courseCyber SecuritybeginnerFeatured

Geek Certified Cyber Security Professional (GCCSP)

This 12-month career transformation program provides practical training in ethical hacking methodology, Linux & network security, web application penetration testing, advanced exploitation, Active Directory attacks, cloud & IoT security, digital forensics, mobile security, blockchain security, and AI in cyber security. Students gain hands-on experience with industry-standard tools like Kali Linux, Metasploit, Burp Suite, Ghidra, Wireshark, and Nmap, while building a professional portfolio through real-world labs, CTF challenges, and a final capstone project, preparing them for careers as Penetration Testers, Security Analysts, SOC Analysts, and Cyber Security Consultants.

Duration: 12 months
Mode: hybrid
Language: Hindi/English
View Curriculum

Curriculum

Module 1: Introduction to Cyber Security & Ethical Hacking

2 weeks

Topics Covered:

  • Evolution of Cyber Threats (RaaS & Nation-State APTs)
  • CIA Triad in the Cloud/IoT Era
  • Risk Management & Threat Modelling (STRIDE, DREAD, Attack Trees)
  • Legal & Ethical Considerations (GDPR, HIPAA, EU AI Act)
  • Penetration Testing Contracts & Rules of Engagement

Projects:

  • Threat Modelling Report for a FinTech Application

Module 2: Networking Fundamentals & Modern Architecture

3 weeks

Topics Covered:

  • Deep-Dive into OSI Model & TCP/IP Stack
  • IP Addressing, Subnetting, and CIDR for Cloud VPCs
  • Vulnerability Analysis: ARP Spoofing, DNS Poisoning, DHCP Attacks
  • Network Topologies & Micro-segmentation
  • Intrusion Detection and Prevention Systems (IDS/IPS): Signature vs. AI/ML-based

Projects:

  • Network Traffic Analysis & Intrusion Detection Lab

Module 3: Linux Fundamentals

4 weeks

Topics Covered:

  • Getting Started with Linux OS & Command Line Mastery
  • Managing Files, Creating/Viewing/Editing Text Files (Vim/Nano)
  • Managing Local Users, Groups & Permission Models (ACLs)
  • Controlling Access to Files (Linux Permissions)
  • Monitoring and Managing Linux Processes (Ps, Top, Kill, Nice)
  • Controlling Services and Daemons (Systemd)

Projects:

  • Linux System Audit & Hardening Script

Module 4: Linux Network Services & Server Security

4 weeks

Topics Covered:

  • Configuring and Hardening SSH (Key-Based Auth, Tunneling)
  • Server Configuration: NFS, Samba, FTP (Vsftpd)
  • Virtual Host Configuration (Apache2 & Nginx)
  • Dark Web Server Configuration (.onion Services)
  • Log Management & Archiving (Rsyslog, Logrotate, Tar, Rsync)
  • Firewall Configurations (Iptables, UFW, Nftables)
  • Managing Networking (Ip, Route, Netplan) & Installing Software Packages (APT, YUM)

Projects:

  • Secure Multi-Service Production Server Deployment

Module 5: Operating System Security

3 weeks

Topics Covered:

  • Operating System Concepts (Kernel vs. Userland)
  • Common OS Vulnerabilities (EternalBlue, DirtyPipe)
  • User Authentication Mechanisms (NTLM, Kerberos, PAM)
  • Securing Operating Systems: Windows (Defender, Bitlocker), Linux (AppArmor/SELinux), macOS (SIP), Android (Sandboxing)
  • Patch Management & System Hardening (CIS Benchmarks)

Projects:

  • Cross-OS Security Hardening Baseline Audit

Module 6: Web Application Security (Traditional & Modern)

4 weeks

Topics Covered:

  • Web Application Architecture (LAMP, MEAN, Serverless)
  • OWASP Top Ten Vulnerabilities (2026 Updated)
  • Secure Coding Practices & Frameworks (Input Validation, Output Encoding)
  • Web Application Firewalls (WAF) & Security Tools (ModSecurity, Cloudflare)

