IITM PRAVARTAK · Technology Innovation Hub of IIT Madras
A 10-month Online Certificate Programme built for early to mid-career professionals who want to grow, up-skill and adapt.
Online Certificate Programme in Cybersecurity & Ethical Hacking in the AI Era
Live masterclasses by IITM Pravartak faculty and leading industry experts.
2 Campus Immersion at IIT Madras Research Park.
Real Indian breach cases anchor every phase.
Use AI tools like Claude and Security Copilot in everyday security work.
Work on real Indian breach scenario, end to end.
Get admit card and admission letter as part of the admission kit.
Final-year students and recent graduates from CS, IT, electronics, or engineering backgrounds with programming basics and command-line comfort. The Foundation phase teaches cybersecurity from first principles - the Bug to Ransomware chain, Indian breach economics, networks, OS internals, and Active Directory - building toward role-ready proof at the capstone.
Working professionals already in IT support, DevOps, junior SOC, cloud engineering, or software engineering who want to deepen into cybersecurity. The programme calibrates existing technical foundations and adds the offensive depth, defensive operations, AI security, OT security, and GRC fluency that distinguish a security specialist from a tech-adjacent practitioner.
Open the programme with the boardroom lens. Map attacker P&L economics across 5 Indian cases (Star Health, JLR, Angel One, Pune SME, Bigbasket) covering 5 sectors and 5 attack types. Build a CyVaR model with an AI Breach Simulator and produce an industry-specific 1-page Cyber Risk Briefing.
The 50-year chain - software bugs to memory corruption to exploits to malware to ransomware - and the parallel detection stack (AV to IDS to EDR to SIEM). Write YARA and Snort rules. Trace Morris Worm to Stuxnet to WannaCry to LockBit as the foundational arc.
Python and Bash for security automation, REST APIs (VirusTotal, AbuseIPDB), AI/ML primer for security tooling. Use Cursor, Copilot, and Claude as daily coding partners with eval discipline - the 'prompt then verify' habit that prevents AI-generated security flaws from shipping.
OSI / TCP-IP, packet analysis with Wireshark, iptables firewall rules, Windows and Linux internals, Sysmon configuration, and Active Directory architecture - the technical floor every defender and attacker is expected to have.
Cryptography fundamentals (symmetric, asymmetric, hashing, TLS, PKI). Threat intelligence at strategic, tactical, and operational levels. MITRE ATT&CK matrix, Kill Chain, OSINT primer, and threat modelling (STRIDE, PASTA). Map a real Indian breach (Cosmos Bank or AIIMS) to ATT&CK techniques.
Comparative attacker P&L on 2 Indian cases · CyVaR model with AI Breach Simulator · industry-specific Cyber Risk Briefing · YARA + Snort rules · AI-augmented log parser and IP reputation script · Wireshark analysis report · AD security config · Kerberos hardening notes · ATT&CK-mapped Indian breach
OSINT mastery (Shodan, Maltego, Recon-ng), Nmap scanning, OWASP Top 10 deep dive (SQL injection, XSS, CSRF, broken access control), and Burp Suite workflow on DVWA.
Metasploit framework end-to-end, password attacks (John, Hashcat), Meterpreter post-exploitation, Linux privilege escalation, and pivoting fundamentals.
BloodHound and SharpHound for AD attack paths, Kerberoasting, Pass-the-Hash, DCSync, Golden Ticket. Static and dynamic malware analysis with Ghidra. AV evasion through obfuscation and packing.
Adversarial ML (FGSM, PGD), OWASP LLM Top 10, prompt injection, deepfake detection, and full pentest cycle on OWASP Juice Shop with HackTheBox practice.
2-day on-campus event at IIT Madras. Red Team CTF with reconnaissance through privilege escalation, AD compromise, and final flag capture. Includes 1-on-1 GitHub portfolio review with mentors, industry panel with cybersecurity professionals from Indian industry, and applied workshops on offensive and defensive craft.
SOC tier model, SIEM architecture, Microsoft Sentinel workspace setup, log ingestion via Azure Monitor Agent, and KQL detection queries calibrated to ATT&CK techniques.
Hypothesis-driven threat hunting, Microsoft Defender for Endpoint, advanced KQL with entity graphs, SANS PICERL incident response lifecycle, and ransomware IR simulation in Sentinel.
Logic App playbooks for automated containment, Microsoft Security Copilot promptbooks for multi-stage attack analysis, phishing header analysis (SPF/DKIM/DMARC), and the SOC 2.0 operating model with human-in-the-loop controls.
Zero Trust architecture, Azure Entra ID, Conditional Access, Privileged Identity Management, Defender for Cloud (CSPM), Azure network security, and IaC security with Terraform + Checkov, plus comparative coverage of AWS / GCP equivalents.
