Through 17 practical programmes, we prepare specialists to understand attacks, assess defences and support decisions with evidence. Each course connects theory with lab work and a final project.
Exercises run in authorised, isolated labs. Advanced courses require networking, operating-system and subject fundamentals; the cohort and final syllabus are agreed according to readiness.
50–190 hours
01SOC & Blue Team
Security Operations Center
We prepare SOC analysts to turn alerts into evidence-based conclusions, teaching log correlation, risk assessment and escalation through practical exercises.
80 hours1.5 months90% practical work
Curriculum & practical project
Telemetry: correlate Windows, Linux, DNS and identity events in a SIEM; verify timestamps and field quality.
Triage: investigate compromised accounts, suspicious PowerShell and network activity; distinguish false positives from credible threats.
We teach endpoint, network and identity defence assessment, using threat hunting and controlled retesting to evaluate how well protective settings work.
60 hours1.5 months95% practical work
Curriculum & practical project
Endpoint defence: EDR signals, Sysmon telemetry, process trees and persistence evidence.
Threat hunting: form a hypothesis, select evidence and investigate anomalies in network and identity activity.
Purple Team: compare lab attack scenarios with detection; improve MFA, segmentation and access controls.
COURSE OUTCOME
Practical project: create detection and response guidance for an attack scenario and compare controls before and after remediation.
We teach the planning and controlled execution of goal-driven Red Team assessments. Lab work connects individual weaknesses into attack paths and explains their business impact through evidence.
190 hours4 months95% practical work
Curriculum & practical project
Operation planning: authorisation, Rules of Engagement, attack surface, critical assets and stop conditions.
Identity paths: assess AD and Entra ID trust relationships, Kerberos, AD CS and excessive privileges in an isolated environment.
Adversary emulation: model attacker behaviour within an agreed scenario; evaluate EDR/SIEM visibility and Blue Team response.
COURSE OUTCOME
Practical project: deliver a lab attack-path map, detection gaps, safe evidence and a prioritised remediation plan for leadership.
We teach in-depth assessment of authorisation, sessions and business logic in web applications and APIs, with reproducible evidence and remediation guidance developers can use.
120 hours2.5 months95% practical work
Curriculum & practical project
Access controls: BOLA/IDOR, roles and tenant data isolation; validate authorisation boundaries.
Identity: OAuth/OIDC, SSO, token lifetimes, session revocation and account recovery.
Deeper assessment: examine SSRF, file uploads, concurrent requests and business workflows such as payments in a Burp Suite lab.
COURSE OUTCOME
Practical project: execute an OWASP WSTG assessment plan and deliver reproducible findings, business impact and remediation guidance.
We prepare investigators to work from digital evidence, correlating endpoint, memory and network artefacts into a timeline that supports response decisions.
60 hours1.5 months90% practical work
Curriculum & practical project
Evidence collection: targeted Velociraptor artefacts, disk images, hash verification and chain of custody.
Analysis: correlate Windows events, browser and file-system artefacts, memory processes and network connections.
Response: establish scope, contain while preserving evidence and define safe recovery criteria.
COURSE OUTCOME
Practical project: a lab incident timeline, evidence register and conclusions for technical teams and leadership.
We teach relevant-threat identification, source evaluation and intelligence-led decisions, practising the full workflow from collection to analysis for leadership and security teams.
70 hours1.5 months90% practical work
Curriculum & practical project
Requirements and sources: define intelligence questions, evaluate open-source reliability and distinguish confidence levels.
Analysis: connect indicators, infrastructure and MITRE ATT&CK behaviours; distinguish similarity from confirmed attribution.
Operational use: STIX/TAXII concepts, sharing with MISP and testable hunting hypotheses for the SOC.
COURSE OUTCOME
Practical project: a threat brief with sources, confidence and defensive actions, plus a focused SOC investigation checklist.
We teach unknown-file analysis in an isolated lab, combining static analysis, execution monitoring and reverse engineering into a clear technical assessment.
100 hours2 months90% practical work
Curriculum & practical project
Static analysis: PE/ELF structures, imports, strings and code flow using tools such as Ghidra.
Dynamic analysis: observe file, registry, process and network changes without affecting external systems.
Detection: behavioural indicators and YARA rules; recognise packed code and anti-analysis indicators.
COURSE OUTCOME
Practical project: analyse a training sample and deliver a behaviour map, tested YARA rule and containment recommendation.
We teach teams to integrate security checks into daily development, covering early defect detection, remediation tracking and software release criteria.
