Basics of Security Hardening of Networking Devices
Cyber Range Courses
ID: CADMUS-CR-01 Owner: AU
Available for training June 2026
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Basic
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer
ECSF Skills View Skills ▾
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Apply auditing tools and techniques
  • Assess and enhance an organisation’s cybersecurity posture
  • Audit with integrity, being impartial and independent
  • Coordinate the integration of security solutions
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Identify and solve cybersecurity-related issues
  • Implement cybersecurity recommendations and best practices
  • Manage and analyse log files
  • Work on operating systems, servers, clouds and relevant infrastructures
Description View Description ▾
This Bootcamp course introduces the fundamental concepts of network switching, routing, and security at Layers 2 and 3. Participants will learn how switching operates within network infrastructure and explore its security implications. Through hands-on practice, they will configure VLANs, trunk links, and inter-switch connections, apply port security, and implement Spanning Tree Protocol to maintain network stability. The course also covers essential hardening techniques, such as securing management interfaces, isolating unused ports and VLANs, and enabling SSH for secure remote access with password encryption. On the routing side, learners will configure static and dynamic routing protocols and apply standard and extended Access Control Lists (ACLs) to control traffic and enhance security.
Advanced Layer 2 Switching and Security Strategies
Cyber Range Courses
ID: CADMUS-CR-02 Owner: AU
Available for training September 2026
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Basic–Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer Penetration Tester Cyber Incident Responder Cybersecurity Auditor Cybersecurity Architect
ECSF Skills View Skills ▾
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Assess the security and performance of solutions
  • Configure solutions according to the organisation’s security policy
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Identify and exploit vulnerabilities
  • Identify, analyse and correlate cybersecurity events
  • Implement cybersecurity recommendations and best practices
  • Integrate cybersecurity solutions to the organisation’s infrastructure
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Work on operating systems, servers, clouds and relevant infrastructures
Description View Description ▾
This Cyber Range course provides an introduction to secure network switching through guided, hands-on configuration of Cisco IOS-based switches. Participants learn to design, implement, and secure Layer 2 environments following CIS and DISA STIG recommendations. The exercises combine networking fundamentals with applied cybersecurity controls to ensure network resilience. Learners simulate common network attacks (e.g., rogue DHCP, MAC spoofing) and deploy corresponding countermeasures.
Advanced Layer 3 Security Hardening and Traffic Control
Cyber Range Courses
ID: CADMUS-CR-03 Owner: AU
Available for training March 2027
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Basic–Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer
ECSF Skills View Skills ▾
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Assess the security and performance of solutions
  • Configure solutions according to the organisation’s security policy
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Identify and exploit vulnerabilities
  • Identify, analyse and correlate cybersecurity events
  • Implement cybersecurity recommendations and best practices
  • Integrate cybersecurity solutions to the organisation’s infrastructure
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Work on operating systems, servers, clouds and relevant infrastructures
Description View Description ▾
This Cyber Range course provides practical training in secure routing and network segmentation based on the CIS Cisco ACI Router STIG Benchmark v1.0.0. Participants will learn to harden router configurations, secure control planes, implement routing protocol authentication, and design segmented networks using VRFs and ACLs. The session combines theoretical grounding with hands-on exercises in a simulated enterprise environment, replicating best practices for BGP, OSPF, and inter-domain routing security.
Firewall Configuration and Security Management
Cyber Range Courses
ID: CADMUS-CR-04 Owner: AU
Available for training March 2027
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Basic–Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer Cybersecurity Auditor Cyber Incident Responder Cybersecurity Architect Cybersecurity Researcher
ECSF Skills View Skills ▾
  • Configure solutions according to the organisation’s security policy
  • Implement cybersecurity recommendations and best practices
  • Select appropriate specifications, procedures and controls
  • Manage and analyse log files
  • Integrate cybersecurity solutions to the organisation’s infrastructure
  • Decompose and analyse systems to develop security and privacy requirements and identify effective solutions
  • Identify and solve cybersecurity‑related issues
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
Description View Description ▾
This Cyber Range course provides hands-on training in configuring and securing firewalls following the CIS pfSense Firewall Benchmark v1.1.0 (2023). Participants will harden firewall configurations, implement traffic control policies, and enforce security mechanisms such as VPN encryption, logging, and intrusion mitigation. Through realistic network scenarios, trainees will create, test, and verify firewall policies that ensure confidentiality, integrity, and availability in both enterprise and small-office networks.
