NCO logo
NCO (National Cyber Organization)
SYS_STATUS: ONLINE
/curriculum

Full syllabus. Basics → Elite.

Ten integrated modules covering foundational networking, Linux, and Python — through offensive tradecraft and enterprise-grade SOC operations.

01
CORE · FOUNDATION

Networking

The bedrock. Networks, protocols, devices, and the security controls that live on them.

▸ View Syllabus (12 topics)
  • Introduction to Networking
  • Networking Models and Types
  • OSI and TCP/IP Model
  • IP Addressing and Subnetting
  • Packet Structure and Protocols (IP, TCP, UDP, ICMP)
  • Network Devices: Routers, Switches, Firewalls
  • Network Topologies and Architecture
  • NAT, DNS, and DHCP Fundamentals
  • Port Forwarding and IP Routing
  • Network Security Fundamentals (Firewalls, IDS/IPS, Proxies, VPNs)
  • NAT and Security Implications
  • Simulation through CISCO Packet Tracer
Enroll →
02
CORE · FOUNDATION

Kali Linux

Fluent Linux, from CLI navigation to bash automation and security tooling.

▸ View Syllabus (14 topics)
  • Introduction to Kali Linux & Lab Setup (VirtualBox, VMware, ISO)
  • Shell, CLI vs GUI, Distributions
  • Basic Linux Commands (pwd, cd, ls, cp, mv, rm)
  • Files & Directory Management (mkdir, touch, nano, cat, less)
  • User and Group Management (adduser, usermod, groups)
  • File Permissions & Ownership (chmod, chown, umask)
  • Linux File System Hierarchy & Navigation
  • Process Management (ps, top, kill, nice, jobs)
  • Package Management (apt, yum, dpkg, snap)
  • Networking commands (ping, netstat, traceroute, ss, ifconfig/ip)
  • Essential Security Tools (nmap, netcat, tcpdump, whois)
  • Bash Scripting Fundamentals (Variables, Loops, Conditions)
  • Automation with Bash (Practical Scripts & Crontab)
  • System Logs & Monitoring (journalctl, syslog, logrotate)
Enroll →
03
CORE · FOUNDATION

Python Programming

The offensive/defensive scripting language. From syntax to hacking libraries.

▸ View Syllabus (19 topics)
  • Introduction to code and platforms
  • Python Variables & Data Types
  • Operators
  • Numbers and Strings
  • Lists and Tuples
  • Dictionaries and Type Casting
  • Arrays and NumPy
  • Conditional Statements
  • Loops — concepts & practice
  • Control Statements
  • Functions
  • OOP Concepts
  • Multithreading and Image Processing
  • File Handling
  • Mail Sending Program & Use Cases
  • Database Connection (MySQL)
  • Sockets: Building & Working
  • Web Scraping: a trick for Bug Bounty
  • Libraries: Hacks for Tools to Hack
Enroll →
04
RED TEAM · INTERMEDIATE

Ethical Hacking

The complete offensive playbook. Recon → exploitation → post-exploitation across every attack surface.

▸ View Syllabus (20 topics)
  • Introduction to Ethical Hacking
  • Information Gathering
  • Scanning
  • Enumeration
  • Vulnerability Analysis (VA)
  • System Hacking
  • Malware, Worms, Trojans
  • Sniffing
  • Social Engineering Techniques
  • DOS / DDOS Attacks
  • Session Hijacking
  • Honeypots, Firewalls, IDS
  • Hacking Web Servers
  • Web Application Hacking
  • SQL Injection & Types
  • WiFi Hacking
  • Exploit Mobile Platform
  • IoT & OT Exploit
  • Cloud
  • Cryptography
Enroll →
05
RED TEAM · INTERMEDIATE

Network Penetration Testing

Break networks the right way. Kali, footprinting, scanning, CTFs, and full privilege escalation.

▸ View Syllabus (26 topics)
  • Introduction to Kali Linux
  • Command Line Fun
  • Bash Scripting
  • Passive Footprinting
  • Active Footprinting
  • Advanced Scanning
  • Initial Access CTFs
  • Privilege Escalation (Windows Based)
  • Introduction to Windows Privilege Escalation
  • Gaining Foothold
  • Initial Enumeration
  • Exploring Automated Tools
  • Kernel Exploits
  • Password & Port Forwarding
  • Windows Subsystem for Linux
  • Impersonation and Potato Attacks
  • GetSystem, RunAs, Registry, Executables
  • Startup Applications, DLL Hijacking
  • Service Permissions (paths)
  • CVE-2019-1388 Challenge
  • Linux Privilege Escalation
  • Root Access CTFs
  • Buffer Overflow Overview
  • Antivirus Evasion
  • Active Directory Overview
  • Report Generation
Enroll →
06
RED TEAM · INTERMEDIATE

Web Application Penetration Testing

OWASP Top 10 hands-on. Burp Suite, injection, auth flaws, and a full case-study pentest.

