IITM PRAVARTAK · Technology Innovation Hub of IIT Madras

Certificate Programme in Cybersecurity & Ethical Hacking in the AI Era

A 10-month Online Certificate Programme built for early to mid-career professionals who want to grow, up-skill and adapt.

Graduates, Tech Freshers & Upskillers
0-4 yrs of experience
10 Months
Live Online Classes
Hero Image
NOV
2026
Next
Cohort

Online Certificate Programme in Cybersecurity & Ethical Hacking in the AI Era

OVERVIEW

Programme Highlights

Live Online Sessions

Live masterclasses by IITM Pravartak faculty and leading industry experts.

2 Campus Immersion

2 Campus Immersion at IIT Madras Research Park.

Case Based-learning

Real Indian breach cases anchor every phase.

AI Co-Pilot Workflows

Use AI tools like Claude and Security Copilot in everyday security work.

Real-World Capstone

Work on real Indian breach scenario, end to end.

Admission Kit

Get admit card and admission letter as part of the admission kit.

PROGRAMME PATHWAY

What You'll Learn

Tech freshers

Tech freshers

Final-year students and recent graduates from CS, IT, electronics, or engineering backgrounds with programming basics and command-line comfort. The Foundation phase teaches cybersecurity from first principles - the Bug to Ransomware chain, Indian breach economics, networks, OS internals, and Active Directory - building toward role-ready proof at the capstone.

Upskillers (0-4 years in IT / DevOps / Cloud / Engineering)

Upskillers (0-4 years in IT / DevOps / Cloud / Engineering)

Working professionals already in IT support, DevOps, junior SOC, cloud engineering, or software engineering who want to deepen into cybersecurity. The programme calibrates existing technical foundations and adds the offensive depth, defensive operations, AI security, OT security, and GRC fluency that distinguish a security specialist from a tech-adjacent practitioner.

01 Foundation
10 weeks

Cyber-Economics & Indian Breach Cases

Open the programme with the boardroom lens. Map attacker P&L economics across 5 Indian cases (Star Health, JLR, Angel One, Pune SME, Bigbasket) covering 5 sectors and 5 attack types. Build a CyVaR model with an AI Breach Simulator and produce an industry-specific 1-page Cyber Risk Briefing.

Bug to Ransomware: First Principles

The 50-year chain - software bugs to memory corruption to exploits to malware to ransomware - and the parallel detection stack (AV to IDS to EDR to SIEM). Write YARA and Snort rules. Trace Morris Worm to Stuxnet to WannaCry to LockBit as the foundational arc.

Programming, AI Primer & AI Co-pilot Workflows for Security

Python and Bash for security automation, REST APIs (VirusTotal, AbuseIPDB), AI/ML primer for security tooling. Use Cursor, Copilot, and Claude as daily coding partners with eval discipline - the 'prompt then verify' habit that prevents AI-generated security flaws from shipping.

Networks, OS Internals & Identity

OSI / TCP-IP, packet analysis with Wireshark, iptables firewall rules, Windows and Linux internals, Sysmon configuration, and Active Directory architecture - the technical floor every defender and attacker is expected to have.

Cryptography, Threat Intel & ATT&CK

Cryptography fundamentals (symmetric, asymmetric, hashing, TLS, PKI). Threat intelligence at strategic, tactical, and operational levels. MITRE ATT& CK matrix, Kill Chain, OSINT primer, and threat modelling (STRIDE, PASTA). Map a real Indian breach (Cosmos Bank or AIIMS) to ATT& CK techniques.

Tools

Python Bash Wireshark Nmap iptables Sysmon YARA Snort SonarQube Cursor Copilot Claude MITRE ATT&CK Navigator Google Sheets (CyVaR)

Foundation mini-projects

Comparative attacker P&L on 2 Indian cases · CyVaR model with AI Breach Simulator · industry-specific Cyber Risk Briefing · YARA + Snort rules · AI-augmented log parser and IP reputation script · Wireshark analysis report · AD security config · Kerberos hardening notes · ATT&CK-mapped Indian breach

02 Core
18 weeks

Recon, Scanning & Web Application Attacks

OSINT mastery (Shodan, Maltego, Recon-ng), Nmap scanning, OWASP Top 10 deep dive (SQL injection, XSS, CSRF, broken access control), and Burp Suite workflow on DVWA.