Projects:

  • Full OWASP Audit of a Serverless Web Application

Module 7: Ethical Hacking Methodology

3 weeks

Topics Covered:

  • Understanding Ethical Hacking & Rules of Engagement
  • Principles of Pentesting: Reconnaissance, Scanning, Exploitation, Post-Exploitation
  • Advanced Information Gathering & OSINT (Google Dorks, Shodan, Censys)
  • Scanning and Enumeration (Nmap, Masscan, Netcat)
  • Vulnerability Assessment, CVSS Scoring & Reporting

Projects:

  • External Footprinting & Reconnaissance Report

Module 8: Network Security (Perimeter & Internal)

3 weeks

Topics Covered:

  • Next-Gen Firewalls (NGFW) & VPNs (IPSec, OpenVPN, Wireguard)
  • Wireless Network Security (WEP, WPA, WPA2, WPA3) & Attacks (KRACK, PMKID)
  • Network Monitoring & Incident Response (SNMP, NetFlow, Zeek)
  • Network Architecture Design for Security (DMZs, Jump-boxes, Zero-Trust)

Projects:

  • Zero-Trust Network Architecture Design & Simulation

Module 9: Cryptography & Secure Communications

3 weeks

Topics Covered:

  • Cryptographic Algorithms & Protocols (AES, RSA, ECC, Hashing)
  • Public Key Infrastructure (PKI) & Digital Certificates (Managing X.509)
  • Secure Communication Channels (SSL/TLS, SSH Port Forwarding)
  • Post-Quantum Cryptography
  • Implementing Encryption (Disk, Database)

Projects:

  • Implementing a Mini-CA & Encrypted Chat Application

Module 10: Core Ethical Hacking & System Hacking

6 weeks

Topics Covered:

  • Password Cracking (John the Ripper, Hashcat - GPU Cracking)
  • Malware, Viruses, Worms, Trojans & Backdoors: Understanding C2 (Command & Control)
  • Sniffers & MITM (Ettercap, Bettercap)
  • Bots and Botnets (Understanding IoT Botnets like Mirai)
  • Social Engineering Techniques (Phishing, Vishing, Deepfake Awareness)
  • Denial of Service (DoS) & Distributed DoS (DDoS) Attacks
  • Hacking Web Servers / Server Rooting (Apache/Nginx Misconfigs)
  • Hacking Wireless Networks (Wi-Fi, Bluetooth, RF Signals)
  • Honeypots (Setting up & Evading)
  • Evading IDS, Firewall & Modern EDR (Endpoint Detection & Response)
  • Buffer Overflow (Stack-based, SEH) & Modern Mitigations (ASLR/DEP)
  • Computer and Mobile Hacking (Physical Access Attacks)

Projects:

  • Building & Detecting a Custom RAT (Remote Access Trojan)

Module 11: Advanced Web Application Security Exploitation

8 weeks

Topics Covered:

  • Understanding and Exploiting SQL Injection (SQLi) - Union, Blind, Boolean, Time-based
  • SQL Authentication Bypass
  • Cross-Site Scripting (XSS) - Reflected, Stored, DOM-based
  • Cross-Site Request Forgery (CSRF)
  • Remote Code Execution (RCE)
  • File Inclusion Vulnerabilities (LFI/RFI)
  • Server-Side Request Forgery (SSRF) - Cloud Metadata Attacks
  • XML External Entity (XXE) Attacks
  • Web Session Hijacking (Cookie Stealing, Fixation)
  • File Upload Vulnerability (Bypassing Filters, Getting Shells)
  • Security Misconfigurations (Default Creds, Directory Listing)
  • Insecure Deserialization (Java, .NET, PHP)
  • Broken Authentication (Brute-force, Credential Stuffing)
  • JWT Token Attack (Alg: None, Brute-force Secrets)
  • Insecure Direct Object References (IDOR)
  • Sensitive Data Exposure (API Keys, Source Code)
  • Multi Factor Authentication (MFA) Bypass (Fatigue, OTP Brute-force)
  • HTTP Request Smuggling (Desync Attacks)
  • Source Code Disclosure, Directory Path Traversal, HTML Injection
  • Host Header Injection (Virtual Host Bypass), Clickjacking, Open Redirects
  • Server-Side Template Injection (SSTI - Jinja2, Twig)
  • Flood Attack on Web (Layer 7 DDoS)
  • Application Security Assessments: SAST, DAST, Source Code Review
  • DevSecOps & CI/CD Pipeline Scanning
  • Vulnerability Assessment & Reporting (Writing CVEs)