Linux OS Security Hardening and Compliance Validation
Cyber Range Courses
ID: CADMUS-CR-05 Owner: AU
Available for training September 2026
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Basic–Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer Cybersecurity Architect Cybersecurity Auditor
ECSF Skills View Skills ▾
  • Implement cybersecurity recommendations and best practices
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Assess and enhance an organisation’s cybersecurity posture
  • Manage and analyse log files
  • Work on operating systems, servers, clouds and relevant infrastructures
  • Identify and solve cybersecurity-related issues
  • Decompose and analyse systems to develop security and privacy requirements and identify effective solutions
  • Apply auditing tools and techniques
  • Configure solutions according to the organisation’s security policy
Description View Description ▾
This Cyber Range exercise provides a hands-on environment for implementing security controls and hardening Linux systems according to CIS and STIG guidelines. Participants perform configuration and validation tasks on Ubuntu 24.04 and Red Hat Enterprise Linux 9 virtual machines. They will execute hardening procedures covering authentication, privilege management, logging, auditing, and network protection. The exercise concludes with a compliance verification phase using CIS-CAT or audit scripts, ensuring participants can evaluate and report on the security posture of Linux systems.
Windows OS Security Hardening and Active Directory Defense
Cyber Range Courses
ID: CADMUS-CR-06 Owner: AU
Available for training September 2026
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Basic–Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer Cybersecurity Architect Cybersecurity Auditor
ECSF Skills View Skills ▾
  • Implement cybersecurity recommendations and best practices
  • Configure solutions according to the organisation’s security policy
  • Work on operating systems, servers, clouds and relevant infrastructures
  • Manage and analyse log files
  • Decompose and analyse systems to identify weaknesses and ineffective controls
Description View Description ▾
This Cyber Range exercise provides hands-on experience in securing Windows 11 workstations and Windows Server 2025 environments, focusing on Active Directory, authentication mechanisms, and OS-level hardening. Participants perform security configuration tasks following CIS Benchmarks and best practices. The exercise includes identifying deviations, applying remediations through Group Policy Objects, PowerShell scripts, and security templates, and verifying compliance using built-in and third-party auditing tools.
Android Device Security and Hardening
Cyber Range Courses
ID: CADMUS-CR-07 Owner: AU
Available for training March 2027
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Basic–Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer Cyber Incident Responder Cybersecurity Architect
ECSF Skills View Skills ▾
  • Configure solutions according to the organisation’s security policy
  • Implement cybersecurity recommendations and best practices
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Assess the security and performance of solutions
  • Manage and analyse log files
  • Identify, analyse and correlate cybersecurity events
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Work on operating systems, servers, clouds and relevant infrastructures
Description View Description ▾
This Cyber Range exercise introduces participants to securing Android mobile devices based on CIS Benchmark. Through guided hands-on tasks, trainees configure, audit, and harden Android environments, focusing on authentication, application control, network access, and privacy. Participants will simulate both user-level and administrator-level activities, including detecting policy deviations, adjusting configurations, and validating compliance with organizational security policies. The exercise concludes with compliance validation and policy reporting using device analysis tools and MDM frameworks.