Exploitation & Post-Exploitation

Metasploit framework end-to-end, password attacks (John, Hashcat), Meterpreter post-exploitation, Linux privilege escalation, and pivoting fundamentals.

AD Attacks, Malware Analysis & AV Evasion

BloodHound and SharpHound for AD attack paths, Kerberoasting, Pass-the-Hash, DCSync, Golden Ticket. Static and dynamic malware analysis with Ghidra. AV evasion through obfuscation and packing.

AI Security & CTF Practice

Adversarial ML (FGSM, PGD), OWASP LLM Top 10, prompt injection, deepfake detection, and full pentest cycle on OWASP Juice Shop with HackTheBox practice.

SOC Operations & Microsoft Sentinel

SOC tier model, SIEM architecture, Microsoft Sentinel workspace setup, log ingestion via Azure Monitor Agent, and KQL detection queries calibrated to ATT&CK techniques.

Threat Hunting, EDR & Incident Response

Hypothesis-driven threat hunting, Microsoft Defender for Endpoint, advanced KQL with entity graphs, SANS PICERL incident response lifecycle, and ransomware IR simulation in Sentinel.

SOAR, Phishing & AI-Augmented SOC

Logic App playbooks for automated containment, Microsoft Security Copilot promptbooks for multi-stage attack analysis, phishing header analysis (SPF/DKIM/DMARC), and the SOC 2.0 operating model with human-in-the-loop controls.

Cloud Security, Zero Trust & Multi-Cloud

Zero Trust architecture, Azure Entra ID, Conditional Access, Privileged Identity Management, Defender for Cloud (CSPM), Azure network security, and IaC security with Terraform + Checkov, plus comparative coverage of AWS / GCP equivalents.

DevSecOps, Container & Supply Chain Security

CI/CD security in GitHub Actions (SAST/DAST/SCA), Trivy container scanning, Kubernetes hardening with pod security standards and RBAC, and software supply chain (SolarWinds analysis, SBOM, Sigstore signing).

OT and ICS Security Fundamentals

Operational Technology and ICS security fundamentals. OT versus IT architecture, the Purdue Enterprise Reference Architecture, ICS components (PLC, RTU, HMI, SCADA), OT protocols (Modbus, DNP3, OPC-UA), the IT/OT convergence risk and the OT incident chain from Stuxnet through the JLR breach. NIST SP 800-82 and IEC 62443 frameworks, passive OT vulnerability assessment, OT-specific incident response, and Indian regulatory context (CEA cybersecurity guidelines for the power sector, MeitY guidance on critical infrastructure).

Tools in this phase

Burp Suite Metasploit BloodHound Ghidra HackTheBox Microsoft Sentinel KQL Defender XDR Logic Apps Security Copilot Azure (Entra, Conditional Access, Defender for Cloud) Terraform Checkov Trivy Kubernetes ICS-CERT advisories IEC 62443 references

Core mini-projects

Full pentest report (Juice Shop + HTB) · AD attack chain (Kerberoasting to DCSync) · Ghidra static analysis report · adversarial ML attack/defence report · 25+ KQL queries mapped to ATT&CK · IR simulation report · Logic App playbook YAML · Terraform IaC + Checkov scan · K8s hardening config · CI/CD pipeline YAML · OT/ICS architecture diagram with passive vulnerability assessment

03 Industry Readiness
9 weeks

AI for Cybersecurity Deep

ML for anomaly detection (Isolation Forest, autoencoders), NLP for phishing detection (BERT classifier), agentic AI architecture for security workflows with human-in-the-loop gates, and RAG over security knowledge bases (FAISS + embeddings) with hallucination-defence discipline.

AI Product Security & Red Teaming

Building secure AI products as a security professional - LLM red teaming, adversarial ML defence (FGSM / PGD with adversarial training), AI security audit frameworks, ISO 42001 AI management system principles, and MITRE ATLAS mapping.

ISO 27001 & Risk Management

ISMS structure (Clauses 4-10), Annex A 93 controls, statement of applicability, risk assessment process, audit evidence standards, and a mock ISO 27001 audit on a sample organisation with non-conformity raising.

