Home Cybersecurity Lab Setup
Month one’s build: Kali Linux and Windows Server virtualised on VMware or VirtualBox, with a secure Linux installation, documented network and an implemented password policy.
- Kali
- VMware
A fast-paced three-month programme taking you from your first Linux install to a working AI-powered security tool — networking, ethical hacking, web security, SOC and SIEM, cloud fundamentals and Python automation, with placement preparation built into the final month.
This is the three-month AI-Powered Cybersecurity programme, written for someone starting straight after 12th who wants working security skills quickly rather than the longest possible syllabus. Three months, and a set of mini projects at the end of every month. It is fast-paced by design — each month carries a full theme — and the pace is what lets you finish with a working AI security tool inside a single term.
Key Highlights
This is the three-month AI-Powered Cybersecurity programme, written for someone starting straight after 12th who wants working security skills quickly rather than the longest possible syllabus. Three months, and a set of mini projects at the end of every month. It is fast-paced by design — each month carries a full theme — and the pace is what lets you finish with a working AI security tool inside a single term. Month one is cybersecurity, networking and system administration. You cover cybersecurity fundamentals — the CIA triad, security domains, types of cyber attack, career paths and cyber laws and ethics — then computer hardware and operating systems, Windows and Linux administration, user and group management and file system permissions. Networking is taught properly rather than skimmed: the OSI and TCP/IP models, IPv4 and IPv6, IP addressing, subnetting, routing and switching, DNS, DHCP, NAT, VPN and common ports and protocols. Then virtualisation with VMware Workstation and VirtualBox, installing Kali Linux and Windows Server and building your own cybersecurity lab, followed by Git and GitHub and a module on AI for cybersecurity. Month two is ethical hacking, web security and security operations. Information gathering through OSINT, Google dorking, WHOIS, DNS and subdomain enumeration; vulnerability assessment with Nmap, Wireshark, Nikto, Gobuster and Nuclei; web security covering HTTP and HTTPS, cookies and sessions, APIs, the OWASP Top 10, SQL injection, XSS, CSRF, authentication and session attacks and file upload vulnerabilities; Burp Suite across Proxy, Target, Repeater, Intruder, Decoder and Comparer; then the defensive half — SOC fundamentals, security monitoring, log analysis, the incident lifecycle, SIEM fundamentals, Wazuh and Splunk basics — and a module on AI-assisted security. Month three is advanced security, AI automation and placement preparation. Advanced ethical hacking with the Metasploit Framework, Hydra, password attacks, wireless security, Active Directory basics and privilege escalation concepts; cloud security across AWS and Azure fundamentals, IAM, security groups, Docker and Kubernetes security; Python security automation; then AI security automation using the OpenAI and Google Gemini APIs. The month closes with the industry capstone and a full placement module. All lab work runs on your own virtual lab, on deliberately vulnerable applications such as DVWA and OWASP Juice Shop, and on TryHackMe, Hack The Box, the PortSwigger Web Security Academy and OverTheWire — systems you are permitted to test, with a trainer supervising.
Every module ends in something you have built and a trainer has reviewed, so the list below is work you will have done rather than topics you will have heard about.
Wazuh and Splunk basics with log analysis and the incident lifecycle
The syllabus is arranged so every module produces an asset rather than a set of notes. You will cover month 1 — cybersecurity, networking & system administration, month 2 — ethical hacking, web security & security operations, month 3 — advanced security, ai automation & placement preparation, and finish with a live project built on Kali Linux, Windows Server, VMware & VirtualBox. Modules run in the order a real project runs: foundations first, then the core skills, then applied work under supervision, then the portfolio and interview preparation that turn all of it into an offer letter.
The working knowledge the job description actually lists.
Month 2 — Ethical Hacking, Web Security & Security Operations
Both halves in one month — offensive assessment on legal targets, and the SOC work that most short courses skip.
4 weeks · 24 sessions
Topics covered
The toolchain
Everything below is installed on the lab machines and used on live client work, not shown once in a slide and forgotten.
Any stream. Month one begins at the CIA triad and computer hardware, and ends with your own cybersecurity lab built on VMware or VirtualBox — which is where every later exercise happens.
Three months fits a single vacation or the gap between school and college, and you finish it with an AI-powered capstone rather than an unfinished playlist of videos.
If you are entering a BCA or B.Sc IT, arriving already able to run a vulnerability assessment and read a SIEM dashboard changes what your first two years look like.
Three months is a real commitment but a bounded one. If it clicks, the longer tracks continue into cloud security, digital forensics, a two-month capstone and a full placement month.
Weekend batches exist for people already working. If you already handle desktops or networks, month one will be familiar and you will move quickly into the hacking and SOC modules.
If TryHackMe rooms and free videos left you with scattered notes, what changes here is a structured three-month calendar and a trainer who reads the report you wrote this week.
Entry-level SOC and IT security roles are among the few technical jobs still decided by whether you can build a lab, run an assessment and read a SIEM dashboard rather than by which degree you hold. That gap is the whole argument for this course: there is local demand, there are budgets, and there are very few trained people to hand the work to.

