Training catalogue · Five tracks
Hours on the range, not hours in a slide deck.
Five specialized tracks built for both individual and corporate teams. Our curriculum doesn't rely on outdated textbooks—it’s powered by the exact same live telemetry and engagement data our consulting practice tackles every Monday morning. Plus, you'll learn directly from active industry operators, not career academics.
Track · Defensive operations
SOC
Tier 1 to Tier 3 analyst tiers, working real telemetry.
Cohorts work a live alert queue replayed from real engagement data, not a curated lab. Triage, escalation, investigation and incident command are each a separate tier, and each has its own assessment. Instructors are operators from the consulting practice.
- Alert queue replayed from real customer telemetry
- Tier-1 / Tier-2 / Tier-3 progression with formal sign-off
- Cohort chat and a mentor log so you learn from the group
Track · Forensics & response
DFIR
Six forensic specialisms across fourteen weeks.
Disk, memory, network, log, mobile, and cloud forensics — each with its own case file, evidence intake, and chain-of-custody discipline. By week fourteen every cohort member has built and defended a multi-stream attack reconstruction.
- Four-stream evidence intake (disk · memory · network · log) per case
- You'll get hands-on with Autopsy, Volatility, Wireshark, plaso, KAPE and Velociraptor
- Chain-of-custody discipline that survives a court / regulator pull
Track · Cyber Threat Intelligence
Threat Intelligence
Strategic, operational, and tactical CTI tradecraft.
CTI is taught the way the consulting practice does it — pivot-driven investigation, Diamond Model attribution, F3EAD intelligence cycle, and report-writing that survives a CISO debrief. Cohorts produce an actor dossier as their capstone.
- Pivot graph investigation against a tracked APT
- Diamond Model + F3EAD cycle as the operating framework
- TLP discipline, peer-share via IB-CART, intel-product authoring
Track · Offensive · Pentest
Pentest
Web, mobile, network, Active Directory, cloud.
Twelve weeks across the five attack surfaces. Each surface gets its own five-phase curriculum (recon, enumeration, exploitation, post-exploitation, reporting) on a live range with production-grade targets. The capstone is an end-to-end engagement on a small unfamiliar estate.
- Each surface gets its own five-phase curriculum
- You'll get hands-on with Burp, sqlmap, nmap, BloodHound, metasploit and YARA
- Capstone: a one-week black-box engagement against an unseen estate
Track · VA / CA
VA / CA
Vulnerability assessment and compliance audit, end to end.
The full pipeline: scope and discover, scan, configure-audit against CIS / STIG / PCI, validate findings through CVSS / EPSS / KEV, write the report. Cohorts ship a real assessment against a sample estate as the capstone.
- Tooling: Nessus · OpenVAS · Qualys · CIS-CAT · OpenSCAP · Tenable
- Prioritisation: CVSS v3.1 · EPSS · CISA KEV · manual triage
- Final deliverable: an executive summary and a technical report, with a remediation guide
For organisations
Run any of the five tracks as a corporate cohort.
Tailored to your stack, your regulators, and your team's current capability. Outcomes mapped to a skill matrix you can put in front of your CHRO and your CISO together.
Scope a corporate cohortFor students
Apply for a sponsored seat via the ISAC Foundation.
Seats funded by CSR partners for students from under-represented backgrounds. Application is open year-round; selection is based on demonstrable interest, not pedigree.
ISAC Foundation