Design the network, virtualize the environment, deploy Active Directory and security controls.
Build it.Operate it.Defend it.
A hands-on cybersecurity engineering pathway where every layer you build becomes the environment you later learn to defend.
Three stages. One continuous environment.
No disconnected modules. No reset between courses. You keep adding operational depth to the same enterprise system.
Run services, databases, endpoints, identity and the day-to-day systems that keep an enterprise alive.
Analyse malware, hunt threats, detect attacks and respond inside the environment you already understand.
The enterprise starts here.
Eight weeks. Twelve hands-on labs. You finish with a working enterprise you built yourself and a management-grade vulnerability assessment report you can explain to an employer.
Understanding Technology
OSI model and the core security technologies around modern infrastructure.
Networking
Design and build a network intended to support 500 hosts.
Virtualization
Stand up the compute environment the enterprise will run on.
Enterprise Network & AD
Active Directory, Group Policy, PowerShell and identity at enterprise scale.
Malware Analysis
Foundational static triage with MITRE ATT&CK context.
Vulnerability Management
Discover, assess, prioritize and report vulnerabilities to standard.
Make the enterprise run.
ECEH-100 gives you the environment. ECEH-200 teaches you to operate it: enterprise software, databases, web services, endpoint management, remote access, and solving real customer use-cases.
Managing an Enterprise Network
Network administration, enterprise software implementation and support, enterprise assets and resources, and remote access management.
Managing Cybersecurity Solutions
Translate customer use-cases into fit-for-purpose security solutions, then implement and support them in the environment.
Wazuh is introduced here as a working SIEM and becomes the detection backbone for the blue-team stage.
Microsoft SQL Server, instances, authentication and enterprise users.
IIS, self-signed and domain certificates, A-records and CNAMEs.
Kaspersky Security Center, agent deployment, reports and health checks.
Nexpose deployment, Windows agents through GPO, scanning and reporting.
Remote Desktop Services and HTTPS application publishing.
Ingest telemetry, build simple dashboards and generate reports.
ECEH-300.
Blue Team Operations.
You take the enterprise you built and learn to defend it: analyse malware, attack the domain, create visibility, hunt the intrusion and respond with the discipline of a real security operations team.
Proof of work, not just attendance.
Infrastructure you can walk through, troubleshoot, operate and defend.
Databases, web services, endpoint protection, remote access and SIEM foundations running in your lab.
Evidence that you can translate technical findings into business-relevant reporting.
Malware triage and incident-response artifacts that show how you investigate, explain and respond.
Fifteen seats.Founding rate.
Small class. Direct instructor access. The first version of the experience.