Ahmedabad · IN
000

Find yourside.

Security isn't one job. Members group into six teams by the field that pulls them in, and grow from Explorer to Mentor along the way.

§ 01Why teams

Attackers and defenders study the same systems from opposite ends.

Teams give every member a home base, and a reason to learn from the other side.

§ 02

Not sure where you fit?

Three quick questions. No wrong answers, and you can switch teams any time.

Question 1 / 3

A new system lands on your desk. Your first instinct?

offenseTeam 01

Red Team

Think like the attacker.

Fig. T1 — Red TeamOffense

Offensive security, done ethically and with permission. Red Team members learn how real intrusions unfold, from reconnaissance to privilege escalation, so weaknesses are found before someone else finds them.

You'll learn
  • →Reconnaissance & OSINT
  • →Network & service enumeration
  • →Exploitation fundamentals
  • →Privilege escalation
  • →Capture-the-flag practice
Where it leads
  • →Penetration tester
  • →Red team operator
  • →Security researcher

Tools you'll touch

  • Nmap
  • Metasploit
  • Burp Suite
  • Hashcat
  • Kali Linux
defenseTeam 02

Blue Team

Build it to hold.

Fig. T2 — Blue TeamDefense

Defensive operations: watching systems, spotting what doesn't belong and hardening everything else. Blue Team members learn how a security operations centre actually runs.

You'll learn
  • →Log analysis & monitoring
  • →SIEM fundamentals
  • →System & network hardening
  • →Firewalls and access control
  • →Alert triage
Where it leads
  • →SOC analyst
  • →Security engineer
  • →Detection engineer

Tools you'll touch

  • Wireshark
  • Splunk / ELK
  • Suricata
  • Sysmon
  • pfSense
offense × defenseTeam 03

Purple Team

Attack, then defend. Repeat.

Fig. T3 — Purple TeamOffense × Defense

Where offense and defense meet. Purple Team members emulate real adversary techniques and then build the detections that catch them, closing the loop between both sides.

You'll learn
  • →MITRE ATT&CK mapping
  • →Adversary emulation
  • →Detection engineering
  • →Writing detection rules
  • →Measuring coverage
Where it leads
  • →Purple team engineer
  • →Threat hunter
  • →Detection engineer

Tools you'll touch

  • MITRE ATT&CK
  • Atomic Red Team
  • Sigma
  • Caldera
  • Velociraptor
offenseTeam 04

AppSec & Web

Every input is a question.

Fig. T4 — AppSec & WebOffense

Application and web security. Members learn how web apps break, through injection, broken authentication and misconfiguration, and how to build them so they don't.

You'll learn
  • →OWASP Top 10
  • →Injection & XSS
  • →Authentication flaws
  • →Secure code review
  • →Responsible disclosure
Where it leads
  • →Application security engineer
  • →Bug bounty hunter
  • →Secure developer

Tools you'll touch

  • Burp Suite
  • OWASP ZAP
  • sqlmap
  • Semgrep
  • Postman
defenseTeam 05

Forensics & IR

Every incident leaves a trail.

Fig. T5 — Forensics & IRDefense

Digital forensics and incident response. When something goes wrong, members learn to reconstruct what happened, contain it and recover, one artefact at a time.

You'll learn
  • →Incident response process
  • →Disk & memory forensics
  • →Timeline reconstruction
  • →Malware triage
  • →Evidence handling
Where it leads
  • →Incident responder
  • →Forensic analyst
  • →Malware analyst

Tools you'll touch

  • Autopsy
  • Volatility
  • FTK Imager
  • YARA
  • KAPE
defenseTeam 06

GRC & Awareness

People are the first perimeter.

Fig. T6 — GRC & AwarenessDefense

Governance, risk, compliance and awareness. Members learn how organisations decide what to protect and how to teach people to spot a phish before they click.

You'll learn
  • →Risk assessment
  • →Security policy
  • →Privacy & data protection
  • →Awareness campaigns
  • →Phishing simulation
Where it leads
  • →GRC analyst
  • →Security awareness lead
  • →Privacy analyst

Tools you'll touch

  • NIST CSF
  • ISO 27001
  • Risk registers
  • GoPhish
  • Threat modelling
§ 04Two sides · drag to compare
Offense

Think like an attacker.

  • 01Reconnaissance
  • 02Capture-the-flag practice
  • 03Web & app testing
  • 04Thinking like an adversary
Defense

Build like a defender.

  • 01Monitoring & detection
  • 02Hardening systems
  • 03Incident response
  • 04Encryption & privacy
§ 05

Seven stages, two answers.

Attack · 01

Reconnaissance

Gather names, emails, subdomains and open ports.

Defend

Shrink your exposure and watch for scanning.

Attack · 02

Weaponisation

Pair an exploit with a payload built for the target.

Defend

Track threat intel on the tools in circulation.

Attack · 03

Delivery

Send it in by phishing email, malicious link or USB.

Defend

Filter mail, train people, lock down removable media.

Attack · 04

Exploitation

Trigger the vulnerability and run code.

Defend

Patch fast, harden configs, least privilege.

Attack · 05

Installation

Plant persistence so access survives a reboot.

Defend

Endpoint detection and application allow-listing.

Attack · 06

Command & control

Open a channel back to the attacker.

Defend

Egress filtering and DNS / network monitoring.

Attack · 07

Actions

Steal, encrypt or destroy what they came for.

Defend

Segment data, keep backups, rehearse response.

§ 06

Everyone starts as an Explorer.

Teams are about what you focus on. Levels are about how far along you are. Nobody stays in one place for long.

  1. Level 11

    Explorer

    Freshers and the curious

    You're here to learn the landscape. Come to events, ask questions, try your first labs and find the team that pulls you in.

  2. Level 22

    Operator

    Members who practise

    You've picked a direction. You work through labs and CTFs, join team sessions and start sharing what you figure out.

  3. Level 33

    Mentor

    Experts and faculty

    You help others move up: run sessions, review work, and connect members with the wider security world.