Projects:

  • Comprehensive Black-Box Web Application Penetration Test

Module 12: Cloud and Virtualization Security

4 weeks

Topics Covered:

  • Cloud Computing Models (IaaS, PaaS, SaaS) & Shared Responsibility Model
  • AWS, Azure, GCP Security Features (Security Groups, IAM Policies)
  • Securing Virtual Environments & Containers (Docker, Kubernetes RBAC)
  • Identity and Access Management (IAM) in the Cloud (Federated Identity, OIDC)
  • Infrastructure as Code (IaC) Security (Scanning Terraform/CloudFormation)

Projects:

  • Cloud Security Posture Assessment & IAM Policy Audit

Module 13: Mobile and IoT Security Foundations

3 weeks

Topics Covered:

  • Mobile App Security Assessments (Static/Dynamic Analysis)
  • Securing Mobile Devices (MDM) and APIs
  • IoT Security Challenges: Insecure Firmware, Hardcoded Credentials
  • Security Implications of Wearable Technology and Smart Homes

Projects:

  • IoT Firmware Vulnerability Assessment & Smart Home Attack Surface Analysis

Module 14: Cyber Forensics (DFIR)

6 weeks

Topics Covered:

  • Key Terminology, Chain of Custody & Evidence Handling (Legal Admissibility)
  • Digital Evidence Fundamentals (Files, Logs, Metadata)
  • Evidence Collection Methods (Live vs. Dead Acquisition)
  • Tools for Imaging and Analysis (Autopsy, Guymager, FTK Imager, EnCase)
  • Understanding File Systems (NTFS, FAT32, ext4) & MFT Analysis
  • File Recovery Techniques (Carving) & Analysing Timestamps (MAC Times)
  • Introduction to Network Forensics & PCAP Analysis (Wireshark, Tshark)
  • Identifying and Tracking Network-Based Attacks
  • Malware Analysis: Types & Behaviour Analysis (Sandboxing)
  • Tools for Malware Analysis (GDB, Radare2, Ghidra, IDA Pro, x64dbg, AndroGuard)

Projects:

  • Full Forensic Investigation & Malware Reverse Engineering Report

Module 15: Advanced Penetration Testing

6 weeks

Topics Covered:

  • Bash Shell Scripting for Automation
  • Practical Tools (Nc, Socat, Chisel)
  • Using Public Exploits (Searchsploit, Exploit-DB Modification)
  • Antivirus Evasion Techniques (Obfuscation, Packers, Shellcode Encryption)
  • Windows Privilege Escalation (Potato Attacks, PrintNightmare, SeImpersonate)
  • Payload Deployments & File Transfers (Certutil, Bitsadmin, PowerShell)
  • Password Attacks (Pass-the-Hash, Pass-the-Ticket, Brute-force)
  • Linux Privilege Escalation (SUID Binaries, Kernel Exploits, Capabilities)
  • Active Directory Attacks (Kerberoasting, AS-REP Roasting, DCSync, Golden/Silver Tickets)
  • Port Redirection & Tunnelling (SSH Tunnels, Ngrok, Ligolo-ng)
  • Modern C2 Frameworks (PowerShell Empire / Covenant)
  • Lab Solving (HackTheBox, VulnHub, TryHackMe, PortSwigger, OWASP JuiceShop)