Business Continuity Planning and Resilience Simulation
Cyber Range Courses
ID: CADMUS-CR-08 Owner: AU
Available for training September 2026
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Risk Manager Cybersecurity Architect Cybersecurity Implementer
ECSF Skills View Skills ▾
  • Analyse business processes, assess and review software or hardware security, as well as technical and organisational controls
  • Build resilience against points of failure aCyber Rangeoss the architecture
  • Analyse and consolidate organisation’s quality and risk management practices
  • Assess the security and performance of solutions
  • Communicate, coordinate and cooperate with internal and external stakeholders
  • Identify non-cyber events with implications on cyber-related activities
  • Work on operating systems, servers, clouds and relevant infrastructures
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Enable business assets owners, executives and other stakeholders to make risk-informed decisions to manage and mitigate risks
Description View Description ▾
This course provides a comprehensive overview of business continuity and disaster recovery (BCDR) principles, integrating theory with hands-on cyber-range exercises. It equips participants with the skills to identify risks, conduct impact analyses, design continuity strategies, and execute disaster recovery plans under pressure.
Disaster Recovery Operations and Technical Restoration
Cyber Range Courses
ID: CADMUS-CR-09 Owner: AU
Available for training September 2026
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cyber Incident Responder Cybersecurity Risk Manager Chief Information Security Officer (CISO)
ECSF Skills View Skills ▾
  • Build resilience against points of failure aCyber Rangeoss the architecture
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Analyse business processes, assess and review software or hardware security, as well as technical and organisational controls
  • Assess the security and performance of solutions
  • Collect information while preserving its integrity
  • Work on operating systems, servers, clouds and relevant infrastructures
  • Identify and solve cybersecurity-related issues
  • Communicate, present and report to relevant stakeholders
  • Understand, practice and adhere to ethical requirements and standards
Description View Description ▾
This Cyber Range module provides hands-on experience in disaster recovery operations using a fully virtualized environment. Participants practice backup configuration, VM snapshotting, replication, restoration, and failover orchestration. A simulated outage scenario requires execution of full DR activation procedures, including service restoration, data verification, and failback to the production environment. The workflow integrates real procedures aligned with ISO 22301, NIST SP 800-34, and industry DR best practices.
CISO Governance, Compliance and Security Oversight
Cyber Range Courses
ID: CADMUS-CR-10 Owner: AU
Available for training June 2026
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Chief Information Security Officer (CISO) Cybersecurity Risk Manager Cybersecurity Auditor Cyber Legal, Policy & Compliance Officer
ECSF Skills View Skills ▾
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Analyse and consolidate organisation’s quality and risk management practices
  • Assess and enhance an organisation’s cybersecurity posture
  • Define and apply maturity models for cybersecurity management
  • Communicate, present and report to relevant stakeholders
  • Collect, evaluate, maintain and protect auditing information
Description View Description ▾
This Cyber Range module enables participants to take on the role of a CISO overseeing a simulated organisation. Using the open-source CISO Assistant platform, trainees configure governance frameworks, assess compliance maturity, manage evidence, and prepare audit-ready documentation. The combined LMS and Cyber Range exercises replicate real-world CISO workflows, including reporting, gap analysis, risk scoring, and executive communication.
Incident Response
Cyber Range Courses
ID: CADMUS-CR-11 Owner: AU+EUC
Available for training September 2026
Duration 12 hours
Platform Category Cyber Range LMS
Proficiency Level Intermediate-Advanced
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cyber Incident Responder Digital Forensics Investigator Cyber Threat Intelligence Specialist
ECSF Skills View Skills ▾
  • Collect information while preserving its integrity
  • Conduct technical analysis and reporting
  • Identify threat actors TTPs and campaigns
  • Identify, analyse and correlate cybersecurity events
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
Description View Description ▾
This Cyber Range module places participants in the role of technical incident responders. Using a fully simulated enterprise environment, participants investigate and contain a multi-stage security incident involving malware, lateral movement, privilege escalation and command-and-control communications. Learners perform real technical tasks including triage, log analysis, forensics collection, network traffic inspection, containment and eradication.