DPDP Act, Privacy & GRC Operations

DPDP Act 2023 deep dive (data fiduciary obligations, consent architecture, data principal rights, Section 9 minor protection), 72-hour CERT-In reporting, vendor risk management, and AI-assisted compliance artifact drafting (AI-augmented breach notification with human review).

Cyber Risk Strategy & Boardroom Communication

Translating technical risk into financial language, CyVaR in board reports, cyber insurance fundamentals, sector-specific obligations (RBI, SEBI, IRDAI, MeitY), and stakeholder communication for the CISO seat - the boardroom layer that distinguishes a security professional from a security operator.

Tools in this phase

Azure OpenAI LangChain FAISS Foolbox / ART BERT classifiers ISO 27001 audit templates DPDP compliance tooling MITRE ATLAS Excel risk register CyVaR Sheets
04 Campus Immersion

Immersion 1: Red Team CTF

2-day on-campus event at IIT Madras Research Park. Red Team CTF with reconnaissance through privilege escalation, AD compromise, and final flag capture. Includes 1-on-1 GitHub portfolio review with mentors, industry panel with cybersecurity professionals from Indian industry, and applied workshops on offensive and defensive craft.

Immersion 2: AI-Accelerated Incident Response on an Indian Breach Scenario

Pick one capstone scenario based on a real Indian breach archetype. Build the end-to-end AI-accelerated response - AI-augmented KQL detection, agentic containment workflows, forensic triage with Volatility, ATT& CK-mapped attack chain, ISO 27001 remediation, DPDP breach notification, and AI-drafted CISO report (human-reviewed). Showcased at Immersion 2 at the IIT Madras Research Park through hackathon and portfolio review.

Portfolio

Graduate with proof, not just a certificate.

0 1

Cyber Risk Briefing for the Boardroom

A business-style report that puts a pure value on a company's cyber risk, built on real Indian breach cases.

Risk · Communication

0 2

Ethical Hacking Report

A full penetration-test report: find the weaknesses in a target system the way an attacker would, then show how to fix them.

Ethical Hacking · Penetration Testing

0 3

Security Operations and Incident Response Pack

Detect, investigate, and respond to a live attack using the same tools (Microsoft Sentinel) real security teams use.

Performance Marketing · Paid Media

0 4

Cloud Security Project

Secure a modern cloud setup against misconfiguration and attack, the way Indian product companies need.

Cloud Security · DevSecOps

0 5

AI for Security Project

Use AI to spot threats and speed up response - the skill that sets a 2026 security professional apart.

AI Security · Automation

0 6

Capstone: AI-Powered Breach Response

Respond end-to-end to a real Indian breach scenario, from detection to a leadership report.

Capstone · End-to-End Defence

BENEFITS

What You Earn At The End

Live online masterclasses delivered by IITM Pravartak faculty

Live online masterclasses delivered by IITM Pravartak faculty

Certification by IITM Pravartak

Certification by IITM Pravartak

Certificate Eligibility: Minimum 65% overall attendance and 30% marks in cumulative evaluations score.

Live online sessions with Industry experts

Live online sessions with Industry experts

Two Immersive 2 day Campus Immersion at IIT Madras Research Park (Optional)

Two Immersive 2 day Campus Immersion at IIT Madras Research Park (Optional)

Pick one real Indian cyber breach scenario and build an end-to-end AI-powered cybersecurity solution

Pick one real Indian cyber breach scenario and build an end-to-end AI-powered cybersecurity solution

IITM Pravartak faculty

Learn from those who've done it.

Prof. Dr. Noor Mahammad SK,

Prof. Dr. Noor Mahammad SK,

IIITDM Kancheepuram

An Associate Professor and Head of the Department of Computer Science and Engineering at IIITDM Kancheepuram. He earned his PhD in Computer Science and Engineering from IIT Madras, along with an MTech in Electronics Design Technol...

Mr. Syed Mohamed A

Mr. Syed Mohamed A

Guest Faculty, IITM Pravartak

Mr. Syed Mohamed A is a Guest Faculty and Subject Matter Expert at IITM Pravartak Technologies Foundation. He is best known for his work in data centre operations, cloud infrastructure and artificial intelligence. He plays a key r...

Applications are open for the November 2026 cohort.
Seats are limited.