Track 02 — The Fortress
Cyber Security
Security is a practical craft, so this track is built on labs. You will learn how networks and systems really work, how attackers break them, and how defenders detect and contain that — then write the kind of report a client actually pays for.
( What you'll learn )
Networking fundamentals
TCP/IP, DNS, routing, NAT and TLS — read a packet capture and explain exactly what happened on the wire.
Linux & Windows internals
Filesystems, permissions, processes, services, the registry and where each system writes its logs.
Scripting for security
Bash and Python for automation: parsing logs, scanning, and building the small tools that save you hours.
Web application security
The OWASP Top 10 exploited and then fixed by hand — injection, broken auth, XSS, SSRF, access control.
Reconnaissance & enumeration
Mapping a target properly. OSINT, scanning, service fingerprinting and building an accurate picture before touching anything.
Exploitation & privilege escalation
Getting a foothold and then escalating, on machines you are authorised to attack. Why each technique works, not just which tool to run.
Cryptography in practice
Hashing, symmetric and asymmetric encryption, certificates, key management — and the implementation mistakes that undo all of it.
SOC operations
Life on the defensive side: SIEM, log pipelines, alert triage, writing detection rules and cutting false positives.
Incident response & forensics
Containment, evidence handling, memory and disk artefacts, timeline reconstruction and the post-incident report.
Cloud & infrastructure security
IAM, misconfigurations, storage exposure, network policy and hardening in cloud environments.
Governance, risk & compliance
Policies, risk registers, audits and the frameworks clients ask about — the part of security that is paperwork, done properly.
Capstone engagement
A full authorised assessment against a lab environment, delivered as a professional report with findings, evidence and prioritised fixes.
( Curriculum — 26 weeks )
Foundations
You cannot secure what you do not understand. Seven weeks on how networks, operating systems and the web actually behave.
- TCP/IP and the OSI model
- DNS, HTTP, TLS in depth
- Wireshark and packet analysis
- Linux command line and permissions
- Windows services and the registry
- Virtualisation and lab setup
- Bash and Python scripting
- Security terminology and threat models
Offensive security
Attacking, on isolated lab targets you are explicitly authorised to test. The goal is understanding defence from the other side.
- Recon and OSINT
- Nmap scanning and enumeration
- Web exploitation: OWASP Top 10
- Burp Suite workflows
- Password attacks and hash cracking
- Privilege escalation, Linux and Windows
- Post-exploitation basics
- Writing findings and evidence
Defensive security
The side most jobs actually sit on. Detection, triage and response, using the same tooling a real SOC runs.
- Log sources and normalisation
- SIEM fundamentals
- Detection rule writing
- Alert triage and escalation
- Threat intelligence basics
- Incident response lifecycle
- Memory and disk forensics
- Tabletop exercises
Cloud, GRC & capstone
Modern infrastructure, the governance layer around it, and your final assessment delivered as professional work.
- Cloud IAM and least privilege
- Common cloud misconfigurations
- Container and CI/CD security
- Hardening baselines
- Risk assessment and registers
- Compliance frameworks overview
- Capstone engagement
- Report writing and presentation
( Tools you'll master )
( Projects you'll build )
Network assessment
Map and audit a lab network end to end — discovery, service analysis, misconfigurations, and a prioritised remediation list.
Web application pentest
A full authorised test against a deliberately vulnerable application, delivered as a client-grade report with proof and fixes.
SOC detection pack
Build log pipelines and write detection rules for a set of attack techniques, then tune them until the false positives stop.
Incident response exercise
Work a simulated breach: contain it, collect evidence, reconstruct the timeline and write the post-incident review.
( Where this leads )
( Is this you? )
A good fit if
- You are patient and methodical — security work is mostly careful investigation
- You want to work in defence, SOC, or authorised testing
- You are willing to build and break your own lab environments
- You accept that documentation and reporting are half the job
Probably not yet if
- You want to attack systems you do not own or have written permission to test
- You are looking for shortcuts rather than fundamentals
- You dislike reading documentation and logs
- You cannot set aside lab time outside class
Authorised, always.
Every offensive technique in this track is practised inside isolated lab environments that we provide and you are explicitly authorised to attack. Learning how an attack works is exactly how defenders get good at stopping it — and knowing where the legal and ethical line sits is part of the curriculum, not an afterthought.
Attacking systems you do not own or have written permission to test is a crime in most jurisdictions, including under Pakistan's PECA 2016. We teach the boundary as seriously as the technique, and students who cross it are removed from the programme.
( Reading on this track )
Next batch enrolling
Enroll ↗