Secure Coding C/C++
Cyber Range Courses
ID: CADMUS-CR-12 Owner: AU
Available for training September 2026
Duration 12 hours
Platform Category LMS Cyber Range
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer Secure Coder / Secure Software Developer (proposed addition to ECSF framework)
ECSF Skills View Skills ▾
  • Review codes assess their security
  • Develop code, sCyber Rangeipts and programmes
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Assess the security and performance of solutions
  • Identify and solve cybersecurity-related issues
  • Apply auditing tools and techniques
  • Design systems and architectures based on security and privacy by design and by defaults cybersecurity principles
  • Manage and analyse log files
  • Decompose and analyse systems to develop security and privacy requirements and identify effective solutions
  • Implement cybersecurity recommendations and best practices
Description View Description ▾
This course teaches participants how to design and write secure code, prevent vulnerabilities, and integrate security into the software development lifecycle. Combining LMS modules with practical labs, the training emphasizes secure programming techniques, vulnerability identification, and remediation.
Secure Coding .Net/C#
Cyber Range Courses
ID: CADMUS-CR-13 Owner: AU
Available for training September 2026
Duration 12 hours
Platform Category LMS Cyber Range
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer Secure Coder / Secure Software Developer (proposed addition to ECSF framework)
ECSF Skills View Skills ▾
  • Review codes assess their security
  • Develop code, sCyber Rangeipts and programmes
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Assess the security and performance of solutions
  • Identify and solve cybersecurity-related issues
  • Apply auditing tools and techniques
  • Design systems and architectures based on security and privacy by design and by defaults cybersecurity principles
  • Manage and analyse log files
  • Decompose and analyse systems to develop security and privacy requirements and identify effective solutions
  • Implement cybersecurity recommendations and best practices
Description View Description ▾
This course introduces participants to the theory and practice of modern cryptography with a focus on post-quantum methods. It covers classical symmetric/asymmetric algorithms, quantum threats, and hands-on implementation of PQC algorithms. Practical labs emphasize integration of PQC into real systems, hybrid deployment, and migration strategies.
Secure Coding Java
Cyber Range Courses
ID: CADMUS-CR-14 Owner: AU
Available for training September 2026
Duration 12 hours
Platform Category LMS Cyber Range
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer Secure Coder / Secure Software Developer (proposed addition to ECSF framework)
ECSF Skills View Skills ▾
  • Review codes assess their security
  • Develop code, sCyber Rangeipts and programmes
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Assess the security and performance of solutions
  • Identify and solve cybersecurity-related issues
  • Apply auditing tools and techniques
  • Design systems and architectures based on security and privacy by design and by defaults cybersecurity principles
  • Manage and analyse log files
  • Decompose and analyse systems to develop security and privacy requirements and identify effective solutions
  • Implement cybersecurity recommendations and best practices
Description View Description ▾
This intensive two-day program equips senior executives with the strategic insights and leadership tools needed to govern enterprise-wide cybersecurity. Through expert-led sessions, case studies, and interactive workshops, participants will learn how to oversee risk management, shape effective policies, and lead organizational culture toward resilience. Designed for board members, C-suite leaders, and top-level decision-makers, the course empowers executives to navigate complex cyber threats, make informed strategic decisions, and safeguard organizational trust in an increasingly digital world.
Secure Coding Python
Cyber Range Courses
ID: CADMUS-CR-15 Owner: AU
Available for training September 2026
Duration 12 hours
Platform Category LMS Cyber Range
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer Secure Coder / Secure Software Developer (proposed addition to ECSF framework)
ECSF Skills View Skills ▾
  • Review codes assess their security
  • Develop code, sCyber Rangeipts and programmes
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Assess the security and performance of solutions
  • Identify and solve cybersecurity-related issues
  • Apply auditing tools and techniques
  • Design systems and architectures based on security and privacy by design and by defaults cybersecurity principles
  • Manage and analyse log files
  • Decompose and analyse systems to develop security and privacy requirements and identify effective solutions
  • Implement cybersecurity recommendations and best practices
Description View Description ▾
This course covers methods and tools for gathering, analyzing and applying cyber threat intelligence (CTI). Students will learn the roles of tactical, operational and strategic intelligence. The class emphasizes using CTI platforms (e.g. MISP) and OSINT tools to collect data on threat actors and campaigns. Participants will practice analysing threat actor behaviors and TTPs, and learn to produce intelligence reports that inform defenders. Through labs, they will integrate threat feeds into a SIEM and demonstrate how intelligence can improve early detection and response. Threat intelligence provides details on threats- including actors, tactics, techniques, and procedures- enabling organizations to anticipate and mitigate attacks.
