Internship · Practitioner-Led · Limited Seats

Network Security
Internship Program

8-Week Live Defensive Security Training

8 Weeks
2 Sessions / Week
24 Live Touchpoints
3 Practitioner Mentors
Hands-On · Defensive Focus

This is not passive learning. You'll analyse real traffic, write detection rules, design secure architectures, and present findings weekly — mentored directly by practitioners who do this work professionally. By week 8, you're ready to step into a SOC, NSOC, or blue team role.

Registration Closed
Meet the Mentors

No refunds after enrolment — check Refund Policy

2 Training Sessions

per week, live

1 Intern Presentation

per week, graded

24 Live Touchpoints

total

3 Practitioner Mentors

direct access

Performance Certificate

earned, not given

Your Mentors

Not instructors who read slides. Practitioners who have done the work — and are still doing it.

Aenosh Rajora — Program Director
person
Founder · CEO

Aenosh Rajora

Program Director

Designs the internship curriculum and leads sessions on attack tradecraft, protocol abuse, and adversary thinking. Built the program to mirror real security operations — not textbook theory.

Offensive Security · Red Team · Active Directory
Red TeamActive DirectoryVAPTNetwork Attacks
View LinkedIn Profile
Haydn Kuti — Defensive Operations Mentor
person
Lead Community Operator

Haydn Kuti

Defensive Operations Mentor

Leads sessions on SOC workflows, alert triage, log analysis, and threat detection. Brings Top 2% TryHackMe performance and real blue team execution experience to the cohort.

Defensive Security · Threat Investigation · Incident Response
SOC OperationsMalware AnalysisIncident ResponseLog Analysis
Top 2% TryHackMe
Holmes CTF — Hack The Box
ISC2 CC CompTIA Security+
View LinkedIn Profile
Melissa Dixon — Network Analysis & CTI Mentor
person
Lead Community Operator

Melissa Dixon

Network Analysis & CTI Mentor

Focuses on traffic analysis, Wireshark labs, and network-level investigation. Brings practical CTI experience and ethical hacking depth to packet-level and detection-focused sessions.

CTI · Network Analysis · Ethical Hacking · Incident Response
WiresharkTcpdumpEthical HackingCTI
Google Cybersecurity ISC2 Candidate
View LinkedIn Profile

What You Will Learn

How networks function and where attacks enter the picture

How to capture, filter, and interpret real network traffic

How attackers abuse protocols and exploit weak architectures

How to detect, triage, and investigate network threats

How to harden infrastructure using defensive frameworks

How to present technical findings and document professionally

Program Structure

8 weeks. 2 sessions per week. Each week closes with an intern presentation. Progressively deeper.

W01

Networking Foundations & Security Mindset

OSI/TCP-IP models, packet flow, DNS/DHCP/ARP deep dives, and understanding why network security fails in real organisations.

OSI ModelDNS/DHCP/ARPNAT/PATThreat Categories
W02

Network Protocol Deep Dive

TCP internals, DNS tunneling, SMB, Kerberos, RDP/SSH security, SNMP risks, and NTP reflection/abuse.

TCP InternalsSMB/NetBIOSKerberosSNMP Risks
W03

Traffic Analysis & Wireshark Ops

Full PCAP malware investigation — detect port scans, brute force, C2 beaconing, and reconstruct attack sessions.

WiresharkC2 DetectionPCAP AnalysisBeaconing
W04

Firewalls, ACLs & Segmentation

Build ACL rule sets, segment flat enterprise networks, design DMZ architecture, and apply Zero Trust principles.

ACL DesignVLAN SecurityDMZZero Trust
W05

IDS/IPS & Detection Engineering

Write Suricata rules, triage alerts, correlate across events, and execute PCAP-to-detection rule exercises.

SuricataAlert TriageRule WritingFalse Positives
W06

Network Hardening & Secure Architecture

Audit device configs for hardening gaps, design secure remote access, review bastion host and VPN architecture.

Switch/Router HardeningAAA BasicsVPN DesignJump Servers
W07

Network Attacks & Adversary Tradecraft

Study MITM, ARP spoofing, VLAN hopping, BGP hijacking, DDoS amplification, and network-based persistence.

ARP SpoofingVLAN HoppingBGP HijackingBotnets
W08

Blue Team Ops & Final Capstone

SOC/NOC/NSOC triage workflows, escalation, documentation standards, and final capstone: Secure and Defend a Mock Enterprise Network.

SOC WorkflowTriageCapstoneCareer Dev

Weekly Presentation Track

Every week you stand up, present your findings, and defend your work. Communication is a core operator skill.

