Skip to content

Community curriculum · Community 01

Cybersecurity

Build India's next generation of security professionals through hands-on attack and defense practice — not textbook theory. Every session ends with a student having done something real: solved a flag, exploited a vulnerability, or secured a system.

This is the planned activity framework for a full academic year. It describes what each chapter is set up to run, not a record of events already delivered.

All four domains and the annual calendar

activities / year
12
major events
4
skill levels
3
cadence
Monthly

The year, quarter by quarter

12 planned entries across the academic year.

  1. Jan — Mar

    1. Community kickoff

      Onboarding

    2. Linux & networking

      Workshop

    3. Beginner CTF

      Competition

  2. Apr — Jun

    1. OWASP Top 10 series

      Workshop series

    2. Bug bounty intro

      Session

    3. Inter-college CTF

      Open competition

  3. Jul — Sep

    1. Red vs. blue team lab

      Simulation

    2. CEH bootcamp

      Certification prep

    3. Campus security drive

      Outreach

  4. Oct — Dec

    1. Advanced CTF

      All-level competition

    2. Annual security summit

      Flagship event

    3. Certificates & showcase

      Year-end

Flagship event

Flagship — quarterly

Capture The Flag (CTF) Competition

Timed team challenge where students exploit intentionally vulnerable systems to capture hidden flags. Three parallel tracks — Beginner, Intermediate, Advanced — so no one is excluded. Winner gets certificates, sponsor prizes, and a recommendation letter.

  • Web exploitation
  • Reverse engineering
  • Cryptography
  • Forensics
  • OSINT
  • Binary exploitation
  • Steganography

Activities

Monthly workshops

  • Ethical hacking workshop series

    Monthly

    3-hour sessions on one specific attack vector per month. Students open a terminal and exploit alongside the instructor using HackTheBox or TryHackMe. No slides-only sessions — ever.

    • Network scanning
    • SQL injection
    • XSS
    • Privilege escalation
  • Industry leader guest sessions

    Monthly

    45-min talk + 15-min Q&A from a working security professional. Topics: real incident postmortems, career paths, current threat landscape. Recorded for members who miss it.

    • CISO talks
    • Incident stories
    • Career paths
    • Bug bounty journeys

Quarterly intensives

  • Threat simulation lab

    Quarterly

    Red team vs. blue team in a sandboxed college network. One group attacks, the other defends. Teaches both mindsets. Run using free tools — no special hardware needed.

    • Red team
    • Blue team
    • Incident response
    • Log analysis
  • Certification prep bootcamp

    Twice/year

    Intensive 2-day prep camps for CEH, CompTIA Security+, and eJPT.

    • CEH
    • CompTIA Security+
    • eJPT
    • Study groups
  • Bug bounty introduction program

    Twice/year

    Walk through HackerOne and Bugcrowd platforms, hall-of-fame programs, and responsible disclosure. Invite a student who has earned a real bounty to share their story.

    • HackerOne
    • Bugcrowd
    • Responsible disclosure
  • Security awareness campus drive

    Twice/year

    Community members run a campus-wide campaign — phishing simulations, password hygiene, social engineering demos. Builds leadership skills and positions ISDC as campus guardians.

    • Phishing demo
    • Password hygiene
    • Social engineering

Skill progression

  1. Level 01

    Foundation

    Months 1 – 3

    • Linux command line basics
    • Networking fundamentals
    • Intro to Kali Linux
    • First TryHackMe room
  2. Level 02

    Intermediate

    Months 4 – 8

    • OWASP Top 10 in practice
    • Burp Suite proficiency
    • Nmap and recon tools
    • HackTheBox easy machines
  3. Level 03

    Advanced

    Months 9 – 12

    • Active Directory attacks
    • Malware analysis basics
    • Bug bounty hunting
    • CTF leadership & design

Tools used

Target outcomes