▸ View Syllabus (19 topics)
  • Introduction to HTTP/HTTPS (Request Methods)
  • Web Application Attack Surface
  • OWASP Top 10 Vulnerabilities
  • Installing & Configuring Burp Suite
  • Burp Suite Basics (Proxy, Repeater)
  • Cross-Site Scripting (XSS) — exploit & prevent
  • Cross-Site Request Forgery (CSRF)
  • Input Validation Vulnerabilities
  • SQL Injection — Manual Exploitation
  • SQL Injection — Automated (SQLmap)
  • SQLi Prevention (Prepared Statements, ORM)
  • File Upload Vulnerabilities & Prevention
  • Directory Traversal & Mitigation
  • Session Hijacking & Fixation
  • Authentication & Authorization Flaws
  • Broken Access Control
  • Insecure Direct Object References (IDOR)
  • Burp Suite for Automated Scanning
  • Final Case Study: Full Web App Pentest
Enroll →
07
RED TEAM · INTERMEDIATE

API Hacking

REST, JSON, JWT, OAuth. Enumerate, exploit, harden — end with a complete API pentest lab.

▸ View Syllabus (12 topics)
  • REST APIs & JSON Structure
  • API Endpoints and Methods
  • Enumerating Endpoints & Parameters
  • Broken Object Level Authorization (BOLA)
  • Common API Vulnerabilities
  • Injection in APIs (SQLi, Command Injection, XXE)
  • API Testing with Postman
  • API Analysis using Burp Suite
  • API Authentication Flaws
  • API Security Best Practices (OAuth 2.0, JWT)
  • API Hardening & Mitigation
  • Final Lab: Complete API Penetration Test
Enroll →
08
RED TEAM · ADVANCED

Mobile Penetration Testing

Android & iOS attack surfaces. APK reversing, ADB, obfuscation, and OWASP Mobile Top 10.

▸ View Syllabus (20 topics)
  • Android Application Security Introduction
  • Setting up Android App Security
  • Android Pentesting Methodologies
  • Lab Setup & Design
  • Traditional Android Pentesting — Test Cases
  • Approach and Guidelines
  • Client Side Vulnerabilities
  • Server Side Vulnerabilities
  • Logical Security Threats
  • OWASP Mobile Top 10
  • Android Debug Bridge (ADB)
  • Vulnerable Android App — Source Code Review
  • APK Structure
  • Reversing with dex2jar
  • Reversing with apktool
  • Signing Applications Manually
  • Code Obfuscation & Protection
  • Adding Malicious Code to Apps
  • Debugging / Root / VM Detection
  • iOS Application Basics & Standards
Enroll →
09
BLUE TEAM · ADVANCED

SOC Specialist · SIEM + EDR (Splunk)

The full Blue Team stack: risk, SIEM with Splunk, EDR telemetry, threat hunting, and IR.

▸ View Syllabus (26 topics)
  • Risk Management and Security
  • Cyber Threats and Attack Patterns
  • Incidents, Events and Logging
  • Security Incidents & Recovery with SIEM
  • Advanced Threat Detection & Analysis
  • Security Event Response & Resolution
  • Introduction to Splunk
  • Installing & Configuring Splunk
  • Searching and Reporting in Splunk
  • Indexing and Data
  • Splunk Search Language (SPL)
  • Dashboards and Visualization
  • Alerts and Notification
  • Splunk Administration & Security
  • Splunk App Development
  • Splunk Enterprise Security
  • Endpoint Monitoring / Data Collection
  • Detection Engine
  • Alerting & Incident Management
  • Investigation / Threat Hunting
  • Response & Remediation
  • Multi-Tenant & API Layer
  • Sensor & Data Collection Layer
  • Forensic & Hunting Module
  • Identity & Lateral Movement Tracking
  • Reporting & Dashboard
Enroll →
10
BLUE TEAM · GOVERNANCE

ISO 27001 Lead Auditor

Certification-track program for auditors. ISMS, controls, and the ISO/IEC 27000 family.

▸ View Syllabus (7 topics)
  • Fundamental concepts of Information Security
  • ISO/IEC 27001 Certification Process
  • Information Security Management System (ISMS)
  • The ISO/IEC 27000 Family of Standards
  • Advantages of ISO/IEC 27001
  • Fundamentals of Information and Assets
  • Principles: Confidentiality, Integrity, Availability
Enroll →