuration weaknesses.
- Monitor cloud activity and investigate suspicious events.
- Contain and respond to a staged cloud-security incident.
What the course covers
-
Cloud threats and shared responsibility (6 hours)
Important cloud assets, provider and customer responsibilities, trust boundaries and common failures.
-
Identity and privileged access (8 hours)
Roles, least privilege, workload identities, multi-factor authentication, conditional access and privileged-access concepts.
-
Cloud network security (8 hours)
Segmentation, private endpoints, firewalls, outbound traffic controls and network-flow evidence.
-
Compute and workload protection (8 hours)
Security of virtual machines, containers, serverless workloads, patching and runtime controls.
-
Storage, databases and data security (6 hours)
Public access, encryption, keys, backups, recovery and sensitive-data protection.
-
Secrets and key operations (4 hours)
Secure vault access, ownership, credential rotation and emergency response.
-
Posture and vulnerability management (8 hours)
Security benchmarks, recommendations, exceptions and remediation tracking.
-
Cloud logging, detections and investigations (8 hours)
Identity, administrative, network and workload security telemetry.
-
Cloud incident response (6 hours)
Credential containment, workload isolation, evidence preservation and recovery.
-
Cloud-defence project (10 hours)
Secure, monitor and defend a staged cloud environment.
Practical work and labs
- Cloud identity, network and storage hardening.
- Privileged-access and least-privilege configuration.
- Cloud-security posture and vulnerability remediation.
- Cloud activity-log investigation.
- Credential containment and cloud incident response.
- Complete cloud-defence project with defined cost limits.
How your work will be assessed
Cloud operations lab portfolio: 35%; configuration and investigation practicals: 25%; final cloud-defence project: 40%.
October 2026 Launch Fee
₹28,000
GST will be charged additionally at the applicable rate.
A7 Identity & Access Management Engineering Design and operate stronger enterprise identity controls for users, administrators and automated services.
What this course is for
Learn how enterprise organisations manage user access from account creation through role changes and account removal. You will work with single sign-on, modern authentication, conditional access, privileged accounts, service identities, access reviews and identity incident response.
- Who can join and required knowledge
- Age 18+. Required knowledge: F-S4 Identity & Access Management Foundations, P6 Enterprise Identity & Directory Services, F-L2 Networks & the Internet for Security and F-L3 Windows & Linux Operating Systems for Cybersecurity—or equivalent skills confirmed through a practical starting-point assessment.
- Course schedule
- 10 weeks; 3 sessions/week × 2 hours
- Guided learning
- 60 hours
What you will be able to do
- Design role-based and attribute-based access controls.
- Implement user account lifecycle and access-review processes.
- Configure and troubleshoot single sign-on and modern authentication.
- Protect privileged accounts and automated service identities.
- Investigate and contain identity-related security incidents.
What the course covers
-
Identity architecture and trust boundaries (6 hours)
Identity sources, directories, tenants, domains and hybrid identity environments.
-
Identity lifecycle and provisioning (6 hours)
New users, role changes, account removal, approvals and automated provisioning concepts.
-
Role and attribute design (6 hours)
Role-based access, attribute-based access, segregation of duties and entitlement design.
-
Single sign-on and modern authentication (8 hours)
SAML, OAuth, OpenID Connect, claims, tokens, signing and troubleshooting.
-
Multi-factor and conditional access (6 hours)
Authentication factors, passwordless access, device and risk signals, recovery and policy testing.
-
Privileged-access management (6 hours)
Temporary elevation, just-in-time access, emergency accounts and privileged-session evidence.
-
Workload and service identities (6 hours)
Managed identities, service accounts, secrets, certificates, rotation and ownership.
-
Identity governance and access reviews (6 hours)
Access certification, unused permissions, exceptions and audit evidence.
-
Identity detection and response (4 hours)
Risky sign-ins, stolen sessions, token revocation and account containment.
-
IAM engineering project (6 hours)
Implement and defend an enterprise identity-management scenario.