Secure Coding Mobile
Cyber Range Courses
ID: CADMUS-CR-16 Owner: AU
Available for training September 2026
Duration 12 hours
Platform Category LMS Cyber Range
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self‑paced
ECSF Roles View Roles ▾
Cybersecurity Implementer Secure Coder / Secure Software Developer (proposed addition to ECSF framework)
ECSF Skills View Skills ▾
  • Review codes assess their security
  • Develop code, sCyber Rangeipts and programmes
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Assess the security and performance of solutions
  • Identify and solve cybersecurity-related issues
  • Apply auditing tools and techniques
  • Design systems and architectures based on security and privacy by design and by defaults cybersecurity principles
  • Manage and analyse log files
  • Decompose and analyse systems to develop security and privacy requirements and identify effective solutions
  • Implement cybersecurity recommendations and best practices
Description View Description ▾
This course uses interactive games and scenario-based exercises to train participants in cybersecurity incident response. A tabletop exercise (TTX) is a role-playing activity where participants respond to a presented scenario in their real or fictional roles. The goal is not perfect performance but working as a team and identifying weaknesses in peacetime. Game-based learning (e.g. capture-the-flag challenges, cyber war-games) creates immersive, problem-solving environments that boost engagement and knowledge retention. Participants will engage in TTX scenarios (e.g. ransomware attack on a company) and serious games to practice decision-making, communication, and coordination. Debrief sessions solidify lessons and suggest policy improvements.
Post-Quantum Cryptography
Cyber Range Courses
ID: CADMUS-CR-17 Owner: AU, CTI
Available for training January 2027
Duration 40 hours
Platform Category LMS Labs BTCMP
Proficiency Level Advanced
Training Type Upskilling
Delivery Method Hybrid & Physical
ECSF Roles View Roles ▾
Cybersecurity Architect Cybersecurity Researcher Chief Information Security Officer (CISO) Cybersecurity Auditor Cybersecurity Implementer
ECSF Skills View Skills ▾
  • Anticipate cybersecurity threats, needs and upcoming challenges
  • Design systems and architectures based on security and privacy by design and by defaults cybersecurity principles
  • Decompose and analyse systems to develop security and privacy requirements and identify effective solutions
  • Develop code, sCyber Rangeipts and programmes
  • Review codes assess their security
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Assess the security and performance of solutions
  • Enable business assets owners, executives and other stakeholders to make risk-informed decisions to manage and mitigate risks
Description View Description ▾
This course teaches how to embed security throughout the software development lifecycle. Learners will study how to integrate security into requirements, design, implementation, and deployment. Topics include secure coding standards, threat modeling methods, and use of automated analysis tools. Students will practice static application security testing (SAST) on codebases, dynamic scanning of running apps, and dependency analysis. Emphasis is on “shifting left” security by adding checks early: for example, using CI/CD to run SonarQube or OWASP ZAP scans. The goal is to reduce software vulnerabilities and ensure robust development practices.
