๐Ÿ›ก๏ธ
Specialization track

Cybersecurity

From security fundamentals and threats to offensive (pentest) and defensive (SOC/Blue Team) practice โ€” using real attack-and-defend labs, you'll build complete security-specialist skills.

120 hours60 lessons
6 modules+ 2 final projects
IntermediateLevel
5โ€“6 monthsDuration
๐Ÿ”‘
Prerequisite: System Administration graduate or equivalent knowledge (Linux, Windows Server, networking, bash/PowerShell basics).
Curriculum

6 modules โ€” from fundamentals to pentest and SOC

Every module is reinforced with hands-on work in an isolated lab environment.

  • CIA triad, threat/vulnerability/risk concepts, attack surface
  • Malware types, phishing, social engineering, DDoS, APT
  • The Cyber Kill Chain and the MITRE ATT&CK framework
  • Building a lab environment: Kali Linux + Metasploitable + DVWA
  • Legal and ethical foundations, first CTF challenges
  • Traffic analysis with Wireshark/tcpdump
  • Firewalls (iptables/nftables), segmentation, DMZ, zero trust
  • IDS/IPS (Snort/Suricata), VPN (IPsec, WireGuard), TLS tunneling
  • Wi-Fi security (WPA2/WPA3), MITM/ARP/DNS spoofing (isolated lab)
  • Project: securing a small network with firewall + IDS + segmentation
  • Pentest methodology (PTES/OSSTMM): recon โ†’ scan โ†’ exploit โ†’ report
  • Advanced Nmap, vulnerability assessment with Nessus/OpenVAS
  • Metasploit Framework, OWASP Top 10 (SQLi, XSS, CSRF, IDOR)
  • Burp Suite, Hashcat/John the Ripper, privilege escalation
  • Project: writing a professional pentest report
  • SOC tiers (L1/L2/L3), Sysmon, key event IDs
  • SIEM: Elastic Stack (ELK) or Wazuh โ€” search and dashboards
  • Detection rules (Sigma), Threat Intelligence (IOCs, MISP)
  • Endpoint security (EDR), vulnerability management, threat hunting
  • SOAR automation, a Purple Team exercise
  • Project: a SOC monitoring stand โ€” SIEM + Sysmon + detection rules
  • Cryptography fundamentals, hands-on TLS/SSL, PKI
  • Secure coding, API security (JWT, OAuth 2.0)
  • DevSecOps: SAST/DAST, dependency and container image scanning (Trivy)
  • Cloud security (AWS/Azure): IAM, shared responsibility, misconfigurations
  • Container/Kubernetes security, MFA/SSO, AD attacks (Kerberoasting)
  • NIST Incident Response process (preparation โ†’ lessons learned)
  • Digital forensics: Autopsy/Volatility, chain of custody
  • Malware analysis fundamentals (static vs dynamic)
  • Compliance: ISO 27001, GDPR, PCI DSS, NIST CSF
  • Final project: a complete security assessment (offensive + defensive) and its defense
๐Ÿงช

Required infrastructure

A VM (4 vCPU / 8 GB RAM) per student; an isolated virtual network (Kali Linux + Metasploitable + DVWA + a Windows VM); a SIEM stand (ELK/Wazuh); AWS/Azure free-tier accounts; an internet-isolated "attack lab."

๐ŸŽ“ Final project (2 parts)

A complete security assessment: offensive + defensive

Part 1 โ€” Offensive: recon โ†’ pentest โ†’ findings report. Part 2 โ€” Defensive: hardening + SIEM detection + an IR playbook. Wraps up with a professional report (pentest report + SOC report), portfolio, and a certificate.

Full track: System Administration (100 hours) + Cybersecurity (120 hours) = 220 hours โ€” from zero to security specialist

Certifications

Recommended certifications

In priority order โ€” from foundation to professional pentest level.

1 CompTIA Security+ 2 CompTIA CySA+ / BTL1 3 eJPT / CEH 4 OSCP

Enroll in the Cybersecurity course

Sign up for a consultation to be notified about the next group start date.