Home Cybersecurity Lab
Month one’s build: Kali Linux and Windows Server virtualised on VMware or VirtualBox, with a secure Linux installation, documented network and an implemented password policy.
- Kali
- VMware
Six months from your first Linux install to an industry-level AI security platform — ethical hacking and web security, SOC and SIEM operations, cloud security and DevSecOps, digital forensics and incident response, with AI automation throughout.
This is the six-month AI-Powered Cybersecurity certificate programme, written for someone starting straight after 12th. Six months, six modules each, and a set of mini projects at the end of every month. It sits between the three-month programme and the nine-month diploma, and what it buys over the shorter track is depth on the two things employers actually staff for: a full month of digital forensics, malware analysis and incident response, and a full month of cloud security and DevSecOps.
Key Highlights
This is the six-month AI-Powered Cybersecurity certificate programme, written for someone starting straight after 12th. Six months, six modules each, and a set of mini projects at the end of every month. It sits between the three-month programme and the nine-month diploma, and what it buys over the shorter track is depth on the two things employers actually staff for: a full month of digital forensics, malware analysis and incident response, and a full month of cloud security and DevSecOps. Month one is cybersecurity foundations and networking — the CIA triad, types of cyber attack, security domains, the threat landscape and career paths; hardware, operating systems, Windows and Linux administration, file systems and user management; then networking properly, with the OSI and TCP/IP models, IP addressing, subnetting, routing, switching, DNS, DHCP, NAT and VPN; virtualisation on VMware and VirtualBox with Kali Linux and Windows Server installed; Git and GitHub; and AI for cybersecurity. Month two is ethical hacking and web security: OSINT, Google dorking, WHOIS, DNS and subdomain enumeration; Nmap, Wireshark, Nikto, Gobuster and Nuclei; web technologies and the OWASP Top 10 with SQL injection, XSS, CSRF, file upload vulnerabilities and authentication bypass; Burp Suite Professional; and AI-assisted reconnaissance, report generation and vulnerability analysis. Month three is advanced ethical hacking and the SOC — Metasploit, Hydra, password attacks and wireless security; Windows security with Active Directory, Group Policy and privilege escalation basics; SOC fundamentals, blue team operations and the incident lifecycle; SIEM with Wazuh, Splunk and the ELK Stack; threat hunting with MITRE ATT&CK, IOCs and detection engineering; and AI-powered SOC work. Month four is cloud security and automation: AWS security across IAM, EC2, S3, CloudTrail and security groups; Azure IAM, Defender and Security Center; Docker and Kubernetes security; DevSecOps with CI/CD security, SAST, DAST and secret management; Python security automation; and the OpenAI and Gemini APIs for an AI security assistant and chatbot. Month five is digital forensics, malware analysis and incident response — evidence collection, chain of custody, memory and disk analysis; static and dynamic malware analysis, sandboxing and indicators of compromise; the incident response cycle; and threat intelligence with IOCs, TTPs, STIX, TAXII and threat feeds. Month six is the industry capstone and placement preparation. All lab work runs on your own virtual lab, on deliberately vulnerable applications such as DVWA and OWASP Juice Shop, and on TryHackMe, Hack The Box, the PortSwigger Web Security Academy and OverTheWire — systems you are permitted to test, with a trainer supervising.
Every module ends in something you have built and a trainer has reviewed, so the list below is work you will have done rather than topics you will have heard about.
Wazuh deployed by you, plus Splunk and the ELK Stack mapped to MITRE ATT&CK
The syllabus is arranged so every module produces an asset rather than a set of notes. You will cover month 1 — cybersecurity foundations & networking, month 2 — ethical hacking & web security, month 3 — advanced ethical hacking & soc, month 4 — cloud security & security automation, and finish with a live project built on Kali Linux & Windows Server, VMware & VirtualBox, Nmap & Wireshark. Modules run in the order a real project runs: foundations first, then the core skills, then applied work under supervision, then the portfolio and interview preparation that turn all of it into an offer letter.
The working knowledge the job description actually lists.
