Community curriculum · Community 01
Cybersecurity
Build India's next generation of security professionals through hands-on attack and defense practice — not textbook theory. Every session ends with a student having done something real: solved a flag, exploited a vulnerability, or secured a system.
This is the planned activity framework for a full academic year. It describes what each chapter is set up to run, not a record of events already delivered.
- activities / year
- 12
- major events
- 4
- skill levels
- 3
- cadence
- Monthly
The year, quarter by quarter
12 planned entries across the academic year.
Jan — Mar
Community kickoff
Onboarding
Linux & networking
Workshop
Beginner CTF
Competition
Apr — Jun
OWASP Top 10 series
Workshop series
Bug bounty intro
Session
Inter-college CTF
Open competition
Jul — Sep
Red vs. blue team lab
Simulation
CEH bootcamp
Certification prep
Campus security drive
Outreach
Oct — Dec
Advanced CTF
All-level competition
Annual security summit
Flagship event
Certificates & showcase
Year-end
Flagship event
Flagship — quarterly
Capture The Flag (CTF) Competition
Timed team challenge where students exploit intentionally vulnerable systems to capture hidden flags. Three parallel tracks — Beginner, Intermediate, Advanced — so no one is excluded. Winner gets certificates, sponsor prizes, and a recommendation letter.
- Web exploitation
- Reverse engineering
- Cryptography
- Forensics
- OSINT
- Binary exploitation
- Steganography
Activities
Monthly workshops
Ethical hacking workshop series
Monthly3-hour sessions on one specific attack vector per month. Students open a terminal and exploit alongside the instructor using HackTheBox or TryHackMe. No slides-only sessions — ever.
- Network scanning
- SQL injection
- XSS
- Privilege escalation
Industry leader guest sessions
Monthly45-min talk + 15-min Q&A from a working security professional. Topics: real incident postmortems, career paths, current threat landscape. Recorded for members who miss it.
- CISO talks
- Incident stories
- Career paths
- Bug bounty journeys
Quarterly intensives
Threat simulation lab
QuarterlyRed team vs. blue team in a sandboxed college network. One group attacks, the other defends. Teaches both mindsets. Run using free tools — no special hardware needed.
- Red team
- Blue team
- Incident response
- Log analysis
Certification prep bootcamp
Twice/yearIntensive 2-day prep camps for CEH, CompTIA Security+, and eJPT.
- CEH
- CompTIA Security+
- eJPT
- Study groups
Bug bounty introduction program
Twice/yearWalk through HackerOne and Bugcrowd platforms, hall-of-fame programs, and responsible disclosure. Invite a student who has earned a real bounty to share their story.
- HackerOne
- Bugcrowd
- Responsible disclosure
Security awareness campus drive
Twice/yearCommunity members run a campus-wide campaign — phishing simulations, password hygiene, social engineering demos. Builds leadership skills and positions ISDC as campus guardians.
- Phishing demo
- Password hygiene
- Social engineering
Skill progression
Level 01
Foundation
Months 1 – 3
- Linux command line basics
- Networking fundamentals
- Intro to Kali Linux
- First TryHackMe room
Level 02
Intermediate
Months 4 – 8
- OWASP Top 10 in practice
- Burp Suite proficiency
- Nmap and recon tools
- HackTheBox easy machines
Level 03
Advanced
Months 9 – 12
- Active Directory attacks
- Malware analysis basics
- Bug bounty hunting
- CTF leadership & design
Tools used
- TryHackMe
- HackTheBox
- PicoCTF
- Kali Linux
- Burp Suite
- Wireshark
- Nmap
- Metasploit
- OWASP WebGoat
- VulnHub
Target outcomes
At least 1 certification
Every active member targets eJPT or CompTIA Security+ before the academic year ends
Public CTF ranking
A verified HackTheBox or TryHackMe profile showing real, measurable progress
Interview-ready portfolio
GitHub with 2+ security writeups, vulnerability research, or lab documentation