Practical work and labs
- Enterprise directory and cloud-identity configuration.
- Single sign-on and token-flow troubleshooting.
- Conditional-access and privileged-access design.
- User lifecycle and access-review exercises.
- Identity-security incident investigation.
- Complete IAM engineering project.
How your work will be assessed
IAM lab portfolio: 35%; identity troubleshooting and design practical: 25%; final IAM engineering project: 40%.
October 2026 Launch Fee
₹22,000
GST will be charged additionally at the applicable rate.
A8 DevSecOps Practitioner Add practical security checks to software build and deployment pipelines without losing delivery visibility.
What this course is for
Learn how to integrate security throughout software development and deployment. You will add code, dependency, secret, infrastructure, container and application-security checks to a working delivery pipeline and manage findings without making the pipeline unusable.
- Who can join and required knowledge
- Age 18+. Required knowledge: F-L4 Python Programming & Secure Coding Foundations, P7 Git, DevOps, Containers & CI/CD Foundations and F-L5 Cloud Computing & Cloud Security Foundations—or equivalent coding and deployment-pipeline skills confirmed through a practical starting-point assessment.
- Course schedule
- 12 weeks; 3 sessions/week × 2 hours
- Guided learning
- 72 hours
What you will be able to do
- Design practical security controls across the software-development lifecycle.
- Add security scanning to a continuous integration and deployment pipeline.
- Identify vulnerable code, dependencies, secrets, infrastructure and containers.
- Create software inventories and protect release artifacts.
- Manage security exceptions, evidence and developer feedback.
What the course covers
-
DevSecOps working model (6 hours)
Shared responsibility, threat-based controls, fast feedback and meaningful security measurements.
-
Repository and branch protection (6 hours)
Code reviews, signatures, protected branches, access tokens and least privilege.
-
Static application-security testing (8 hours)
Security rules, finding analysis, false positives, developer feedback and baselines.
-
Dependency security and software inventory (8 hours)
Third-party packages, security advisories, software bills of materials, licences and inventory.
-
Secrets and credential protection (6 hours)
Secret detection, prevention, credential rotation and incident handling.
-
Infrastructure-as-code security (6 hours)
Configuration policies, deployment plans, drift, scanning and remediation.
-
Container and registry security (6 hours)
Container images, provenance, vulnerability scanning, signing and admission-control concepts.
-
Dynamic testing and security automation (6 hours)
Safe test environments, test data, automated security checks and release gates.
-
Software supply-chain integrity (6 hours)
Build isolation, trusted artifacts, provenance and secure software releases.
-
Security exceptions and measurements (4 hours)
Risk acceptance, ownership, expiry dates, control coverage and useful measurements.
-
DevSecOps pipeline project (10 hours)
Secure a delivery pipeline from source-code submission to a deployed application.
Practical work and labs
- Build and configure a continuous integration and deployment pipeline.
- Static code, dependency and secret scanning.
- Infrastructure and container-security scanning.
- Software bill of materials and signed-artifact workflow.
- Security finding review, tuning and exception handling.
- Complete secure-delivery pipeline project.
How your work will be assessed
Pipeline lab portfolio: 35%; security-control implementation practical: 25%; final DevSecOps project: 40%.
October 2026 Launch Fee
₹28,000
GST will be charged additionally at the applicable rate.
A9 Container & Kubernetes Security Assess and improve the security of container images, workloads and Kubernetes configurations.
What this course is for
Learn how to secure container builds, registries and Kubernetes environments. You will work with access control, namespaces, network policies, secrets, workload restrictions, admission controls, security logging and runtime monitoring.
- Who can join and required knowledge
- Age 18+. Required knowledge: F-L3 Windows & Linux Operating Systems for Cybersecurity, F-L2 Networks & the Internet for Security, F-L5 Cloud Computing & Cloud Security Foundations and P7 Git, DevOps, Containers & CI/CD Foundations—or equivalent skills confirmed through a practical starting-point assessment.