Month 3 — Advanced Ethical Hacking & SOC
A full month of blue team work — the part an L1 analyst is actually hired to do.
4 weeks · 24 sessions
Topics covered
The toolchain
Everything below is installed on the lab machines and used on live client work, not shown once in a slide and forgotten.
Any stream. Month one begins at the CIA triad and computer hardware and ends with your own cybersecurity lab on VMware or VirtualBox — the environment every later exercise runs in.
Month three is a full month of SOC work — Wazuh, Splunk, the ELK Stack, MITRE ATT&CK, detection engineering — and month five adds the incident response cycle. That combination is what an L1 analyst is actually hired to do.
Six months of evenings or weekends runs comfortably beside a BCA, B.Sc IT or first-year B.Tech, and finishes with a documented capstone well before campus placements begin.
Month five is the reason to choose this over the three-month track: evidence collection, chain of custody, memory and disk analysis, static and dynamic malware analysis and sandboxing are not covered in any shorter programme.
Weekend batches exist for people already working. If you handle desktops or networks today, month one will feel familiar and the cloud and DevSecOps work in month four is the fastest route to a better title.
If TryHackMe rooms left you able to follow a walkthrough but not to write the report afterwards, what changes here is a trainer reading your work each week and eight mini projects with deadlines attached.
Employers hiring an analyst want to know you can collect evidence without contaminating it, profile a suspicious binary and take an incident from detection to a lessons-learned write-up — and a whole month on exactly that is what separates this from a short course. That gap is the whole argument for this course: there is local demand, there are budgets, and there are very few trained people to hand the work to.

Build skills that hold up beyond the classroom.
What separates this from a playlist of tutorials is supervision on real work. From the second half of the course you build on live client projects with a trainer beside you, make decisions that have consequences, and correct them the following week. That loop is the skill. No employer in Phagwara will take your word for it without work they can inspect.
Be realistic about the money. A fresher who finishes with a working portfolio starts near the bottom of the band and moves quickly; someone who finishes with a certificate and nothing to show does not. The difference is entirely what you built.
The alternative is what most people try first: free videos, a cheap online course, six months of drifting, and knowledge you cannot demonstrate. A structured programme with live projects, a mentor who corrects you, an internship letter and a placement cell that actually calls employers is the difference between knowing the subject and being hired to do it.
Students reach the Phagwara centre from Banga, Nakodar, Kartarpur and the university belt, and the weekend batch exists so a job or a degree does not have to be paused to attend.
Linux and Windows administration and a full networking module — OSI and TCP/IP, subnetting, routing, switching, DNS, DHCP, NAT and VPN — before a single tool is opened.
OSINT and enumeration, Nmap, Wireshark, Nikto, Gobuster and Nuclei, then the OWASP Top 10 in Burp Suite Professional — SQL injection, XSS, CSRF, file upload and authentication bypass.
Wazuh, Splunk and the ELK Stack with log collection and analysis, blue team operations, the incident lifecycle, MITRE ATT&CK, IOCs, threat intelligence and detection engineering.
Evidence collection and chain of custody, memory and disk analysis, static and dynamic malware analysis, sandboxing, and the full detection-to-lessons-learned cycle.
AWS IAM, EC2, S3, CloudTrail and security groups; Azure IAM, Defender and Security Center; Docker and Kubernetes security; CI/CD security, SAST, DAST and secret management.
Python automation and the OpenAI and Gemini APIs for an AI security assistant and chatbot, then one industry-level AI security platform documented, deployed and hardened.

Complete the course with a portfolio of live projects and receive an industry-recognised certificate, plus a documented internship letter accepted by Punjab universities.
Recognised by employers across Punjab and beyond
Based on real client work, not a simulation
Live work you can show in any interview
CV review, mock interviews and hiring drives
Two certificates on completion — the course certificate and a separate capstone project certificate.
The roles this opens, what they pay in Punjab and beyond, and who is hiring for them — drawn from published job-market listings, not a brochure number.
Straight after 12th this is the usual first step — monitoring, triage and escalation on a real alert queue. Month three is its foundation.