CI/CD security in GitHub Actions (SAST/DAST/SCA), Trivy container scanning, Kubernetes hardening with pod security standards and RBAC, and software supply chain (SolarWinds analysis, SBOM, Sigstore signing).
Operational Technology and ICS security fundamentals. OT versus IT architecture, the Purdue Enterprise Reference Architecture, ICS components (PLC, RTU, HMI, SCADA), OT protocols (Modbus, DNP3, OPC-UA), the IT/OT convergence risk and the OT incident chain from Stuxnet through the JLR breach. NIST SP 800-82 and IEC 62443 frameworks, passive OT vulnerability assessment, OT-specific incident response, and Indian regulatory context (CEA cybersecurity guidelines for the power sector, MeitY guidance on critical infrastructure).
Full pentest report (Juice Shop + HTB) · AD attack chain (Kerberoasting to DCSync) · Ghidra static analysis report · adversarial ML attack/defence report · 25+ KQL queries mapped to ATT&CK · IR simulation report · Logic App playbook YAML · Terraform IaC + Checkov scan · K8s hardening config · CI/CD pipeline YAML · OT/ICS architecture diagram with passive vulnerability assessment
ML for anomaly detection (Isolation Forest, autoencoders), NLP for phishing detection (BERT classifier), agentic AI architecture for security workflows with human-in-the-loop gates, and RAG over security knowledge bases (FAISS + embeddings) with hallucination-defence discipline.
Building secure AI products as a security professional - LLM red teaming, adversarial ML defence (FGSM / PGD with adversarial training), AI security audit frameworks, ISO 42001 AI management system principles, and MITRE ATLAS mapping.
ISMS structure (Clauses 4-10), Annex A 93 controls, statement of applicability, risk assessment process, audit evidence standards, and a mock ISO 27001 audit on a sample organisation with non-conformity raising.
DPDP Act 2023 deep dive (data fiduciary obligations, consent architecture, data principal rights, Section 9 minor protection), 72-hour CERT-In reporting, vendor risk management, and AI-assisted compliance artifact drafting (AI-augmented breach notification with human review).
Translating technical risk into financial language, CyVaR in board reports, cyber insurance fundamentals, sector-specific obligations (RBI, SEBI, IRDAI, MeitY), and stakeholder communication for the CISO seat - the boardroom layer that distinguishes a security professional from a security operator.
2-day on-campus event at IIT Madras. Red Team CTF with reconnaissance through privilege escalation, AD compromise, and final flag capture. Includes 1-on-1 GitHub portfolio review with mentors, industry panel with cybersecurity professionals from Indian industry, and applied workshops on offensive and defensive craft.
Pick one capstone scenario based on a real Indian breach archetype. Build the end-to-end AI-accelerated response - AI-augmented KQL detection, agentic containment workflows, forensic triage with Volatility, ATT&CK-mapped attack chain, ISO 27001 remediation, DPDP breach notification, and AI-drafted CISO report (human-reviewed). Showcased at Immersion 2 at the IIT Madras campus through hackathon and portfolio review.
0 1
A business-style report that puts a pure value on a company's cyber risk, built on real Indian breach cases.
0 2
A full penetration-test report: find the weaknesses in a target system the way an attacker would, then show how to fix them.
0 3
Detect, investigate, and respond to a live attack using the same tools (Microsoft Sentinel) real security teams use.
0 4
Secure a modern cloud setup against misconfiguration and attack, the way Indian product companies need.
0 5
Use AI to spot threats and speed up response - the skill that sets a 2026 security professional apart.
0 6
Respond end-to-end to a real Indian breach scenario, from detection to a leadership report.
Certificate Eligibility: Minimum 65% overall attendance and 30% marks in cumulative evaluations score.
IIITDM Kancheepuram
An Associate Professor and Head of the Department of Computer Science and Engineering at IIITDM Kancheepuram. He earned his PhD in Computer Science and Engineering from IIT Madras, along with an MTech in Electronics Design Technol...
Guest Faculty, IITM Pravartak
Mr. Syed Mohamed A is a Guest Faculty and Subject Matter Expert at IITM Pravartak Technologies Foundation. He is best known for his work in data centre operations, cloud infrastructure and artificial intelligence. He plays a key r...
Admissions
Pay ₹99 and complete a short application form.
start application
Our admissions team reviews your profile and schedules a 20-minute call.
Response within 3 business days
Receive your offer letter, complete payment, and join the cohort.
Next cohort: Nov 2026
Pay ₹99 and complete a short application form.
start application
Our admissions team reviews your profile and schedules a 20-minute call.
Response within 3 business days
Receive your offer letter, complete payment, and join the cohort.
Next cohort: Nov 2026
contact details
For any queries, you can Whatsapp us at
For any queries, you can contact us at
Join the Program
Copyright © Nolan Edutech Private Limited. All rights reserved
Address :- Incubex HSR21, 5th Main Rd, Sector 6, HSR Layout, Bengaluru, Karnataka 560102.