- Course schedule
- 12 weeks; 3 sessions/week × 2 hours
- Guided learning
- 72 hours
What you will be able to do
- Build and maintain more secure container images.
- Protect container registries and software artifacts.
- Apply least privilege to Kubernetes users, services and workloads.
- Implement network segmentation and workload-security policies.
- Detect and respond to container and Kubernetes security problems.
What the course covers
-
Container internals and security threats (6 hours)
Container isolation, runtimes, system boundaries and common attack surfaces.
-
Secure container-image builds (6 hours)
Minimal base images, non-root users, packages, secrets and repeatable builds.
-
Registry and supply-chain security (6 hours)
Registry access, vulnerability scanning, signing, provenance and retention.
-
Kubernetes architecture (6 hours)
Control plane, worker nodes, workloads, APIs and trust boundaries.
-
Identity, service accounts and access control (8 hours)
Users, service accounts, roles, role bindings, tokens and least privilege.
-
Namespaces, networking and exposure (8 hours)
Segmentation, services, ingress, network policies and outbound communication.
-
Secrets, configuration and data (6 hours)
Secret handling, encryption, storage volumes and external secret-management systems.
-
Workload security and admission controls (8 hours)
Security contexts, system capabilities, workload policies and admission controls.
-
Logging and runtime detection (6 hours)
Audit logs, workload events, suspicious behaviour and investigation.
-
Hardening and incident response (4 hours)
Security benchmarks, workload isolation, credential rotation and recovery.
-
Kubernetes security project (8 hours)
Assess, harden, monitor and defend a local Kubernetes environment.
Practical work and labs
- Local container and Kubernetes lab environment.
- Container-image and registry vulnerability scanning.
- Image signing and artifact-verification exercises.
- Kubernetes access-control and network-policy implementation.
- Workload-security and admission-control configuration.
- Runtime-event investigation and cluster-hardening project.
How your work will be assessed
Container and Kubernetes lab portfolio: 35%; configuration practical: 25%; final Kubernetes security project: 40%.
October 2026 Launch Fee
₹29,000
GST will be charged additionally at the applicable rate.
A10 Secure Code Review for Python Applications Review Python code for security weaknesses, explain the risk and recommend or implement safer code.
What this course is for
Learn how to review Python applications using a repeatable security process. You will trace untrusted data, examine security decisions, identify weaknesses, use automated tools carefully, implement safer code and verify that fixes work.
- Who can join and required knowledge
- Age 18+. Required knowledge: F-L4 Python Programming & Secure Coding Foundations and P2 Web Applications, APIs & SQL Foundations—or equivalent Python and application-security skills confirmed through a practical starting-point assessment.
- Course schedule
- 10 weeks; 3 sessions/week × 2 hours
- Guided learning
- 60 hours
What you will be able to do
- Perform a structured security review of a Python application.
- Trace untrusted data through application code.
- Identify authentication, access-control, injection and file-handling weaknesses.
- Review secrets, cryptography, logging and third-party dependencies.
- Implement safer code and write tests that verify security fixes.
What the course covers
-
Code-review method and threat context (6 hours)
Scope, application architecture, entry points, important assets and trust boundaries.
-
Data flow and input validation (6 hours)
Data sources, transformations, sensitive operations, allowlists and canonicalisation.
-
Injection and unsafe code execution (6 hours)
SQL, operating-system command, template and interpreter-related risks.
-
Authentication, sessions and authorisation (8 hours)
Identity flows, access checks, multi-user boundaries and account recovery.
-
Files, paths, uploads and unsafe objects (6 hours)
Path traversal, file types, archives, deserialisation and unsafe parsers.
-
Outbound requests and server-side request risks (4 hours)
URL validation, network boundaries, redirects and cloud metadata services.
-
Secrets, cryptography and sensitive data (6 hours)
Configuration, logging, security libraries, storage and key lifecycle.