Network Penetration Testing
Cyber Range Courses
ID: CADMUS-CR-18 Owner: CTI
Available for training July 2026
Duration 20 hours
Platform Category Cyber Range
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self-paced (with hands-on labs)
ECSF Roles View Roles ▾
Penetration Tester Cybersecurity Implementer Cybersecurity Researcher
ECSF Skills View Skills ▾
  • Anticipate cybersecurity threats, needs and upcoming challenges
  • Assess and enhance an organisation’s cybersecurity posture
  • Conduct ethical hacking
  • Conduct technical analysis and reporting
  • Identify and exploit vulnerabilities
  • Identify, analyse and correlate cybersecurity events
  • Use penetration testing tools effectively
  • Work on operating systems, servers, clouds and relevant infrastructures
  • Assess the security and performance of solutions
  • Work ethically and independently; not influenced and biased by internal or external actors
  • Work under pressure
Description View Description ▾
This course provides a deep dive into Network Penetration Testing, focusing exclusively on the assessment and exploitation of network infrastructures. Trainees learn how attackers map, probe, and compromise networked systems by exploiting protocol weaknesses, insecure services, misconfigurations, and weak segmentation practices. The program covers scanning, enumeration, service exploitation, password attacks, lateral movement, and network-level post-exploitation techniques. Participants practice intensively within a realistic cyber range, where they will attack multi-segmented networks, bypass defenses, exploit vulnerable services, capture credentials, and escalate access across the environment. Emphasis is placed on understanding real-world attacker techniques (MITM, spoofing, pivoting), while building the ability to produce professional reporting and remediation guidance for securing enterprise networks.
Network Penetration Testing
Cyber Range Courses

This course provides a deep dive into Network Penetration Testing, focusing exclusively on the assessment and exploitation of network infrastructures. Trainees learn how attackers map, probe, and compromise networked systems by exploiting protocol weaknesses, insecure services, misconfigurations, and weak segmentation practices.

Web Application Penetration Testing
Cyber Range Courses

This course provides a comprehensive, hands-on exploration of Web Application Penetration Testing, focusing on real-world techniques, exploitation workflows, and attacker methodologies. Through a combination of theory, guided demonstrations, and intensive cyber range labs, participants learn how to deconstruct and assess modern web applications across all layers-client-side, server-side, authentication flows, and backend architectures.

The training is fully aligned with OWASP Testing Guide (WSTG), OWASP Top 10, CWE, ASVS, and industry standards for offensive security operations. Learners engage with practical scenarios including session hijacking, API exploitation, business logic attacks, misconfiguration discovery, injection exploitation, and chained attack escalation.

By the end of the course, participants will have the skills required to conduct full-scope web penetration tests, produce actionable findings, and support secure development and risk mitigation across organizations.

WEB Application Penetration Testing
Cyber Range Courses
ID: CADMUS-CR-19 Owner: CTI
Available for training December 2026
Duration 20 hours
Platform Category Cyber Range
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Hybrid & Physical (Online instructor-led, hands-on cyber range labs)
ECSF Roles View Roles ▾
Penetration Tester Cybersecurity Implementer Cybersecurity Architect Cyber Incident Responder Cybersecurity Auditor Digital Forensics Investigator Cyber Threat Intelligence Specialist
ECSF Skills View Skills ▾
  • Conduct ethical hacking
  • Identify and exploit vulnerabilities
  • Use penetration testing tools effectively
  • Identify, analyse and correlate cybersecurity events
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Conduct technical analysis and reporting
  • Model threats, actors and TTPs
  • Work on operating systems, servers, clouds and relevant infrastructures
  • Think Cyber Rangeeatively and outside the box
  • Communicate, present and report to relevant stakeholders
  • Work ethically and independently; not influenced and biased by internal or external actors
Description View Description ▾
This course focuses on penetration testing techniques targeting operating systems, including Windows and Linux environments. Learners study how OS-level vulnerabilities, misconfigurations, privilege escalation paths, and insecure services can be discovered and exploited. The curriculum covers enumeration, local and remote exploitation, post-exploitation techniques, credential dumping, persistence mechanisms, and lateral movement. Participants practice hands-on in a cyber range, attacking intentionally vulnerable OS images and applying real exploitation workflows. The course prepares learners to understand and evaluate the security posture of system-level components and to propose effective remediation strategies.
