Live Workshops

Short, intense, hands-on.

One to three days on a single topic, taught live in small cohorts. You spend most of the time in labs. Every seat includes the recording, the lab guide, and a certificate of completion.

Format

Live online or on-site

Timezone

IST · UTC+5:30

Cohort size

Capped for lab support

Includes

Recording · Lab guide · Certificate

Language

English / Hindi

Offensive Security

Web Application Penetration Testing

Work through the OWASP Top 10 the way an assessor does — against a deliberately vulnerable target, with the same tooling and reporting discipline we use on client engagements.

2 days Intermediate Live online

What you'll be able to do

  • Map and enumerate an application's real attack surface
  • Find and exploit injection, access-control and authentication flaws
  • Chain low-severity findings into a demonstrable business impact
  • Write a finding the way a client will actually act on it

Agenda

  1. Recon and mapping · scoping an application honestly
  2. Injection: SQL, command, template
  3. Broken access control and IDOR at scale
  4. Authentication, session handling and JWT failures
  5. Reporting: severity, evidence and remediation that lands
Tools
Burp Suite Community, OWASP ZAP, ffuf, browser dev tools
Prerequisites
Comfortable with HTTP, basic Linux command line. No prior pentesting required.
Lab requirements
Laptop with 8 GB RAM, admin rights, and virtualization enabled. Lab VM image supplied a week ahead.
Who it's for
Developers, QA engineers, and security analysts moving into offensive work.

Dates to be announcedIST

Cloud Security

Cloud Security Essentials — AWS

The misconfigurations that actually cause cloud breaches — identity, storage exposure and network boundaries — found and fixed in a live AWS account you control.

2 days Intermediate Live online

What you'll be able to do

  • Reason about IAM policies and spot privilege-escalation paths
  • Detect and remediate public exposure of storage and compute
  • Design VPC boundaries that survive a compromised workload
  • Turn on the logging you will need before an incident, not after

Agenda

  1. The shared responsibility model, applied honestly
  2. IAM: policies, roles, and the escalation paths people miss
  3. S3, EBS and snapshot exposure
  4. VPC design, security groups and egress control
  5. CloudTrail, GuardDuty and building a usable audit trail
Tools
AWS Console, AWS CLI, ScoutSuite, Prowler
Prerequisites
Basic AWS familiarity — you have deployed something before. No certification required.
Lab requirements
Laptop with a modern browser and an AWS account with billing enabled. Free-tier is sufficient; lab spend is under a dollar.
Who it's for
Cloud and DevOps engineers, architects, and security teams inheriting a cloud estate.

Dates to be announcedIST

Blue Team

SOC Analyst Fundamentals

What a first-line analyst actually does across a shift: triage, escalate, and write the note the next analyst needs. Built from our managed SOC playbooks.

3 days Beginner Live online

What you'll be able to do

  • Triage an alert queue under time pressure without losing the real one
  • Read logs and correlate events across sources
  • Separate a true positive from noise, and justify the call
  • Escalate with the context an incident responder needs

Agenda

  1. How a SOC runs: tiers, shifts, SLAs and handover
  2. Log sources and what each one can and cannot tell you
  3. SIEM querying and building a usable detection
  4. Phishing triage end to end
  5. Incident escalation, documentation and handover discipline
Tools
Splunk / Elastic (lab instance provided), CyberChef
Prerequisites
Basic networking — you know what an IP, a port and DNS are. Genuine entry point into security.
Lab requirements
Laptop with a modern browser. All lab infrastructure is hosted; nothing to install.
Who it's for
Graduates and career changers targeting a first security role, and IT support staff moving into security.

Dates to be announcedIST

GRC & Compliance

ISO 27001 ISMS Implementation

A practical working session for the people who will own the controls — risk assessment through to management review, using your own context rather than a generic case study.

2 days Intermediate Live online or on-site

What you'll be able to do

  • Scope an ISMS without making it unmanageably large
  • Run a risk assessment that produces decisions, not a spreadsheet
  • Select and justify Annex A controls defensibly
  • Prepare evidence your certification auditor will accept

Agenda

  1. Scoping and the statement of applicability
  2. Risk assessment and treatment, done practically
  3. Annex A control selection and justification
  4. Documentation: what you need and what you do not
  5. Internal audit and management review
Tools
Provided risk register and SoA templates
Prerequisites
You own or will own compliance in your organisation. No prior ISO experience assumed.
Lab requirements
Laptop with a spreadsheet application.
Who it's for
Compliance officers, IT managers, internal auditors and control owners.

Dates to be announcedIST

GRC & Compliance

PCI DSS v4.0 Implementation

Scoping, segmentation and evidence for the teams who run PCI controls day to day — and what your assessor will ask for when the time comes.

2 days Intermediate Live online or on-site

What you'll be able to do

  • Define and defend your cardholder data environment scope
  • Use segmentation to reduce scope legitimately
  • Understand what changed in v4.0 and what it means for you
  • Assemble evidence in the form an assessor expects

Agenda

  1. Scoping the CDE and the cost of getting it wrong
  2. Segmentation strategy and validation
  3. v4.0 changes and the customised approach
  4. Requirement walkthrough for control owners
  5. Evidence preparation and common assessment failures
Tools
Provided scoping worksheet and evidence checklist
Prerequisites
Involvement in payment systems, infrastructure or compliance.
Lab requirements
Laptop with a spreadsheet application.
Who it's for
Engineering, infrastructure and compliance teams preparing for a PCI DSS assessment.

Dates to be announcedIST

Awareness

Phishing & Social Engineering Defence

A short, non-technical session for whole teams — how modern phishing actually works, and how to make reporting the reflex instead of clicking.

Half day All staff Live online or on-site

What you'll be able to do

  • Recognise current phishing, vishing and business email compromise patterns
  • Understand why smart people click, and design around it
  • Know exactly what to do in the sixty seconds after a suspicious message

Agenda

  1. How attacks are built and targeted today
  2. Live teardown of real-world lures
  3. Invoice fraud and BEC for finance teams
  4. Reporting: making it fast and blame-free
Tools
None — non-technical session
Prerequisites
None.
Lab requirements
None.
Who it's for
Whole organisations, and finance or executive teams specifically.

Scheduled on requestIST

FAQ

Before you register

Are the workshops recorded?

Yes. Every registered attendee receives the recording and the lab guide after the session, and keeps access to them. Labs themselves are live-only, so attend if you can.

Do I need prior security experience?

It depends on the workshop — each one lists its prerequisites and level above. SOC Analyst Fundamentals and Phishing Defence are genuine entry points; the pentesting and cloud workshops assume some technical background.

What do I need on my machine?

Each workshop lists its lab requirements. Please check these before registering — an underpowered laptop is the single most common reason someone cannot follow the labs.

Do I get a certificate?

Yes, a certificate of completion naming the workshop and contact hours. It is a record of attendance and practical work, not an accredited certification exam.

Can you run this for just my team?

Yes — any workshop can run privately for a single organisation, on-site or online, adapted to your environment. See corporate training.

How do I pay?

Register your interest and we will confirm your seat with an invoice and payment details. Seats are held once payment is confirmed.

Next step

Register your interest

Tell us which workshop and we will confirm dates, seat availability and payment details.

info@cyberintelix.com · +91 92118 62224