Skip to main content

+92 348 6603537 info@secstackhq.com

SECSTACKHQ AGENCY & ACADEMY

Academy

SecStack Academy

Live online training run by people who test systems every week, so the examples in class come from last month's work. Taught in English and Urdu.

Admissions: +92 348 6603537 or info@secstackhq.com

Free beginner workshops, limited seats

Before you pay for anything, come and see whether the field suits you. Two hours, live online, with lab access on the day. You leave having found your first vulnerability yourself. Seats are capped so everyone gets help when they get stuck.

  • Ethical hacking, first steps
  • Build your first web page
  • Staying safe online, for everyone

Next batch

Sat, 4 October · 3:00 PM PKT

Live online (Zoom link on confirmation)

9 of 25 seats left

Reserve a free seat

Two-month certification courses

Eight weeks, two or three live sessions a week, one capstone project at the end.

Certified Ethical Hacker (CEH) practical prep

The full CEH blueprint, practised rather than memorised. Run reconnaissance on a target range, scan and enumerate, exploit misconfigurations, then write the findings up the way a client expects to receive them.

Duration
8 weeks
Level
Beginner
Fee
PKR 10,000
Enroll now

Certified Penetration Testing Professional (CPENT) labs

For students who already have the basics. Pivoting between segmented networks, privilege escalation on Windows and Linux, Active Directory attack paths, and a full report written under time pressure.

Duration
8 weeks
Level
Advanced
Fee
PKR 20,000
Enroll now

Web application security and bug bounty auditing

The OWASP Top 10 hands-on, then the skills that separate a duplicate report from a paid one: reading JavaScript for hidden endpoints, testing business logic, and writing a report a triager can reproduce in two minutes.

Duration
8 weeks
Level
Intermediate
Fee
PKR 15,000
Enroll now

Full-stack web development and technical SEO architecture

Build and deploy three real projects. Front end, backend, database and hosting, finishing with the SEO work that decides whether anyone ever finds what you built.

Duration
8 weeks
Level
Beginner
Fee
PKR 10,000
Enroll now

Weekend batches

Saturday and Sunday, 11:00 AM to 2:00 PM PKT. Built for people with a full-time job or a university schedule.

Evening batches

Monday, Wednesday and Friday, 8:00 PM to 10:00 PM PKT, after office hours.

Live interactive labs

Every class is live with instructor support on a shared lab range. Sessions are recorded for revision.

Eight-week curriculum

Module outline for the security tracks. The web development track follows the same rhythm with its own projects.

Module 1Reconnaissance and footprinting+
Linux command line, networking refresher, and how a tester maps a target before touching it: DNS records, subdomain discovery, certificate transparency logs, public repositories and employee footprint. Ends with a written recon report on a target we own.
Module 2Scanning and enumeration+
Port and service discovery, banner analysis, SMB and SNMP enumeration, and reading a scan result critically instead of trusting the tool's confidence score.
Module 3Network security and defences+
How firewalls, IDS and segmentation actually behave, where they are usually misconfigured, and what a defender sees while a test is running.
Module 4Exploitation and post-exploitation+
Turning a confirmed weakness into proof of impact inside a controlled lab: password attacks, misconfigured services, privilege escalation on Linux and Windows, and the discipline of staying inside an agreed scope.
Module 5Web application audits, part one+
Burp Suite workflow end to end. Injection, broken access control, authentication and session flaws, and insecure direct object references.
Module 6Web application audits, part two+
File upload abuse, server-side request forgery, deserialisation basics, and business logic testing that no scanner will ever find for you. Includes bug bounty scope reading and duplicate avoidance.
Module 7Reporting, ethics and the law+
Writing the deliverable clients pay for: executive summary, risk rating, reproduction steps and remediation advice. Plus written authorisation, responsible disclosure, and what Pakistan's electronic crimes law means for your work.
Module 8Capstone: a real-world pentest report+
A full assessment of a lab environment on your own, from scoping to final report, reviewed line by line by the instructor. Then CV review, portfolio of write-ups, and the interview questions that actually come up.

Reserve your seat

Fill this in and your details open a WhatsApp message to our admissions line, already written. We confirm your batch the same day, usually within a couple of hours.

Prefer to talk first? Call or WhatsApp +92 348 6603537, or email info@secstackhq.com.

Preferred batch

This opens WhatsApp with your details filled in. Nothing is stored on this website. See our privacy policy.

Questions about the academy

Can I switch from a weekend batch to an evening batch after enrolling?

Yes, once, if a seat is open in the batch you want to move to. Ask your instructor or email admissions before the third class; after that point the curriculum has diverged enough that switching disrupts both batches.

Do you provide a certificate of completion?

Yes. Students who complete the capstone project receive a SecStackHQ certificate of completion naming the course and the modules covered. This is separate from and does not replace an EC-Council certification, which is issued only after you pass their exam.

What do I need to join the live online classes?

A laptop or desktop with at least 8GB of RAM, a stable internet connection, and Zoom installed. Lab access runs through a browser, so no separate virtual machine software is required on your side.