Projects:

  • Full Internal Network Compromise & Domain Dominance Simulation

Module 16: Network Penetration Testing (External & Internal)

4 weeks

Topics Covered:

  • In-depth Network Penetration Testing Methodologies (OSSTMM, PTES)
  • Advanced Reconnaissance and OSINT Techniques (TheHarvester, Recon-ng)
  • Exploiting Complex Network Vulnerabilities (Routing Protocols, SNMP)
  • Reporting and Communicating Findings (Executive Summaries)

Projects:

  • Professional External & Internal Penetration Test for a Simulated Client

Module 17: Advanced Exploitation Techniques

4 weeks

Topics Covered:

  • Kernel-Level Vulnerabilities & Exploitation (Privilege Escalation to SYSTEM/root)
  • Advanced Memory Corruption Attacks (Heap Spraying, Use-After-Free)
  • Writing Custom Exploits and Payloads (Python, C, ASM)
  • Mitigations & Defenses Against Advanced Attacks (Control Flow Guard, CET)

Projects:

  • Custom Shellcode & Exploit Development for a Known CVE

Module 18: Exploitation & Post-Exploitation Mastery

3 weeks

Topics Covered:

  • Exploiting Vulnerabilities: Metasploit Framework & Exploit-DB
  • Privilege Escalation & Maintaining Access: Persistence Mechanisms (Cron, Services, Registry)
  • Covering Tracks & Post-Exploitation Activities (Clearing Logs, Timestomping)
  • Legal and Ethical Aspects of Advanced Penetration Testing

Projects:

  • Simulated APT Attack Lifecycle & Cleanup Scenario

Module 19: Mobile Application Penetration Testing (Android/iOS)

4 weeks

Topics Covered:

  • Introduction to Mobile Penetration Testing & Lab Setup (Rooted/Emulated Devices)
  • Android Architecture & APK File Structure
  • Reversing Application with Apktool, JADX, and Bytecode Viewer
  • Static Analysis (Manifest Permissions, Hardcoded Secrets) using MobSF
  • Exploiting Insecure Data Storage (SQLite, SharedPrefs) & Communication (HTTP vs HTTPS)
  • Exploiting Insecure Authentication, Authorization & Insufficient Cryptography
  • Code Tampering (Repackaging APKs) & Reverse Engineering (Smali/Binary Patching)
  • SSL Pinning Bypass (Using Frida, Objection)
  • Intercepting Network Traffic (Setting up Proxy for Mobile Apps)

Projects:

  • Comprehensive Android/iOS Banking App Security Audit

Module 20: Internet of Things (IoT) Penetration Testing

4 weeks

Topics Covered:

  • Introduction to IoT Architecture & Sensor Networks
  • Wireless Protocol Analysis (ZigBee, Z-Wave, BLE, LoRa)
  • Review of Electronic Platforms (Raspberry Pi, Arduino, ESP8266)
  • Mobile App Platform and Middleware for IoT (MQTT, CoAP)
  • Machine Learning for Intelligent IoT (Anomaly Detection)
  • Analytic Engine for IoT (Using ELK Stack for IoT Logs)
  • Hardware Hacking: UART, JTAG, SPI Debugging and Firmware Extraction

Projects:

  • Hardware Tear-Down & Firmware Backdooring on an IoT Device

Module 21: Blockchain & Cryptocurrency Security

3 weeks

Topics Covered:

  • Understanding Blockchain Technology (Distributed Ledgers, Consensus)
  • Cryptocurrency Vulnerabilities (Wallet Hacks, Exchange Exploits, 51% Attacks)
  • Smart Contract Security and Auditing (Ethereum/Solidity, Rust)
  • DeFi (Decentralized Finance) Flash Loan Attacks

Projects:

  • Smart Contract Security Audit & Exploit Reproduction

Module 22: Programming Languages for Hackers

6 weeks

Topics Covered:

