Run a proper scan
Authenticated or unauthenticated, active or passive, internal or external — you build the scan plan that matches the engagement letter, not the one the tool defaults to.
Training · VA / CA · Vulnerability Assessment + Configuration Audit
A twelve-week practitioner programme that runs two disciplines in parallel: vulnerability assessment, from raw scanner output to a validated, risk-prioritised register; and configuration audit, from a hardening benchmark to a system you can prove is built to meet it. You work real lab tenants, production-grade scanners, and the evidence an auditor signs.
The misunderstood discipline
VA and CA are the two disciplines that touch every security programme, and the two most consistently misunderstood. A scanner dumps ten thousand findings; the practitioner validates the two hundred that are real; the configuration auditor checks whether the estate was ever built to a hardened standard — and whether it has drifted since. The programme trains both halves of that role.
01
Scanners produce findings. A practitioner produces a defensible risk register — validated, deduplicated, cleared of false positives, and weighted for business context. That gap is the whole discipline.
02
A once-a-year checklist produces a binder no-one reads and an estate that has drifted by February. Real configuration audit measures systems against a hardening benchmark, tracks the deviations that matter, and proves the baseline still holds between cycles.
03
Vulnerability teams rarely think in hardening baselines; configuration auditors rarely validate an exploit. The practitioner who can do both — find the vulnerability and prove the config that would have stopped it — is the one who gets hired and gets listened to.
Two parallel tracks. One practitioner.
The programme runs both tracks in parallel. They cross twice — at Validation (week 5) and Reporting (week 11) — where a single piece of evidence has to satisfy the risk owner who has to fix it and the auditor who has to sign it off.
What you do on the programme
Authenticated or unauthenticated, active or passive, internal or external — you build the scan plan that matches the engagement letter, not the one the tool defaults to.
You run a manual proof-of-concept against every high and critical, cull the false positives, consolidate duplicates, and overlay business context — the unglamorous work that turns ten thousand rows into the two hundred that are real.
Start from the CVSS base, apply temporal modifiers and an environmental score, then overlay the risk owner's own view. The scanner hands you a severity; your job is to justify the one you actually assign.
Measure a host, image, or cloud account against its CIS Benchmark and the hardening clauses inside ISO 27001, PCI-DSS, and NIST CSF. Every deviation gets recorded, and every deviation gets traced to the control it breaks.
Config exports, scan output, screenshots, before-and-after diffs — each one indexed, timestamped, and attached to the benchmark control it satisfies, so a hardened state is something you can show, not just claim.
Executive summary, scope statement, methodology, a findings narrative, a configuration-gap analysis, a risk-prioritised remediation roadmap, and a retest scope — the format an auditor will accept on the first read.
Sample week · Configuration audit · week 7 of 12
A representative week auditing a single tenant in the Cyberange lab against a hardening standard. Both tracks work the same environment in parallel, and Friday's deliverable is one integrated report that satisfies the risk owner who has to remediate and the auditor who has to sign it off.
Monday
Read the tenant's engagement letter, then decide which hardening baselines apply — the relevant CIS Benchmarks plus the configuration clauses of ISO 27001, PCI-DSS, and the sector regulator's framework. Document the baseline per asset class, and bound the scope with the risk owner.
Tuesday
Run authenticated vulnerability scans against the in-scope estate. In parallel, measure live configuration against the baselines — CIS-CAT runs, config exports, cloud-posture pulls. Two tracks, one tenant, same day.
Wednesday
Cull the scan output and run manual proof-of-concepts against the criticals, then cross-reference against Tuesday's configuration data: does a live vulnerability trace back to a control the benchmark said should have been hardened? More often than not, it does.
Thursday
Every validated finding and every configuration deviation mapped to its ISO Annex A control, PCI requirement, NIST CSF subcategory, and CIS Benchmark item — the same issue through four lenses. The cohort cross-checks each other's mappings.
Friday morning
Executive summary, risk-prioritised technical findings, a configuration-gap analysis mapped to the baselines, a prioritised remediation roadmap, and a retest scope — the one report a risk owner and an auditor will both accept.
Friday afternoon
An instructor — usually with prior audit-side experience — runs a mock review across the table. Your evidence, your scoping, and your control mappings all get challenged, while the cohort watches and grades.
Tooling coverage
Nessus, OpenVAS/Greenbone, nuclei, trivy and grype — plus authenticated-profile engineering and writing your own NASL and nuclei template checks.
OWASP ZAP, Burp Pro (Scanner), and nuclei web templates, with the false-positive thresholds and auth-flow recording that make them usable against a real app.
kube-bench, kube-hunter, Prowler, ScoutSuite and CloudSploit — CIS-benchmark-aligned configuration auditing across containers and cloud.
PingCastle, BloodHound (read-only), Purple Knight and ADRecon — posture and configuration, never exploitation.
CIS-CAT and OpenSCAP for benchmark scoring, config-baseline diffing, and evidence-vault patterns — workflow over vendor lock-in.
ISO 27001 Annex A, PCI-DSS 4.0, NIST CSF 2.0, NIST SP 800-53, SOC 2 Trust Services Criteria, and the CIS Benchmarks.
RBI Cybersecurity Framework, SEBI CSCRF, IRDAI guidelines, CERT-In Directions, NCIIPC CII guidance, and the DPDP Act 2023.
A template library covering executive summary, scope, methodology, findings, configuration-gap analysis, remediation roadmap, retest scope, and evidence index.
What you walk away with
Three full tenant assessments, with genuine validation work and real risk-owner sign-offs in your portfolio.
Three integrated VA and CA reports — framework-mapped, evidence-indexed, in the shape an auditor will actually accept.
You can move between ISO, PCI, NIST CSF, the CIS Benchmarks, and the major Indian-regulator frameworks in a single sitting — most candidates can speak one.
BFSI risk-and-compliance teams, MSSP assessment desks, internal-audit cyber units, and regulator-side assessment cells — reached through a referral, not a job portal.
Frameworks drilled
Practice
"An unvalidated vulnerability is only a finding. An unprioritised finding is only noise. And noise that no-one has tied back to a control and a fix isn't security work at all — it's paperwork waiting to get lost."
Weekend and weekday cohorts. Corporate cohorts on request. Particularly well suited to BFSI risk-and-compliance teams, internal-audit cyber units, and MSSP assessment desks.