120 hours2.5 months90% practical work
Curriculum & practical project
Design: threat modelling, data flows and trust boundaries; connect requirements with OWASP ASVS controls.
Pipeline: SAST, SCA, secret detection and SBOM; prioritise code and dependency weaknesses by risk.
Delivery: containers, IaC and CI/CD permissions; artifact trust and security release gates.
COURSE OUTCOME
Practical project: build a security pipeline for a lab repository, with an exception process and remediation verification.
We teach staff to manage accounts, devices and work documents safely, using familiar workplace scenarios to build phishing recognition, risk reduction and reporting skills.
60 hours1.5 months85% practical work
Curriculum & practical project
Account security: password managers, MFA, passkeys and suspicious sign-in notifications.
Data handling: sharing permissions, cloud links, backups and confidential-data exposure through AI tools.
Fraud awareness: QR codes, messaging, impersonation calls and payment requests; verify through a second channel.
COURSE OUTCOME
Practical project: a workplace protection checklist and an exercise in reporting suspicious activity.
We teach Linux principles alongside practical administration, building foundations for penetration testing, SOC and DevSecOps through files, permissions, processes and services.
60 hours1.5 months90% practical work
Curriculum & practical project
System foundations: file systems, users and groups, permissions, packages and services.
Investigation: processes, network connections, systemd logs and Bash automation for repeatable tasks.
Hardening: SSH configuration, least privilege, patching and log monitoring; a rollback plan for changes.
COURSE OUTCOME
Practical project: configure a lab server and produce a health-check script and concise operations guide.
We teach human-risk reduction through processes and training, using agreed deception scenarios to practise controlled simulation, outcome measurement and targeted education.
60 hours1.5 months90% practical work
Curriculum & practical project
Threat models: BEC, help-desk impersonation, QR and messaging fraud; AI-assisted impersonation risks.
Campaign rules: authorisation, privacy, groups and scope; simulations without collecting real passwords or payments.
Measurement: reporting, independent verification and process adherence; training tailored to job roles.
COURSE OUTCOME
Practical project: an authorisation brief, safe simulation scenario, training material and aggregated leadership report.
We teach how to translate technical evidence into clear risk, business impact and actionable recommendations, producing reports that support leadership decisions and technical remediation.
50 hours1 months90% practical work
Curriculum & practical project
Finding structure: separate scope, observation, evidence, verification conditions and limitations.
Prioritisation: CVSS concepts, asset value and existing controls; distinguish technical severity from business risk.
Communication: executive summary, technical appendix, owners and deadlines, and retest status.
COURSE OUTCOME
Practical project: turn supplied assessment evidence into a two-level report for leadership and technical teams.
We teach public institutions to connect information security with accountability and practical controls, covering sensitive information, service continuity and staff access management.
50 hours1 months90% practical work
Curriculum & practical project
Governance: asset registers, data categories, separation of duties and documented evidence of requirements.
Operations: service accounts, remote access, log monitoring and supplier permissions.
Readiness: incident notification chains, backup and recovery; a service-disruption tabletop exercise.
COURSE OUTCOME
Practical project: a risk register, responsibility matrix and 90-day improvement plan for a model organisation.
We teach rigorous research within bug bounty programme rules, practising application-logic assessment, finding validation and reports that programme teams can reproduce.
We teach attack-path analysis of Active Directory permissions and trust relationships, using an isolated lab to assess how individual settings affect domain security.
80 hours1.5 months95% practical work
Curriculum & practical project
Mapping: use BloodHound to examine how groups, ACLs, delegation and service accounts relate to critical assets.
Deeper analysis: assess Kerberos, AD CS and cross-domain trust weaknesses in an isolated lab.
Defence: administrative tiering, least privilege and detection; verify that remediation breaks the attack path.
COURSE OUTCOME
Practical project: a lab-domain attack-path map, risky permissions register and Blue Team retest report.
We teach the integration of open-source security tools into collection, detection and response, assessing both their configuration and practical monitoring coverage.
50 hours1 months95% practical work
Curriculum & practical project
Architecture: endpoint and network telemetry, SIEM and EDR/XDR roles; distinguish tools from MDR as a managed service.
Integration: tools such as Wazuh, osquery and Velociraptor; data quality, retention and operator access.
Controls: data-loss detection, DLP policy, rule testing and approval for automated response.
COURSE OUTCOME
Practical project: a lab monitoring stack, validated detection scenario and an operations and maintenance guide.
We design the syllabus around your team’s skills, responsibilities and expected outcomes. We agree the schedule, pricing, tool licences and assessment when you order, and explain CYBER-BRO course certificates and external exam conditions separately.