CHFI, Computer Forensics
Offensive practitioners who also understand forensics are markedly more valuable on incident work.
View courseCPENT is where ethical hacking stops being a syllabus and starts being a job. This 80-hour penetration testing course in Bangalore assumes you already understand attacker methodology and pushes you into the harder problem: operating against defended, segmented environments where the easy paths are closed.
The programme is heavily weighted toward lab time. You will pivot between network segments, attack systems that are not directly reachable, chain weaknesses that are individually low severity, and write the whole thing up to a standard a client would pay for.
CPENT-level practitioners work as Penetration Testers, Red Team Operators, Senior VAPT Analysts and Offensive Security Consultants.
Every module pairs instruction with lab work. You practise the technique in the same session you learn it.
| 01. Penetration testing methodology and scoping Structuring an engagement, defining scope, and the contractual basis of legal testing. |
| 02. Advanced reconnaissance and OSINT Building a target picture from sources the defender forgot they exposed. |
| 03. Network exploitation and privilege escalation Gaining and expanding access across Windows and Linux estates. |
| 04. Pivoting and lateral movement Reaching segmented targets that are not directly routable from your foothold. |
| 05. Web application penetration testing Deep testing beyond automated scanning, including logic and authorisation flaws. |
| 06. Active Directory attack paths The domain-level attack chains that dominate real enterprise compromises. |
| 07. Binary and application-layer weaknesses Understanding exploitation beneath the web tier. |
| 08. Evasion and defended environments Operating where EDR, segmentation and monitoring are present and functioning. |
| 09. Professional reporting and client communication Turning technical findings into prioritised, business-legible remediation advice. |
Batch dates vary; the sequence does not. Weekday, weekend and evening formats cover the same blocks.
| Block | Hours | Focus |
|---|---|---|
| Block 1 | 16 hrs | Methodology, scoping and advanced reconnaissance Structuring a full-scope engagement, the contractual basis of legal testing, and building a target picture from exposed sources. |
| Block 2 | 16 hrs | Network exploitation and privilege escalation Gaining and expanding access across Windows and Linux estates where the straightforward paths are already closed. |
| Block 3 | 16 hrs | Pivoting, lateral movement and segmentation bypass Reaching targets that are not routable from your foothold, the skill that separates CPENT from CEH. |
| Block 4 | 16 hrs | Web application and Active Directory attack paths Deep web testing beyond automated scanning, and the domain-level chains that dominate real enterprise compromise. |
| Block 5 | 16 hrs | Evasion, defended environments and reporting Operating where EDR, segmentation and monitoring are present and working, then producing a client-grade report. |
| Tool | Used for |
|---|---|
| Full offensive toolkit | Nmap, Metasploit, Burp Suite and supporting tooling at depth |
| Active Directory attack tooling | Domain enumeration, relay and privilege path analysis |
| Pivoting and tunnelling tooling | Reaching segmented and non-routable targets |
| Credential and hash tooling | Extraction, reuse and offline analysis |
| Web and API testing tooling | Manual testing beyond scanner coverage |
| Reporting frameworks | Structuring findings for client delivery |
| Format | Fully hands-on, remote-proctored, open book, on a live enterprise range |
| Duration | One 24-hour sitting, or two 12-hour sessions |
| Passing score | Form-specific cut score, commonly 60-85% |
| LPT (Master) | Score 90% or above and you also earn LPT (Master) |
| Report requirement | A professional penetration test report must be submitted after the exam |
| Prerequisites | No mandatory prerequisite, but treat it as a capstone |
Offensive practitioners who also understand forensics are markedly more valuable on incident work.
View courseUnderstanding what defenders see when you operate makes you a substantially better tester.
View courseFormally, CEH is not mandatory, but the course assumes CEH-level knowledge. If you cannot currently run a structured engagement from reconnaissance through exploitation without guidance, do CEH first, starting CPENT underprepared wastes the lab time you are paying for.
CEH teaches methodology across a broad surface. CPENT tests whether you can apply it against environments that fight back, segmented networks, hardened hosts, monitored estates. It is substantially more demanding and considerably more lab-heavy at 80 hours.
Yes, though the entry bar is higher than for defensive roles. Bangalore has a strong consulting and product security market that hires penetration testers, but most practitioners arrive via a SOC, VAPT or development background rather than directly from training.
80 hours, delivered at our Marathahalli centre and online, with weekend options. Given the lab intensity, we recommend allowing additional self-directed practice time between sessions.
Core cyber security fundamentals spanning endpoints, networks, web security, IAM, SOC and governance.
View courseBeginner-to-job-ready programme with live labs, SOC operations, ethical hacking and compliance coverage.
View courseEthical hacking fundamentals covering reconnaissance, exploitation, reporting, tooling and attacker methodology.
View courseSOC-focused training on SIEM fundamentals, alert triage, incident workflows and security operations.
View courseDigital forensics covering evidence handling, DFIR workflows, incident investigation and compliance reporting.
View courseSpeak to a counsellor about batch dates, fees and whether this course fits your current background. No obligation, no sales pressure.