(T) Training · 6,000+ people trained
Taught by the people who run the engagements.
Every course is built from findings in real assessments, not a vendor curriculum. Delivered in-person or virtually, for corporate teams and individual practitioners.
DELIVERY
In-person at your office, or virtual over video with live lab access.
COHORT SIZE
Private corporate cohorts from 8 people. Open cohorts capped at 20.
TAUGHT BY
The same senior practitioners who run our pentest engagements.
MATERIALS
Lab environments, slide decks, and a written reference each attendee keeps.
Course catalogue
Six courses, two tracks.
Awareness courses for the whole organisation; practitioner courses for engineers and security teams. All are hands-on and delivered against live lab environments.
AWARENESS TRACK
Corporate IT Security & Personal Scam Awareness
HALF DAYALL STAFF
The organisation-wide baseline. Built around scams and attacks actually landing in Indian inboxes this year, not generic 2015 phishing examples.
Covers
·Recognising phishing, vishing, and payment fraud
·Password hygiene, MFA, and password managers
·Safe handling of corporate data and devices
·What to do in the first ten minutes of an incident
PRACTITIONER TRACK
HackTheWeb: Pentesting Beyond Basics
3 DAYSINTERMEDIATE
For people who have read the OWASP Top 10 and now need to exploit it. Heavy on chaining low-severity findings into real compromise: the skill that separates a scan from an assessment.
Covers
·Advanced access-control and IDOR exploitation
·Authentication and session attack chains
·SSRF, deserialisation, and injection beyond SQLi
·Business-logic abuse and exploit chaining
PRACTITIONER TRACK
API Pentesting
2 DAYSINTERMEDIATE
APIs now carry most of the risk and get the least of the testing. Structured around the OWASP API Security Top 10, with labs on REST and GraphQL.
Covers
·Broken object and property-level authorisation
·Mass assignment and over-exposure
·JWT and token handling flaws
·Rate-limit and resource-consumption abuse
PRACTITIONER TRACK
BurpSuite Essentials
1 DAYBEGINNER
Most teams use maybe a tenth of Burp. This is the working knowledge, from proxy setup and scoping through to writing your own match-and-replace rules and extensions.
Covers
·Proxy, scoping, and target configuration
·Repeater, Intruder, and payload crafting
·Macros, session handling, and authenticated scans
·Useful extensions and custom rules
PRACTITIONER TRACK
Secure by Design: Mastering DevSecOps
2 DAYSINTERMEDIATE
Security integrated into the SDLC in a way engineers will actually keep. Tooling, automation, and, importantly, how to configure gates that do not get switched off after a sprint.
Covers
·SAST, DAST, and SCA in CI/CD pipelines
·Secrets management and dependency hygiene
·Container and IaC scanning
·Building gates teams will not disable
PRACTITIONER TRACK
Threat Modelling Essentials
1 DAYALL TECHNICAL
A repeatable method your team can run without us. By the end of the day, attendees have produced a real threat model for one of your own systems.
Covers
·Asset, entry-point, and trust-boundary mapping
·STRIDE and attack-tree techniques
·Rating and prioritising identified threats
·Running the workshop yourself afterwards
How a corporate cohort runs
Tailored to your stack, not a generic syllabus.
01
Scoping call
Who is attending, what they already know, and what you need them able to do afterwards.
02
Tailoring
We swap generic lab targets for scenarios that match your stack, sector, and threat profile.
03
Delivery
Hands-on sessions at your office or over video, with live labs each attendee works in directly.
04
Follow-up
Written reference material, a skills-gap summary for you, and an optional follow-up Q&A session.
6K+
Employees trained
6
Courses in the catalogue
15+
Years of field experience behind the material
Delivered at
ByteCon
Emcure Pharmaceuticals
CoCon Cyber Security Conference
nullcon
Enquire
Tell us who needs training and we will shape a cohort.
Private cohorts from eight people. Individual seats on open cohorts are announced on our insights page and mailing list.
PRIVATE COHORTS
Fixed fee per cohort, quoted from headcount and duration. Travel billed at cost for in-person outside Mumbai.
LEAD TIME
Typically 3–4 weeks from signature, to allow tailoring to your environment.
OPEN COHORTS
Individual seats are announced on our insights page. Join the mailing list for dates.
CONFERENCE & CSR
We regularly teach at community conferences. Get in touch if you are organising one.