  • C/C++ Programming: Understanding Memory Management, Pointers & Writing Buffer Overflows
  • x86_64 Assembly Language Programming & Binaries Reversing/Debugging (GDB/Pwndbg)
  • PHP Programming for Vulnerable Web Apps Development (Building CTF Challenges)

Projects:

  • Develop a CTF Challenge from Scratch with Known Vulnerabilities

Module 23: Artificial Intelligence & Machine Learning in Cyber Security

4 weeks

Topics Covered:

  • Overview of AI and Machine Learning in Cyber Security
  • AI-Powered Threat Detection & Prediction Systems (UEBA)
  • Using AI for Malware Classification and Anomaly Detection (Supervised vs. Unsupervised)
  • Building Intelligent Intrusion Detection Systems (IDS) using ML Models (Random Forest, Neural Networks)
  • Deep Learning for Phishing and Spam Detection (NLP Models)
  • Automated Vulnerability Scanning and Exploitation with AI (Auto-GPT for Pentesting)
  • Using AI in Digital Forensics: Pattern Recognition and Timeline Correlation
  • ChatGPT, Claude, and Copilot for Cyber Operations: Automating Scripting, Log Analysis & Reporting
  • Ethical Considerations and Adversarial Machine Learning (Evading AI Models)
  • Introduction to Popular Tools and Frameworks (TensorFlow, Scikit-learn, OpenAI API, IBM Watson)

Projects:

  • Train an ML Model to Detect Phishing Emails & Evade an AI Detector

Learning Objectives

  • Master ethical hacking methodology from reconnaissance to post-exploitation
  • Exploit modern web vulnerabilities aligned with the latest OWASP Top 10
  • Perform advanced penetration testing on Windows and Linux environments
  • Conduct Active Directory attacks and defense strategies
  • Secure and exploit cloud, mobile, and IoT ecosystems
  • Apply digital forensics and incident response (DFIR) techniques to real-world breaches

Why Choose GCCSP at The Geek Institute of Cyber Security?

The Geek Certified Cyber Security Professional (GCCSP) program is a comprehensive, 12-month industry-oriented program that transforms tech enthusiasts into job-ready cyber security professionals. This course bridges the gap between basic IT knowledge and advanced offensive and defensive security proficiency across network security, web application exploitation, cloud security, digital forensics, and AI-driven threat detection.

  • Cutting-Edge Curriculum: 23 structured modules covering everything from foundational Linux to Advanced Active Directory Attacks, Modern EDR Evasion, and AI in Cyber Security.
  • 100% Practical & Hands-on Training: Over 500 hours of practical labs, real-world scenarios, and CTF challenges.
  • Full Portfolio Development: Build 23+ portfolio projects including full network compromises, forensic investigations, and custom exploit development.
  • Multiple Career Paths: Opens doors to roles such as Penetration Tester, SOC Analyst, Security Consultant, and Red Team Operator.
  • Expert Instructors: Learn from working cyber security professionals with industry certifications (OSCP, CEH) and real-world experience.
  • Placement Support: Resume building, mock interviews, and direct referrals to hiring partners.
  • Professional Certificate: Industry-recognized GCCSP certification enhancing your employability.

Who Should Enroll?

This program is perfect for:

  • Fresh Graduates looking to start a career in cyber security
  • IT Professionals wanting to transition into specialized security roles
  • Network Administrators seeking to specialize in advanced defense
  • Career Changers passionate about ethical hacking and forensics
  • Students (12th pass or above) interested in building a hacker portfolio
  • Business Owners wanting to understand security fundamentals

No prior cyber security experience required — just bring your curiosity, dedication, and willingness to learn!