Denial of Service (DoS)
Cyber Range Courses
ID: CADMUS-CR-20 Owner: CTI
Available for training July 2026
Duration 6x4 hours
Platform Category Cyber Range
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self-paced (with hands-on labs)
ECSF Roles View Roles ▾
Cyber Incident Responder Digital Forensics Investigator Cyber Threat Intelligence Specialist Penetration Tester Chief Information Security Officer (CISO) Cyber Threat Intelligence Specialist Cybersecurity Architect
ECSF Skills View Skills ▾
  • Anticipate cybersecurity threats, needs and upcoming challenges
  • Build resilience against points of failure aCyber Rangeoss the architecture
  • Conduct technical analysis and reporting
  • Identify, analyse and correlate cybersecurity events
  • Implement cybersecurity recommendations and best practices
  • Manage and analyse log files
  • Model threats, actors and TTPs
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
Description View Description ▾
This course provides a comprehensive, hands-on exploration of Web Application Penetration Testing, focusing on real-world techniques, exploitation workflows, and attacker methodologies. Through a combination of theory, guided demonstrations, and intensive cyber range labs, participants learn how to deconstruct and assess modern web applications across all layers—client-side, server-side, authentication flows, and backend architectures. The training is fully aligned with OWASP Testing Guide (WSTG), OWASP Top 10, CWE, ASVS, and industry standards for offensive security operations. Learners engage with practical scenarios including session hijacking, API exploitation, business logic attacks, misconfiguration discovery, injection exploitation, and chained attack escalation. By the end of the course, participants will have the skills required to conduct full-scope web penetration tests, produce actionable findings, and support secure development and risk mitigation across organizations.
Operating Systems Penetration Testing
Cyber Range Courses
ID: CADMUS-CR-21 Owner: CTI
Available for training December 2026
Duration 20 hours
Platform Category Cyber Range
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self-paced (with hands-on labs)
ECSF Roles View Roles ▾
Penetration Tester Cybersecurity Researcher Cybersecurity Implementer Cyber Incident Responder Cybersecurity Architect Digital Forensics Investigator Cyber Threat Intelligence Specialist
ECSF Skills View Skills ▾
  • Conduct ethical hacking
  • Identify, analyse and correlate cybersecurity events
  • Identify and exploit vulnerabilities
  • Use penetration testing tools effectively
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Work on operating systems, servers, clouds and relevant infrastructures
  • Conduct technical analysis and reporting
  • Communicate, present and report to relevant stakeholders
  • Work ethically and independently; not influenced and biased by internal or external actors
  • Work under pressure
  • Perform social engineering
Description View Description ▾
This advanced course introduces participants to the methodologies, tools and techniques used to assess the security of mobile applications and Operational Technology (OT) environments. Students learn how to analyze and exploit vulnerabilities in Android/iOS applications through static analysis, dynamic testing, reverse engineering, traffic interception, and exploitation of insecure mobile design patterns. For OT, participants explore industrial control system architectures, SCADA environments, PLC behavior, industrial network protocols, and critical vulnerabilities found in real-world OT infrastructures. Through a safe cyber range designed for industrial systems, learners practice reconnaissance, protocol testing, exploitation, segmentation bypass and post-exploitation methods adapted to safety-critical environments. The course blends mobile and OT domains to highlight how modern cyber-physical and mobile-controlled industrial systems can be compromised, and how to mitigate these threats effectively.
