Flagship Programme
Cybersecurity
Enrols as Cyber Security in the academy's catalogue.
Security is mostly not an entry-level field. Most people arrive through IT support or networking first, and this course is aimed squarely at that route. Anyone selling a three-month path straight into a security job is not being straight with you.
| Duration | 3 Months |
|---|---|
| Contact hours | 240 hours |
| Level | Intermediate |
| Modules | 6 |
| Topics | 24 (16 practical) |
| Fee | PKR 60,000 |
What the programme includes
- Live classes with a named trainer, on a published schedule
- Recordings of every session, so a missed class is not a lost one
- Marked assignments with written feedback
- Project work reviewed and verified by your trainer
- A final assessment
- A completion letter stating your attendance, results and verified work — independently verifiable by any employer
Syllabus
1. How attacks actually work
30 hoursReplacing the film version with the commercial reality.
-
What attackers want, and why you are a target
Money, resellable accounts, your contact list, a route into your employer, ransom. None of it requires you to be important.
-
Untargeted attacks and credential stuffing
hands on
Why being ordinary is not protection, and what password reuse actually costs.
-
The human is the weakest point
Why it is cheaper to convince someone to hand over a code than to defeat encryption.
-
The Pakistani threat picture
SIM swap, EasyPaisa and JazzCash fraud, WhatsApp account theft, fake job offers. Local and specific.
2. Networking for defenders
50 hoursEnough network knowledge to reason about traffic.
-
TCP/IP, ports and what is listening
hands on
Reading a connection and knowing what should not be there.
-
DNS, HTTP and TLS
hands on
How a certificate actually proves anything, and what a browser warning means.
-
Scanning and enumeration with nmap
hands on
In a lab you own. Scope and written authorisation covered before the first scan.
-
Reading traffic with Wireshark
hands on
Seeing credentials cross a network in plain text — once seen, never forgotten.
3. Systems and hardening
40 hoursMaking a machine harder to take.
-
Linux fundamentals for security work
hands on
Users, permissions, processes, logs and services.
-
Patching, and why it is the highest-value control
Unglamorous, unpopular, and the thing that would have stopped most real incidents.
-
Least privilege in practice
hands on
Shared admin logins, and why every named person needs their own account.
-
Backups you have actually restored
hands on
An untested backup is a hope. Restoring one is the exercise.
4. Web application security
50 hoursWhere most real vulnerabilities are found.
-
The OWASP Top Ten, demonstrated not recited
hands on
Each one shown working in a lab application.
-
Injection and broken access control
hands on
The two that cause the most real damage — including changing an id in a URL to read another user's record.
-
Using Burp Suite
hands on
Intercepting, modifying and replaying requests.
-
Writing the finding, not just finding it
hands on
A vulnerability nobody can understand or reproduce does not get fixed. Severity, reproduction steps, and the remediation.
5. Detection and response
40 hoursAssuming something will get through.
-
Logs, and what to keep
hands on
The evidence you will wish you had.
-
Recognising an incident in progress
Indicators, and the cost of a false alarm versus a missed one.
-
The first hour
hands on
Contain, preserve, communicate. In that order, and why improvising the third one damages an organisation most.
-
Phishing analysis
hands on
Headers, links and attachments — taking a real reported message apart.
6. Law, ethics and career reality
30 hoursThe part that keeps you employable and out of trouble.
-
PECA and the legal boundary in Pakistan
What unauthorised access means in law. Testing a system you were not asked to test is a crime, whatever your intent.
-
Scope, authorisation and the engagement letter
hands on
Never touching anything without it in writing.
-
Disclosure done responsibly
What to do when you find something in a system that is not yours.
-
How people really enter this field
Usually through IT support or networking first. Anyone selling a three-month route straight into a security job is not being straight with you.
Against the national standard
Pakistan's National Vocational & Technical Training Commission publishes a course-contents document for the trades it funds. This programme is mapped to Certified Ethical Hacker (CEH) — 12 weeks, 4 hours a day, 240 contact hours.
Published by NAVTTC and reproduced here so you can check our syllabus against it. We teach it to those hours: 240 contact hours over 12 weeks, the same as the standard. Read the NAVTTC document.
12 modules in the national standard
-
Introduction to CEH and LAB Setup
— week 1,
20 hours
Motivational Lecture Course Intro Success stories Job Market Intro to CEH Roles of Security Expert What is cyberspace. What is hacker and its... · Details maybe seen at Annexure-I · What is virus and its different types · Different types of attacks · Setup virtual machine for LAB environment · Install and configure Kali Linux · Intro Kali Linux. Important Linux Commands · Get familiar with OSI Lay...
-
Information Gathering
— week 2,
20 hours
Shodan and IoT Device Information · Details maybe seen at · Maltego for Data Link Analysis · The Harvester for Gathering Emails and Subdomains · Spokeo and People Search Tools · Data Scraping Techniques · Google Dorks and Advanced Search Queries · Geolocation and IP Tracing
-
Scanning & Enumeration
— week 3,
20 hours
Network Scanning Fundamentals Types of Network Scans Port Scanning Techniques · Details maybe seen at Annexure-I · TCP Connect Scanning UDP Scanning Banner Grabbing · Network Enumeration Methods Scanning Tools and Utilities Nmap - Network Mapper · Ping Sweeps and Sweep Detection Network Mapping and Topology Discovery Vulnerability Scanning · Operating System Detection Automated Scanning Workflows...
