Bristleback Cybersecurity Professional complete cybersecurity environment

BRISTLEBACK CYBERSECURITY PROFESSIONAL BBCP · PROFESSIONAL PROGRAM

Understand the attack.
Detect the threat. Respond with confidence.

A comprehensive hands-on cybersecurity program covering security foundations, ethical hacking, SOC operations, threat detection, digital forensics, incident response, risk, governance and security compliance.

27Modules
7Levels
LabsPractical work
End-to-endCyber operations

02 · COMPLETE CYBERSECURITY

Learn how the pieces connect.

BBCP combines the most useful offensive, defensive, investigative and governance skills into one structured cybersecurity journey.

01
◎

What you'll learn

Security foundations, reconnaissance, vulnerability assessment, web and network attacks, SOC operations, SIEM, threat hunting, DFIR, incident response, GRC and professional reporting.

02
◌

Who is this for?

Beginners entering cybersecurity, IT and networking professionals moving into security, aspiring SOC analysts, junior security analysts and administrators transitioning to cybersecurity.

03
⌁

Prerequisites

Basic computer and networking knowledge is recommended. The programme is designed to build the cybersecurity foundation before moving into specialised hands-on work.

See the learning path →

03 · THE BBCP PATH

From cybersecurity foundations to full operations.

A seven-level progression connecting attacker techniques, security monitoring, investigation, response, governance and professional cybersecurity reporting.

LEVEL 1

Cybersecurity Foundations

01Cybersecurity Fundamentals15 topics+
  • CIA triad
  • Assets
  • Threats
  • Vulnerabilities
  • Risks
  • Security controls
  • Attack surface
  • Defense in depth
  • Authentication
  • Authorization
  • Accounting
  • Common attack types
  • Cyber Kill Chain
  • MITRE ATT&CK
  • Security architecture
02Networking for Cybersecurity13 topics+
  • OSI/TCP-IP
  • IP addressing
  • TCP/UDP
  • DNS
  • DHCP
  • HTTP/HTTPS
  • SMTP
  • SSH
  • SMB
  • LDAP
  • Kerberos
  • Network attacks
  • Network security concepts
03Windows & Linux Security Fundamentals12 topics+
  • Windows architecture
  • Linux architecture
  • Users and groups
  • Permissions
  • Processes
  • Services
  • Authentication
  • Windows Event Logs
  • Linux logs
  • PowerShell
  • Bash
  • Security configuration
LEVEL 2

Offensive Security Fundamentals

04Reconnaissance & Information Gathering14 topics+
  • Passive reconnaissance
  • Active reconnaissance
  • OSINT
  • DNS enumeration
  • Domain discovery
  • Network discovery
  • Service enumeration
  • Technology identification
  • Attack surface mapping
  • Nmap
  • Amass
  • theHarvester
  • WHOIS
  • DNS tools
05Vulnerability Assessment13 topics+
  • Vulnerability vs exploit
  • CVE
  • CVSS
  • Vulnerability scanning
  • Service enumeration
  • Misconfiguration
  • Web vulnerabilities
  • Network vulnerabilities
  • Prioritizing vulnerabilities
  • Nmap
  • Nessus Essentials
  • OpenVAS/Greenbone
  • Nikto
06Web & Network Attack Fundamentals17 topics+
  • Authentication attacks
  • Brute force
  • Password attacks
  • Web attacks
  • SQL injection concepts
  • XSS
  • Command injection
  • File inclusion
  • Directory traversal
  • Exploitation concepts
  • Reverse shells
  • Basic privilege escalation
  • Burp Suite Community
  • Metasploit
  • Hydra
  • Netcat
  • OWASP Juice Shop
07Attack Simulation & MITRE ATT&CK13 topics+
  • Initial access
  • Execution
  • Persistence
  • Privilege escalation
  • Defense evasion
  • Credential access
  • Discovery
  • Lateral movement
  • Collection
  • Command & control
  • Exfiltration
  • Impact
  • Attacker-to-SOC evidence mapping
LEVEL 3

SOC & Security Monitoring

08SOC Fundamentals13 topics+
  • What is a SOC?
  • SOC architecture
  • SOC roles
  • L1/L2/L3 analysts
  • SOC workflow
  • Alert
  • Event
  • Incident
  • Case
  • Escalation
  • Incident severity
  • SOC metrics
  • Analyst responsibilities
09Log Management & Analysis10 topics+
  • Windows Event Logs
  • Sysmon
  • Linux logs
  • Authentication logs
  • Firewall logs
  • DNS logs
  • Web logs
  • Log collection
  • Log normalization
  • Timeline analysis
10SIEM11 topics+
  • SIEM architecture
  • Log ingestion
  • Searching
  • Correlation
  • Dashboards
  • Alerts
  • Detection rules
  • Investigation
  • Wazuh
  • Splunk
  • Underlying SIEM concepts
11Network Security Monitoring13 topics+
  • Packet capture
  • Packet analysis
  • Network flows
  • DNS investigation
  • HTTP investigation
  • Suspicious traffic
  • C2 traffic
  • Port scanning detection
  • Brute-force detection
  • Wireshark
  • tcpdump
  • Zeek
  • Suricata
12Endpoint Security Monitoring12 topics+
  • Endpoint telemetry
  • Windows processes
  • Services
  • PowerShell
  • WMI
  • Scheduled tasks
  • Persistence
  • Linux processes
  • SSH
  • Cron
  • Authentication
  • Sysmon telemetry
LEVEL 4