Evidence collection, memory and disk analysis and the write-up afterwards. Month five is a whole month on this, and no shorter programme carries it.
Securing AWS and Azure environments and containers. Month four’s DevSecOps work maps straight onto it, and it is one of the hardest roles to fill locally.
Vulnerability assessment and penetration testing delivered as billable engagements, judged on the professional reporting standard month two teaches.
A newer title and the reason AI runs through every month — building the automation and detection tooling a modern SOC increasingly relies on.
Salary outlook — SOC Analyst / Security Analyst
Monitors, tests, defends and investigates the systems a business runs on. A year or two on a real alert queue usually doubles the starting figure.
Indicative ranges compiled from public job-market listings. Actual offers vary by employer, skillset and interview performance.
Month one’s build: Kali Linux and Windows Server virtualised on VMware or VirtualBox, with a secure Linux installation, documented network and an implemented password policy.
Two deliberately vulnerable applications worked end to end in Burp Suite Professional — SQL injection, XSS, CSRF, file upload and authentication bypass against the OWASP Top 10.
A network scanned with Nmap and Nuclei, traffic read in Wireshark, findings written to a professional standard — with AI report generation speeding the write-up, not replacing your judgement.
A SIEM you deployed yourself with real log collection, an AI log analyser over it, and a threat hunting report built on MITRE ATT&CK, IOCs and detection engineering.
Python automation on the OpenAI and Gemini APIs producing a security assistant and an automated vulnerability scanner, plus a cloud security assessment across AWS and Azure.
One platform in month six — an AI SOC platform, threat hunting platform, vulnerability scanner, security automation platform or security chatbot — documented with architecture and a user manual, pushed to GitHub and deployed with security hardening.
Every project moves through the same loop: understand the brief, build with guidance, then explain the decisions behind your work.
Take a real requirement apart before touching a tool — what is being asked, what it needs, and which part to build first.
Home Cybersecurity Lab
Work hands-on with your trainer watching the screen, so a wrong turn is caught in the same session rather than three weeks later.
DVWA & Juice Shop Assessments
Walk through what you built and why you built it that way. This is the interview rehearsal, run against every project rather than once at the end.
Professional Vulnerability Report
There are many places to learn this in Phagwara and the brochure syllabus looks similar at all of them. What differs is who teaches, whether you ever touch real work, and whether anyone picks up the phone after you have paid. techcadd has trained students across Punjab since 2007 on the same model: small batches, working practitioners as trainers, client projects as coursework.
Your trainer is not a full-time lecturer. They handle security work for techcadd’s services arm, so the examples in class are current rather than a case study from five years ago.
Month one ends with your own virtualised lab running Kali Linux and Windows Server. Every exercise after that happens in it, on DVWA and Juice Shop, or on TryHackMe, Hack The Box, PortSwigger Academy and OverTheWire — never against systems you have no permission to touch.
Offensive technique first, then detection, response and forensics — and the purple team practice of using each to improve the other, which is how mature security teams actually run.
Evidence handling, memory and disk analysis, malware sandboxing and the incident response cycle. No three-month course carries this, and it is what a serious employer asks about.
Month four builds against the real OpenAI and Gemini APIs — an AI security assistant, a security chatbot, an automated vulnerability scanner — rather than watching a recording of one.
ATS resume, GitHub and LinkedIn work, subject-wise interview questions across networking, Linux, security, hacking, SOC, SIEM, cloud and AI, then technical, HR and practical mock rounds and repeated drives with hiring partners.
Find answers to the questions students ask before enrolling.
Six months, running as a fixed calendar of six modules per month: cybersecurity foundations and networking; ethical hacking and web security; advanced ethical hacking and SOC; cloud security and security automation; digital forensics, malware analysis and incident response; then the industry capstone and placement preparation. Weekday, evening and weekend batches cover the same syllabus, and 1-on-1 training is available. Every class runs for 2 hours.

Send your question and a counsellor will call you back about batch timings, fees, EMI options, placement record, or whether this course fits your degree.
One call with a counsellor is usually enough to find out. Book a free demo class and see the lab before you decide.