Build skills that hold up beyond the classroom.
What separates this from a playlist of tutorials is supervision on real work. From the second half of the course you build on live client projects with a trainer beside you, make decisions that have consequences, and correct them the following week. That loop is the skill. No employer in Phagwara will take your word for it without work they can inspect.
Be realistic about the money. A fresher who finishes with a working portfolio starts near the bottom of the band and moves quickly; someone who finishes with a certificate and nothing to show does not. The difference is entirely what you built.
The alternative is what most people try first: free videos, a cheap online course, six months of drifting, and knowledge you cannot demonstrate. A structured programme with live projects, a mentor who corrects you, an internship letter and a placement cell that actually calls employers is the difference between knowing the subject and being hired to do it.
Students reach the Phagwara centre from Banga, Nakodar, Kartarpur and the university belt, and the weekend batch exists so a job or a degree does not have to be paused to attend.
Cybersecurity concepts, Linux and Windows administration, and a full networking module — OSI and TCP/IP, subnetting, routing, DNS, DHCP, NAT, VPN and common ports.
OSINT and enumeration, Nmap, Wireshark, Nikto, Gobuster and Nuclei, then the OWASP Top 10 in Burp Suite — SQL injection, XSS, CSRF, session and file upload attacks.
SOC operations, security monitoring, log analysis and the incident lifecycle, with Wazuh and Splunk basics — the defensive half most short courses leave out.
AI vulnerability assessment, report generation, log analysis, threat detection and security analytics, plus prompt engineering and AI research techniques from month one.
Automation scripts, API automation, log parsing and report automation, then the OpenAI and Gemini APIs for an AI security assistant, chatbot, threat intelligence and incident response.
One AI-powered capstone, plus ATS resume building, a GitHub portfolio, LinkedIn optimisation, subject-wise interview questions and technical, HR and practical mock rounds.

Complete the course with a portfolio of live projects and receive an industry-recognised certificate, plus a documented internship letter accepted by Punjab universities.
Recognised by employers across Punjab and beyond
Based on real client work, not a simulation
Live work you can show in any interview
CV review, mock interviews and hiring drives
Two certificates on completion — the course certificate and a separate capstone project certificate.
The roles this opens, what they pay in Punjab and beyond, and who is hiring for them — drawn from published job-market listings, not a brochure number.
Monitor alerts, triage what matters and escalate what does not resolve. The standard first job in security, and what the SIEM and log-analysis work in month two is for.
General security work inside an IT team — assessments, hardening, access reviews and reporting.
Run scans, verify findings by hand and write them up. The role the month-two assessment report maps onto most directly.
Patching, access control, endpoint protection and user security. The most widely available entry role locally.
A newer title, and the reason month three exists — using AI tooling for log analysis, threat detection and report generation on a real alert queue.
Salary outlook — SOC Analyst (L1)
Monitors and defends the systems a business runs on. Three months makes you interviewable for the junior titles; experience on a real alert queue is what moves the figure quickly.
Indicative ranges compiled from public job-market listings. Actual offers vary by employer, skillset and interview performance.
Month one’s build: Kali Linux and Windows Server virtualised on VMware or VirtualBox, with a secure Linux installation, documented network and an implemented password policy.
The addressing, subnetting, DNS, DHCP and NAT from month one applied to your own lab network and written up — the document that proves you understand what you built.
Two deliberately vulnerable applications worked end to end in Burp Suite — SQL injection, XSS, CSRF, session and file upload flaws against the OWASP Top 10.
A network scanned with Nmap and Nuclei, traffic read in Wireshark, findings written up to a professional standard — with AI report generation speeding the write-up, not replacing your judgement.
Wazuh and Splunk log sources parsed and triaged with an AI-assisted analyser — the first thing you build that does a real SOC job faster than a person could.
One complete solution — an AI SOC dashboard, AI vulnerability scanner, AI security assistant, AI threat detection platform or AI phishing detection tool — built in Python on the OpenAI or Gemini API. This is the one interviewers ask about.
Every project moves through the same loop: understand the brief, build with guidance, then explain the decisions behind your work.
Take a real requirement apart before touching a tool — what is being asked, what it needs, and which part to build first.
Home Cybersecurity Lab Setup
Work hands-on with your trainer watching the screen, so a wrong turn is caught in the same session rather than three weeks later.
Network Documentation & Hardening
Walk through what you built and why you built it that way. This is the interview rehearsal, run against every project rather than once at the end.
DVWA & Juice Shop Assessments
There are many places to learn this in Phagwara and the brochure syllabus looks similar at all of them. What differs is who teaches, whether you ever touch real work, and whether anyone picks up the phone after you have paid. techcadd has trained students across Punjab since 2007 on the same model: small batches, working practitioners as trainers, client projects as coursework.
Your trainer is not a full-time lecturer. They handle security work for techcadd’s services arm, so the examples in class are current rather than a case study from five years ago.
Month one ends with your own virtualised lab running Kali Linux and Windows Server. Every exercise after that happens in it, on DVWA and Juice Shop, or on TryHackMe, Hack The Box, PortSwigger Academy and OverTheWire — never against systems you have no permission to touch.
We will tell you plainly whether the three-month or the nine-month track fits your goal. A student sold the wrong length is a student who does not finish.
Subnetting, routing, DNS, DHCP, NAT and VPN as their own module. Skipping this is why so many short-course graduates cannot explain what a scan result means.
Month three builds against the real OpenAI and Gemini APIs — an AI security assistant, a security chatbot, threat intelligence and incident response — rather than watching a recording of one.
ATS resume, GitHub portfolio and LinkedIn work, subject-wise interview questions, technical, HR and practical mock rounds, then repeated drives with hiring partners across Phagwara, Jalandhar and Ludhiana.
Find answers to the questions students ask before enrolling.
Three months, running as a fixed calendar: cybersecurity, networking and system administration; ethical hacking, web security and security operations; then advanced security, cloud, Python and AI automation with the capstone and placement preparation. Weekday, evening and weekend batches cover the same syllabus, and 1-on-1 training is available. Every class runs for 2 hours.

Send your question and a counsellor will call you back about batch timings, fees, EMI options, placement record, or whether this course fits your degree.
One call with a counsellor is usually enough to find out. Book a free demo class and see the lab before you decide.