Threat Detection & Investigation

13Threat Intelligence11 topics+
  • Threat intelligence
  • IOC
  • IOA
  • TTP
  • Threat actors
  • Malware indicators
  • IOC enrichment
  • Threat intelligence lifecycle
  • MITRE ATT&CK
  • Threat intelligence feeds
  • Indicator validation
14Phishing & Email Investigation12 topics+
  • Email architecture
  • SMTP
  • Email headers
  • SPF
  • DKIM
  • DMARC
  • Malicious URLs
  • Malicious attachments
  • Sender analysis
  • Domain analysis
  • IOC extraction
  • Phishing investigation
15Threat Hunting9 topics+
  • Threat hunting concepts
  • Hunting methodology
  • Hypothesis-driven hunting
  • IOC hunting
  • TTP hunting
  • MITRE ATT&CK hunting
  • SIEM hunting
  • Network hunting
  • Endpoint hunting
16Detection Engineering11 topics+
  • Detection logic
  • Indicators vs behaviours
  • Detection rules
  • Correlation
  • False positives
  • Alert tuning
  • Detection coverage
  • MITRE ATT&CK mapping
  • Sigma
  • YARA
  • Actual detection-rule creation
LEVEL 5

Digital Forensics & Incident Response

17Digital Forensics Fundamentals13 topics+
  • Digital evidence
  • Evidence handling
  • Chain of custody
  • Forensic imaging
  • Hashing
  • File systems
  • Windows artifacts
  • Registry
  • Browser artifacts
  • Event logs
  • Timeline analysis
  • Autopsy
  • FTK Imager
18Memory & Endpoint Forensics9 topics+
  • Memory acquisition concepts
  • Memory analysis
  • Processes
  • Network connections
  • DLLs
  • Handles
  • Malware indicators
  • Persistence
  • Volatility
19Malware Investigation Fundamentals12 topics+
  • Malware types
  • Malware lifecycle
  • Static analysis
  • Dynamic analysis
  • Hashes
  • Strings
  • PE basics
  • Behaviour analysis
  • Network behaviour
  • Sandbox concepts
  • IOC extraction
  • YARA
20Incident Response12 topics+
  • Incident response lifecycle
  • Preparation
  • Identification
  • Triage
  • Containment
  • Eradication
  • Recovery
  • Lessons learned
  • Evidence preservation
  • Root-cause analysis
  • Incident prioritization
  • Incident documentation
LEVEL 6

Security Governance, Risk & Compliance

21Security Governance & Risk12 topics+
  • Governance
  • Security policies
  • Roles and responsibilities
  • Risk
  • Threat
  • Vulnerability
  • Risk assessment
  • Risk treatment
  • Risk acceptance
  • Risk register
  • Risk appetite
  • Security controls
22Security Standards & Compliance11 topics+
  • ISO/IEC 27001
  • ISO 27002
  • NIST CSF
  • CIS Controls
  • SOC 2
  • PCI DSS
  • GDPR
  • ITGC
  • Compliance requirements
  • Evidence
  • Audit findings
23Security Policies & Controls9 topics+
  • Information Security Policy
  • Access Control Policy
  • Password Policy
  • Incident Response Policy
  • Asset Management
  • Acceptable Use
  • Backup
  • Business Continuity
  • Vendor Security
24Security Risk & Audit9 topics+
  • Control objectives
  • Control testing
  • Evidence collection
  • Compliance assessment
  • Security gaps
  • Findings
  • Corrective actions
  • Risk reporting
  • Management reporting
LEVEL 7

Full Cybersecurity Operations

25Attack-to-Detection Lifecycle11 topics+
  • Reconnaissance
  • Exploitation
  • Persistence
  • Privilege Escalation
  • Lateral Movement
  • Command & Control
  • Detection
  • Investigation
  • Containment
  • Recovery
  • Detection Improvement
26Security Operations Case Management11 topics+
  • Alert triage
  • Case creation
  • Evidence collection
  • Investigation notes
  • IOC documentation
  • Timeline
  • Escalation
  • Incident classification
  • Root cause
  • Remediation
  • Case closure
27Cybersecurity Reporting7 topics+
  • SOC investigation report
  • Incident report
  • Executive summary
  • IOC report
  • Vulnerability report
  • Risk report
  • Remediation plan

04 · PRACTICAL CYBERSECURITY

Don't just learn tools. Learn to connect evidence to action.