-
Errors, logs and business logic (4 hours)
Safe error handling, audit events, application states and workflow abuse.
-
Dependencies and automated review tools (4 hours)
Static analysis, dependency scanning, finding review and tool limitations.
-
Fixing, testing and reporting (4 hours)
Safe code changes, regression tests and evidence that vulnerabilities were corrected.
-
Python code-review project (6 hours)
Review, correct, test and present the security of a realistic Python application.
Practical work and labs
- Manual review of purpose-built Python projects.
- Static-analysis and dependency-scanning exercises.
- False-positive identification and tool-result validation.
- Vulnerability correction and regression testing.
- Complete Python application security review and report.
How your work will be assessed
Security-review portfolio: 35%; code correction and testing practical: 25%; final Python code-review project: 40%.
October 2026 Launch Fee
₹23,000
GST will be charged additionally at the applicable rate.
A11 Cyber Risk, GRC & Security Auditing Assess cyber risk, examine controls and evidence, and produce clear governance and audit documentation.
What this course is for
Learn how organisations identify cyber risks, design controls, assess third parties and conduct security audits. You will prepare risk registers, examine evidence, test controls, document findings and present the results to management. This is a non-coding cybersecurity pathway, but it requires detailed analysis and professional judgement.
- Who can join and required knowledge
- Age 18+. Required knowledge: F-L1 Cybersecurity Essentials & Career Foundations, F-S5 Cyber Law, Privacy, Governance & Ethics and P8 Risk, Controls & Audit Preparation—or equivalent skills confirmed through a practical starting-point assessment.
- Course schedule
- 10 weeks; 2 sessions/week × 3 hours
- Guided learning
- 60 hours
What you will be able to do
- Complete a scoped cyber-risk assessment.
- Prepare and maintain a practical risk-treatment plan.
- Design and map cybersecurity controls.
- Examine evidence and test whether controls are working.
- Plan a security audit and produce clear findings and management reports.
What the course covers
-
Governance and security frameworks (6 hours)
Security objectives, accountability, policies and orientation to commonly used frameworks.
-
Assets, scope and risk assessment (6 hours)
Asset inventories, boundaries, assessment criteria, likelihood, impact and clear risk statements.
-
Control design and mapping (6 hours)
Control objectives, implementation methods, ownership and framework mapping.
-
Risk treatment and tracking (6 hours)
Treatment plans, risk acceptance, exceptions, measurements and management reporting.
-
Third-party and supply-chain risk (6 hours)
Supplier assessment, contracts, evidence, monitoring and concentration risks.
-
Privacy, legal and incident obligations (6 hours)
Data handling, authorisation, incident response, notification and record-keeping.
-
Audit planning and programmes (6 hours)
Audit objectives, scope, criteria, materiality, sampling and working documents.
-
Evidence, interviews and control testing (6 hours)
Evidence reliability, control design, operating effectiveness, traceability and professional judgement.
-
Findings and management reporting (6 hours)
Documenting the issue, requirement, cause, impact, severity, recommendation and management response.
-
Cyber-risk and audit project (6 hours)
Complete a combined risk-and-audit case and present the findings in a closing meeting.
Practical work and labs
- Build a risk register and cybersecurity control library.
- Prepare a third-party security assessment and evidence-request list.
- Conduct simulated control-owner interviews.
- Review evidence and complete control-testing samples.
- Prepare an audit report and conduct a management closing meeting.
How your work will be assessed
Risk and control work products: 30%; security-audit practical: 25%; final report and presentation: 45%.
October 2026 Launch Fee
₹19,000
GST will be charged additionally at the applicable rate.
Course completion
A certificate must represent work you can demonstrate.
- Complete at least 80% of the guided classes.
- Complete the required practical work, labs and final course project.
- Follow all legal, safety and ethical lab rules.
- Achieve the required overall course-assessment score.
The minimum overall assessment score is 60% for Young Cyber Explorers, Foundation and Practitioner courses, and 70% for Advanced Cybersecurity Pathways.