W01
Technical Diagram

Explain How a Packet Travels From Browser to Server

Annotated diagram with per-layer breakdown and one attack vector identified per layer

W02
Research Brief

Most Abused Enterprise Protocol and Why

Research brief covering CVE history, exploitation method, and real-world business impact

W03
Live Investigation

Analyse This PCAP and Present Findings

Full malware PCAP investigation: victim host, initial suspicious packet, C2 infrastructure, payload transfer, beaconing pattern

W04
Architecture Design

Design Secure Network Segmentation for a Small Enterprise

Network diagram with VLAN layout, DMZ design, ACL rule set, and Zero Trust rationale

W05
Triage Report

Investigate an IDS Alert and Explain Your Verdict

Alert triage walkthrough with true/false positive determination and supporting evidence chain

W06
Hardening Audit

Harden a Given Network Architecture

Config audit with gap analysis, prioritised remediation steps, and secure architecture redesign

W07
Case Study

Break Down One Real Network Attack Case Study

Kill-chain analysis of a real-world attack (e.g. Mirai Botnet, AS7007 BGP Hijack) with lessons learned

W08
Capstone Final Capstone

Final Capstone: Secure and Defend a Mock Enterprise Network

Network diagram · Segmentation strategy · Firewall rule set · Detection logic · Threat model · Attack path analysis

Week 8 — Final Capstone Requirements

Your capstone must cover all six components. This is the definitive evaluation of your operator-level capability.

Network Diagram
Segmentation Strategy
Firewall Rule Set
Detection Logic
Threat Model
Attack Path Analysis

Performance-Based Recognition

Certificates are earned — not distributed. Your tier reflects actual output, assessed across all 8 weeks by your mentors.

Entry Level

Apprentice

  • Attended 80%+ of all live sessions
  • Completed and submitted all weekly presentations
  • Participated in Q&A and group discussions throughout

Demonstrates consistent participation and foundational network security knowledge across all 8 weeks.

Top-Tier Level

Operator

  • All Analyst-level criteria met
  • Exceptional six-component final capstone
  • End-to-end operator-level thinking demonstrated
  • Formally recognised by instructors for output quality

Reserved for interns who demonstrate true operator capability — someone TCL would refer to employers with confidence.

Certificate tier is determined by your mentors at program end based on session attendance, presentation quality, lab outputs, and capstone execution. All assessments are final and non-negotiable.

How You'll Actually Learn

  • Live PCAP traffic analysis with real attack patterns
  • Firewall rule writing and ACL design exercises
  • Network diagram threat modelling assignments
  • Detection engineering with Suricata/Snort rule writing
  • Hardening checklists applied to real device configs
  • CVE breakdown and deep-dive research assignments
  • Weekly presentations defending your technical findings

Real-World Toolset

Wireshark
Suricata / Snort
Nmap
Linux Networking Tools
Packet Crafting Utilities

Built-In Learning Systems

Every week has structured deliverables so you're never stuck — and never coasting.

24 Live Touchpoints
Weekly Intern Presentations
Wireshark PCAP Challenges
Firewall Rule Exercises
Network Diagram Threat Modeling
Hardening Checklists
Private Intern Community

How to Earn Your Certificate

Meet all four criteria to qualify. Partial completion does not result in a certificate.

Attend 80%+ Sessions

Show up consistently. Reliability is the first operator-level behaviour we assess.

Complete Weekly Presentations

Every week, you present your findings to the cohort and defend your work.

Submit Final Capstone

A complete six-component enterprise network defence submission — no partial credit.

Participate in Q&A

Active, meaningful discussion and peer engagement expected across all sessions.

Where This Takes You

By program end you'll have real hands-on experience, a capstone project, and interview-ready skills for defensive security roles.

SOC / NSOC Analyst

Network Security Engineer

Blue Team Operator

Gain hands-on experience with real defensive tooling and enterprise scenarios
Build a capstone project and documented write-up for your portfolio
Develop presentation skills to explain and defend findings in interviews
Understand how to continue into advanced offensive training at TCL
  • Beginners and intermediate learners entering network security
  • Students preparing for SOC or blue team roles
  • Anyone wanting structured, mentor-led defensive training
  • Those targeting Net+ / CCNA / entry-level security certifications
  • Not passive — you present, analyse, and defend findings every week
  • Real-world defensive scenarios, not outdated theory or recycled slides
  • Traffic analysis + hardening + detection combined in one program
  • Mentored by practitioners — not hired instructors with no field experience

Train like it's your job.

24 live sessions. Weekly presentations. A capstone that proves your skills. Mentored by three active practitioners. Limited seats per cohort — this is an internship, not a course you can coast through.

Registration Closed

No refunds after enrolment.   Read the Refund Policy →

Limited seats per cohort · live sessions · direct practitioner feedback