Mobile/OT Penetration Testing
Cyber Range Courses
ID: CADMUS-CR-22 Owner: CTI
Available for training July 2026
Duration 30 hours
Platform Category Cyber Range
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Hybrid & Physical (online theory, physical lab environment for OT components)
ECSF Roles View Roles ▾
Penetration Tester Penetration Tester Cybersecurity Implementer Cybersecurity Architect Cyber Incident Responder Cybersecurity Researcher Cyber Threat Intelligence Specialist
ECSF Skills View Skills ▾
  • Conduct ethical hacking
  • Identify and exploit vulnerabilities
  • Use penetration testing tools effectively
  • Conduct technical analysis and reporting
  • Identify, analyse and correlate cybersecurity events
  • Assess the security and performance of solutions
  • Implement cybersecurity recommendations and best practices
  • Select appropriate specifications, procedures and controls
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Analyse business processes, assess and review software or hardware security, as well as technical and organisational controls
  • Model threats, actors and TTPs
  • Identify threat actors TTPs and campaigns
  • Manage and analyse log files
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Develop and communicate, detailed and reasoned investigation reports
  • Communicate, present and report to relevant stakeholders
  • Review and enhance security documents, reports, SLAs and ensure the security objectives
  • Identify and solve cybersecurity-related issues
  • Draw cybersecurity architectural and functional specifications
  • Coordinate the integration of security solutions
  • Build resilience against points of failure aCyber Rangeoss the architecture
  • Think Cyber Rangeeatively and outside the box
  • Organise and work in a systematic and deterministic way based on evidence
  • Work ethically and independently; not influenced and biased by internal or external actors
Description View Description ▾
This course teaches participants how to design and write secure code, prevent vulnerabilities, and integrate security into the software development lifecycle. Combining LMS modules with practical labs, the training emphasizes secure programming techniques, vulnerability identification, and remediation.
TBA
Cyber Range Courses
ID: CADMUS-CR-23 Owner: NCSA
Available for training
Duration 1 week (≈10 total hours)
Platform Category Cyber Range Interactive Simulation
Proficiency Level Basic / Intermediate
Training Type Upskilling / Awareness
Delivery Method Online instructor-led (with interactive gaming elements)
ECSF Roles View Roles ▾
Chief Information Security Officer (CISO) Cyber Incident Responder Cybersecurity Risk Manager Cybersecurity Educator Cybersecurity Auditor
ECSF Skills View Skills ▾
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Communicate, coordinate and cooperate with internal and external stakeholders
  • Work under pressure
  • Collaborate with other team members and colleagues
  • Manage cybersecurity resources
  • Build a cybersecurity risk-aware environment
  • Identify, analyse and correlate cybersecurity events
  • Assess and enhance an organisation’s cybersecurity posture
  • Motivate and encourage people
Description View Description ▾
This course teaches participants how to design and write secure code, prevent vulnerabilities, and integrate security into the software development lifecycle. Combining LMS modules with practical labs, the training emphasizes secure programming techniques, vulnerability identification, and remediation.
Cyber Threat Intelligence
Cyber Range Courses
ID: CADMUS-CR-24 Owner: NCSA
Available for training
Duration 20 hours
Platform Category Cyber Range & Online Lab
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online self-paced (optional virtual instructor sessions)
ECSF Roles View Roles ▾
Penetration Tester Cyber Threat Intelligence Specialist Cybersecurity Researcher Digital Forensics Investigator
ECSF Skills View Skills ▾
  • Identify and exploit vulnerabilities
  • Use penetration testing tools effectively
  • Conduct ethical hacking
  • Perform social engineering
  • Conduct technical analysis and reporting
Description View Description ▾
This course teaches participants how to design and write secure code, prevent vulnerabilities, and integrate security into the software development lifecycle. Combining LMS modules with practical labs, the training emphasizes secure programming techniques, vulnerability identification, and remediation.
Advanced Digital Forensics and Incident
Cyber Range Courses
ID: CADMUS-CR-25 Owner: NCSA
Available for training March 2026
Duration 4 weeks
Platform Category Cyber Pange
Proficiency Level Advanced
Training Type Upskilling Cyber Range oss-skilling, advanced forensics domain.
Delivery Method Online Instructor-Led
ECSF Roles View Roles ▾
Digital Forensics Investigator Cyber Incident Responder Cyber Legal, Policy & Compliance Officer
ECSF Skills View Skills ▾
  • Explain and present digital evidence in a simple, straightforward and easy to understand way
  • Identify, analyse and correlate cybersecurity events
  • Work ethically and independently; not influenced and biased by internal or external actors
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
Description View Description ▾
This course teaches participants how to design and write secure code, prevent vulnerabilities, and integrate security into the software development lifecycle. Combining LMS modules with practical labs, the training emphasizes secure programming techniques, vulnerability identification, and remediation.