-
Vulnerability Analysis
— week 4,
20 hours
Vulnerability Assessment Fundamentals Types of Vulnerabilities · Details maybe seen at · Vulnerability Scanning Techniques · Automated Vulnerability Scanners · Manual Vulnerability Assessment · Common Vulnerability Databases Common Vulnerability Scoring System (CVSS) · Vulnerability Management Practices · Vulnerability Analysis Tools
-
System Hacking & Malware Analysis
— week 5,
20 hours
System Hacking Fundamentals Password Cracking Techniques Password Cracking Tools · Details maybe seen at Annexure-I · Privilege Escalation Methods Exploiting Weak Passwords Brute Force and Dictionary Attacks · Cracking Windows Passwords Cracking Linux Passwords Privilege Escalation on Windows · Privilege Escalation on Linux Rootkits and Trojans Hiding Files and Processes Covering Tracks and Removi...
-
Network Sniffing & Wifi Hacking
— week 6,
20 hours
Introduction to Network Packet Sniffing Legal and Ethical Aspects of Sniffing Wireshark and Packet Capture Basics · Details maybe seen at Annexure-I · Analyzing Captured Packets Packet Filtering and Display Options · Advanced Protocol Analysis Packet Decryption Techniques Capturing and Analyzing SSL/TLS Traffic · Sniffing on Wireless Networks Sniffing on Switched Networks · ARP Spoofing and MITM A...
-
Social Engineering & Session Hijacking
— week 7,
20 hours
Introduction to Social Engineering Legal and Ethical Aspects of Social Engineering Information Gathering for Social Engineering · Details maybe seen at Annexure-I · Pretexting and Impersonation Phishing and Spear Phishing Attacks · Baiting and Tailgating Attacks Influence and Persuasion Techniques · Manipulating Human Behavior Building Trust and Rapport Elicitation and Information Extraction · Psy...
-
DOS/DDOS & SQL Injection Attack
— week 8,
20 hours
Introduction to Denial of Service Attacks Legal and Ethical Aspects of DoS Attacks Types of DoS Attacks (e.g., Flood, Amplification, Logic Bombs) · Details maybe seen at Annexure-I · Distributed Denial of Service (DDoS) Attacks Botnets and Botnet Herders · Reflective and Amplification Attacks Protocol-Based Attacks (e.g., SYN Flood) · Application Layer Attacks (e.g., HTTP Flood) Denial of Service...
-
Hacking Web Servers & Web Applications
— week 9,
20 hours
Introduction to Web Server Hacking Legal and Ethical Aspects of Web Server Hacking Web Server Fundamentals (e.g., Apache, Nginx) · Details maybe seen at Annexure-I · Information Gathering and Reconnaissance Vulnerability Scanning and Enumeration · Web Server Misconfigurations Directory Traversal Attacks · File Inclusion Vulnerabilities SQL Injection in Web Servers Remote Code Execution (RCE) · Exp...
-
Hacking Mobile Platforms
— week 10,
20 hours
Introduction to Mobile Platform Security Legal and Ethical Aspects of Mobile Hacking · Details maybe seen at Annexure-I · Mobile Platform Fundamentals (iOS, Android) Mobile Application Security Models · Identifying Mobile Security Vulnerabilities Setting Up a Mobile Hacking Environment · Device and Emulator Testing Jailbreaking (iOS) and Rooting (Android) · Analyzing Mobile Apps for Vulnerabilitie...
-
Cryptography & Bug Bounty
— week 11,
20 hours
Introduction to Cryptography Legal and Ethical Aspects of Cryptography Basic Concepts of Cryptography (Encryption, Decryption) · Details maybe seen at Annexure-I · Classical Cryptography (Caesar, Vigen re, etc.) Modern Cryptography Techniques (AES, RSA, ECC, etc.) · Cryptographic Hash Functions (MD5, SHA, etc.) Public Key Infrastructure (PKI) Cryptographic Protocols (SSL/TLS, SSH, etc.) · Cryptana...
-
Final Exam and Assessment
— week 12,
20 hours
Details maybe seen at Annexure-I Final Project · Description · Introduction to CEH and LAB Setup · Hands-on Practice on LAB Setup for testing Hands-on Practice on an Information Gathering · Information Gathering · Investigate a suspicious domain or website associated with a potential security incident. Analyze the domain registration details, check for... · Scanning & Enumeration · Conduct a compr...
Before, and after
Before you start
-
Comfortable with computers and networks
Not a first computing course. CCNA or equivalent networking is an advantage.
-
Free: Cybersecurity Fundamentals
Recommended before enrolling.
Where it leads
-
CCNA
The networking depth most security roles expect.
-
CCNP
For those going down the network engineering route.
Roles this prepares you for
-
IT Support with security responsibility
The most common genuine first step, and this programme is aimed squarely at it.
-
SOC Analyst (Tier 1)
Monitoring and triage. Usually requires networking depth as well.
-
Junior Security Analyst
Typically reached after one to two years in IT or networking, not directly from a course.
These are the roles the programme is aimed at. BvLogic Academy does not guarantee employment, an income, or a timeframe — and you should be careful with any institute that does.
Other courses
- Full Stack Development · 3 Months
- AI & Generative AI · 3 Months
- Digital Marketing + AI · 3 Months
- Python Development · 3 Months
Interested in this programme?
Try the subject free first — there is no reason to pay before you know you like it.
Browse the free courses Take the career test