Available courses
A hands-on 3-day course covering the full lifecycle of cyber threat intelligence — from collection and analysis to structured reporting and operational integration. Students work with real-world frameworks, APT datasets, and industry-standard tooling to build actionable intelligence capabilities.
This beginner-friendly course introduces students to the mindset, methods, and tools used by real-world threat actors. Through the lens of Threat Intelligence and APT analysis, participants will learn how hackers operate, how attacks are structured, and how to identify adversary fingerprints in the wild.
A three-day intensive course covering the attack surface of modern cloud environments across AWS, Azure, and GCP. Students will explore cloud misconfigurations, identity abuse, lateral movement, and detection engineering using real-world adversary techniques and hands-on lab exercises.
A hands-on red vs blue team demonstration tracing a full cyberattack lifecycle — from passive reconnaissance through phishing delivery, C2 establishment, post-exploitation, and live SOC detection using Wazuh, QRadar, and Grafana.
Participants follow the attacker's tradecraft step by step, then flip to the defender's perspective to correlate alerts and triage a real incident across a segmented lab environment.
A two-day intensive course covering the 2025–2026 threat landscape and building a structured, framework-driven Incident Response program. Day 1 delivers threat intelligence and IR theory; Day 2 focuses on hands-on lab practice and decision-making under pressure.
A hands-on 3-day course covering the full incident response lifecycle — from preparation and detection through containment, eradication, and post-incident review. Students work with real-world tooling, malware artifacts, and simulated breach scenarios to build operational IR capabilities.
A hands-on, practitioner-focused course that trains analysts to proactively search for hidden threats inside enterprise environments using behavioral analytics, threat intelligence, and adversary emulation techniques.
Students progress from hunting fundamentals and hypothesis-driven methodologies through live lab exercises, leaving with repeatable hunt playbooks and the skills to operationalize threat hunting within a SOC.
A focused one-day hands-on course introducing the complete Blue Team toolkit — SysInternals, Wireshark, Wazuh, Bunker WAF, and OPNSense. Students set up and navigate each tool's lab environment, and operate under realistic training rules of engagement that mirror professional SOC and incident response standards.
A hands-on, three-day course covering the essential defensive security tools used by modern blue teams — from endpoint visibility and packet analysis to SIEM alerting, web application firewalls, and perimeter firewall management. Students work directly with SysInternals, Wireshark, Wazuh, Bunker WAF, and OPNSense in realistic lab scenarios.