Defenders and ethical hackers, on call for the real attack surface.
A blue-team-first security curriculum — network and web security, identity, cryptography, OS hardening, incident response, cloud security and offensive tooling — taught by engineers who have run real production SOCs.
One payment for the seat, with — of InfraBuild Labs platform access included.
We could not reach the billing service just now. Ask us for the current cohort fee and we will send it straight back.
Referral applied:
Enrol now → Questions first? Talk to us →Checkout runs on the InfraBuild Labs platform. Every application is reviewed by hand, and your seat is confirmed once it is approved.
Six weeks, ten modules, built the way a security team is built — foundations first, then the network, then the application, then the response.
CIA triad, threat models, the attack lifecycle (Cyber Kill Chain, MITRE ATT&CK), risk vs vulnerability.
TCP/IP, firewalls, IDS/IPS with Snort and Suricata, VPNs, segmentation, packet capture in Wireshark.
Symmetric vs asymmetric, hashing, the TLS handshake, certificates, key management, OpenSSL hands-on.
AuthN vs AuthZ, MFA, OAuth/OIDC, SAML, IAM in AWS and Azure, least privilege, RBAC vs ABAC.
Linux hardening to CIS, Windows GPOs, EDR basics, patching, secure baselines, audit logging.
OWASP Top 10 in depth — injection, auth flaws, XSS, CSRF, SSRF, broken access control. Burp labs.
Recon with Nmap, enumeration, exploitation with Metasploit, privilege escalation, lateral movement.
The NIST IR lifecycle — triage, containment, eradication, recovery, postmortems, SIEM hunting in Splunk.
AWS shared responsibility, IAM, KMS, VPC, GuardDuty, Security Hub, CloudTrail, posture management.
SOC 2, ISO 27001, NIST CSF, PCI-DSS, risk frameworks, audit evidence, policies, vendor risk.
The tools named in the job descriptions you are aiming at — learned in the order they turn up in real work.
If one of these sounds like you, you will be in the right cohort. If none of them do, tell us and we will point you at the track that fits.
Enter security from scratch on a hands-on blue-team and ethical-hacking path.
Add security depth — network, web, cloud — to the IT skills you already have.
Ship secure code: OWASP, threat modelling, secrets management, DevSecOps.
Move from sysadmin, support or audit into SOC, GRC or pentesting.
Not topics covered — things you can do on your own once the six weeks are behind you.
The job titles this curriculum is built against. We teach to the work these roles do, not to a certificate.
The things people ask us on the call, answered here so you do not have to book one first.
The next batch is enrolling now. Three evenings a week, six weeks, and every application read by a human before a seat is confirmed.