What You'll Build

During this 12-month journey, you'll create a robust professional portfolio:

Core Security Projects

  • Threat Modelling Report for a FinTech Application
  • Network Traffic Analysis & Intrusion Detection Lab
  • Secure Multi-Service Production Server Deployment
  • Cross-OS Security Hardening Baseline Audit
  • Full OWASP Audit of a Serverless Web App
  • Comprehensive Black-Box Web App Penetration Test

Advanced Penetration Testing Projects

  • Full Internal Network Compromise & Domain Dominance Simulation
  • Custom Shellcode & Exploit Development for a Known CVE
  • Simulated APT Attack Lifecycle & Cleanup Scenario
  • Comprehensive Android/iOS Banking App Security Audit
  • Hardware Tear-Down & Firmware Backdooring (IoT)

Specialized Tracks

  • Forensics & Malware Analysis: Full Forensic Investigation & Reverse Engineering Report
  • Cloud Security: Cloud Security Posture Assessment & IAM Policy Audit
  • Blockchain: Smart Contract Security Audit & Exploit Reproduction
  • AI in Security: Train an ML Model to Detect Phishing Emails
  • Secure Coding: Develop a CTF Challenge from Scratch

Career Opportunities

GCCSP qualifies you for high-demand cyber security roles:

Entry-Level Positions (₹4-6 LPA)

  • Security Analyst
  • Junior Penetration Tester
  • SOC Analyst
  • Vulnerability Management Analyst

Mid-Level Positions (₹6-10 LPA)

  • Penetration Tester
  • Cyber Security Consultant
  • Security Engineer
  • Incident Response Analyst

Advanced Roles (₹10-15+ LPA)

  • Senior Security Analyst
  • Red Team Operator
  • Security Architect
  • Bug Bounty Hunter (Freelance)

Top Hiring Companies

  • TCS, Wipro, Infosys (Security Divisions)
  • Deloitte, EY, KPMG (Security Consulting)
  • Paytm, Razorpay, PhonePe (FinTech Security)
  • Amazon, Microsoft, Google (Security Teams)
  • Government Agencies & Defense Sector

Learning Experience

Learning Format

  • Duration: 12 months
  • Mode: Hybrid (Online/Offline)
  • Structured Learning: 23 progressive modules from basic principles to advanced AI-driven attacks.
  • Total Hours: 500+ hours of training

Learning Methodology

  • 30% Theory & Concepts
  • 70% Hands-on Practice, Labs & Projects
  • Weekly assessments and CTF challenges
  • Practical lab access 24/7
  • Final Capstone Project with industry mentor evaluation

Course Includes

  • Course Material: Complete notes, command cheatsheets, and lab guides.
  • Software Access: Kali Linux, Metasploit, Burp Suite Pro, Ghidra, and Cloud Sandboxes.
  • Lab Practice: 24/7 access to private lab environment and VPN connectivity.
  • Assessments: Module-wise practical exams and CTF scoreboards.
  • Certification: Industry-recognized GCCSP certificate.
  • Job Support: Portfolio review, LinkedIn optimization, and interview preparation.
  • Alumni Access: Lifetime access to the student community and updated materials.

Fee Structure

Course Fee: ₹52,000 (12 months)

Payment Options:

  1. One-time Payment: ₹46,000 (₹6,000 discount)
  2. Half-yearly: ₹23,000 × 2 installments
  3. Quarterly: ₹11,500 × 4 installments
  4. Monthly: ₹3,834 × 12 installments

Frequently Asked Questions

Do I need prior programming or hacking experience?

No prior experience is needed. The course starts from fundamentals and teaches Python, Bash, and C programming from scratch.

Is the GCCSP certification recognized in the industry?

Yes, it's a skill-validated certification aligned with practical requirements for roles like Penetration Tester and SOC Analyst. It focuses on what you can do, not just what you know.

Will you help me get a job after the program?

Yes, we provide dedicated placement assistance including mock interviews, resume building, and direct referrals to our 50+ hiring partners.

What if I miss a live session?

All sessions are recorded and available for lifetime access via our LMS.

Can I pay the fees in installments?

Yes, flexible EMI and installment options are available.

Tags

Ethical HackingPenetration TestingNetwork SecurityWeb Application SecurityCloud SecurityDigital ForensicsPython for SecurityLinux Administration