BBCP is designed around the complete security workflow: understand the attack, identify the evidence, investigate what happened, respond appropriately and improve the defence.

01

Offensive Security

Reconnaissance, vulnerability assessment, web and network attack fundamentals and controlled attack simulation.

02

SOC & SIEM

Work with logs, alerts, correlation, Wazuh, Splunk and the reasoning behind security operations.

03

Network & Endpoint

Investigate packets, DNS, HTTP, Windows telemetry, PowerShell, Linux activity and endpoint behaviour.

04

Threat Hunting

Use hypotheses, IOC/TTP searches, MITRE ATT&CK and detection logic to look beyond existing alerts.

05

DFIR & Response

Preserve evidence, investigate hosts and memory, classify incidents, contain threats and document recovery.

06

Governance & Reporting

Understand security risk, controls, compliance evidence and produce professional security reports.

05 · SIGNATURE BBCP LAB

Follow one attack from start to finish.

The signature learning experience connects offensive activity to the evidence a defender sees and the actions taken afterwards.

01 · ATTACK

Reconnaissance

Map the attack surface and identify the path an attacker could take.

02 · ATTACK

Exploitation

Perform a controlled attack and identify the resulting technical evidence.

03 · DETECT

Security Monitoring

Trace logs, network activity and endpoint telemetry to identify the attack.

04 · RESPOND

Investigation

Build a timeline, preserve evidence, contain the incident and document findings.

05 · IMPROVE

Detection Improvement

Create better detections, controls and remediation recommendations.

05 · PRICING

BBCP course fee.

The standard BBCP course fee is ₹30,000. Learning-mode offers are calculated automatically from the standard fee. The course fee is collected in two equal instalments.

FULL COURSE FEE

₹30,000

Standard fee for the complete BBCP programme.

Full price
ONLINE · 40% OFF

₹18,000

Save ₹12,000 · 2 equal instalments of ₹9,000

Online offer
OFFLINE · 10% OFF

₹27,000

Save ₹3,000 · 2 equal instalments of ₹13,500

Offline offer
Two equal instalments.Coming Soon · Batch allocation is confirmed before payment and course commencement.₹30,000 standard

07 · REFUND & CANCELLATION

Four Learning Satisfaction Checkpoints. You stay in control.

The BBCP fee for the selected learning mode is collected in two equal instalments. At the 25%, 50%, 75% and 100% syllabus checkpoints, you can assess whether the learning delivered so far is satisfactory. If you are not satisfied, the applicable refund is calculated against the relevant remaining portion of the instalment for that checkpoint. No certificate is issued for an unfinished exit.

25% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 100% of first instalment

Exit the programme. The applicable first-instalment amount is refundable.

50% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 50% of first instalment

Exit the programme. If satisfied, continue and pay the second equal instalment.

75% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 100% of second instalment

Exit the programme. The applicable second-instalment amount is refundable.

100% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 50% of second instalment

Exit the programme. No certificate is issued.

IF SATISFIED

Continue → complete BBCP

On successful completion of the programme and final checkpoint, the BBCP Certificate of Completion is issued.

PAYMENT STRUCTURE

Two equal instalments

The standard and published offer payment plans use two equal instalments. Custom payment arrangements, if enabled, are handled separately.

08 · LEARNING MODE

Online or in the classroom.

Choose the learning mode that works best for you. Offline delivery is offered only when a suitable Puducherry batch is opened.

Teaching languages: English and Tamil.

01

Online

Live instructor-led sessions with practical lab work and guided investigation.

02

Offline · Puducherry

Classroom-based learning when a minimum batch size is reached.

03

Practical-first

Hands-on work is integrated throughout the programme rather than kept as an optional add-on.

09 · AVAILABLE BATCH SLOTS

Find your learning slot.

Batch slots are allocated according to programme demand. Current BBCP slots will be announced when a batch is formed.

SLOT 01Awaiting allocationNo batch assigned yet
SLOT 02Awaiting allocationNo batch assigned yet
SLOT 03Awaiting allocationNo batch assigned yet
SLOT 04Awaiting allocationNo batch assigned yet

11 · CERTIFICATION & REGISTRATION

Ready to build complete cybersecurity capability?

Register your interest, choose your preferred learning mode and schedule, and we'll consider you for the next suitable BBCP batch.

BBCP Certificate of Completion

Complete the programme requirements and practical learning journey to receive the Bristleback Cybersecurity Professional Certificate of Completion.

Coming Soon