I2W Training Institute

Twelve weeks. Two operations skill sets. One serious start.

Most entry-level courses teach either networking or security. This one deliberately covers both — the NOC discipline that keeps infrastructure running and the SOC discipline that defends it — because that combination is exactly what L1/L2 hiring managers look for. It is taught in person at our Noida office by the consultants who run live client operations, and 80% of your time is spent in the lab, not the slides.

12 wks
Three focused months, Monday to Friday
180 hrs
Contact hours with working I2W consultants
80%
Practical, 20% theory — real tool exposure
24+
Industry tools used hands-on in the lab

Why this programme

Built by an operations company, not a coaching centre.

Everything you practise here comes out of real shifts: the tickets we actually raise, the alerts we actually tune, the reports we actually send to clients after an incident. That is the difference between knowing what a SIEM is and being trusted to work one.

Trainers who do this for a living

You are taught by the NOC/SOC and security consultants who run client operations at I2W, not by full-time lecturers reading a syllabus.

80% practical, 20% theory

Splunk, Wazuh, Zabbix, ServiceNow, Nessus, Wireshark, Burp Suite and more — configured by you, in the I2W training lab.

A certificate from an operations company

Certificate of Completion from I2W Consultants Pvt. Ltd., awarded at 80% or higher overall score and 90% attendance.

Career support built in

Resume building, L1/L2 interview prep, individual mock interviews with industry experts, placement support and referral assistance.

Curriculum

Week by week, from a subnet mask to a live attack drill.

Month 1

Foundation, networking and NOC operations

W1

Networking fundamentals and the OSI/TCP-IP stack

  • · Topologies, IPv4/IPv6 addressing and subnetting in depth
  • · OSI seven-layer model against the TCP/IP model
  • · DNS, DHCP, FTP, HTTP/HTTPS, SSH, Telnet and ICMP

Lab · Firewall packet capture and subnetting practice

W2

Advanced networking and infrastructure

  • · Routing with OSPF and BGP; switching with VLANs, STP and trunking
  • · Firewalls, routers, switches and access point setup
  • · Load balancers and VPNs (IPSec, SSL VPN)

Lab · Virtual network build in Cisco Packet Tracer and EVE-NG

W3

Core NOC operations and monitoring tools

  • · NOC architecture and the L1/L2/L3 support workflow
  • · Deploying Nagios, Zabbix, PRTG and SolarWinds
  • · Troubleshooting with ping, traceroute, MTR and netstat

Lab · PRTG / Zabbix dashboard, server and port monitoring

W4

Incident management and ITIL (NOC capstone)

  • · Incident, problem, change and configuration management
  • · Ticketing in ServiceNow and Jira
  • · SLA management and the escalation matrix

Lab · Create, manage and resolve L1/L2 tickets in a ServiceNow / Jira simulator

Where you stand: You can build, monitor and troubleshoot an enterprise network — and run its ticket queue like an L1/L2 NOC engineer.

Month 2

Cyber security fundamentals and SOC operations

W5

Inside a SOC and the threat landscape

  • · L1 and L2 analyst roles, shift handover and escalation
  • · The Cyber Kill Chain and MITRE ATT&CK in depth
  • · Phishing, ransomware, DDoS, malware, SQLi and XSS

Lab · Real-world attack vector analysis and phishing header forensics

W6

SIEM part 1 — collection and normalisation

  • · Splunk, IBM QRadar, Wazuh and Log360 compared
  • · Collecting syslog, Windows event, firewall and web server logs
  • · Parsing, normalisation and search queries (SPL/KQL); the ELK stack

Lab · Stand up Splunk / Wazuh and ingest Windows and Linux logs

W7

SIEM part 2 — detection engineering

  • · Custom use cases and alerting rules
  • · SPL, KQL and Wazuh XML/JSON rulesets
  • · Correlation for brute force, privilege escalation and suspicious PowerShell
  • · False-positive tuning and dashboard building

Lab · Build SOC dashboards and write your own correlation rules

W8

EDR, DLP and VAPT overview

  • · EDR/XDR operations with CrowdStrike, Defender and SentinelOne
  • · DLP policy design and endpoint control
  • · Introduction to vulnerability assessment and penetration testing

Lab · Configure DLP and EDR rules against exfiltration; Nmap, Burp Suite and SQLMap

Where you stand: You can operate a SIEM end to end — ingest logs, write detections mapped to MITRE ATT&CK, and defend endpoints and data.

Month 3

Incident response, SOC drills and career preparation

W9

Incident response basics

  • · The IR life cycle under the NIST and SANS frameworks
  • · Threat hunting and extracting indicators of compromise

Lab · Incident triage drill in the training lab

W10

Real-world SOC simulation and drills

  • · Red team versus blue team, and purple teaming basics
  • · Handling a simulated ransomware, DDoS or malware outbreak
  • · Incident report writing and root cause analysis

Lab · End-to-end attack and defence simulation

W11

Compliance and cloud security basics

  • · ISO 27001, SOC 2 and DPDP Act overview
  • · AWS and Azure SOC/NOC monitoring basics
  • · Email security and gateway protection

Lab · AWS CloudWatch / Azure Sentinel log monitoring setup

W12

Career readiness, resume and mock interviews

  • · Writing a resume around real lab and project work
  • · L1/L2 technical interview prep: networking, SIEM, threat scenarios
  • · Individual mock interviews with industry experts

Lab · Placement support and referral assistance onboarding

Where you stand: You have survived a full attack-and-defence drill, can write an incident report — and can walk into an L1/L2 interview prepared.

Tools

Train on the tools employers name in the job advert.

WiresharkCisco Packet TracerEVE-NGNagiosZabbixPRTGSolarWindsServiceNowJiraSplunkIBM QRadarWazuhLog360ELK / Elastic StackMS SentinelCrowdStrikeDefender EDRSentinelOneNmapBurp SuiteSQLMapNessusAWS CloudWatchAzure Sentinel

Where this takes you

  1. 01NOC Engineer (L1/L2)
  2. 02SOC Analyst (L1/L2)
  3. 03Network Support Engineer
  4. 04SIEM Analyst
  5. 05Monitoring Analyst
  6. 06Incident Response Trainee
  7. 07VA Analyst (entry)
  8. 08IT Operations Analyst

Batches

Pick the half of the day that suits you.

Seats per batch are capped deliberately — a lab stops being hands-on the moment three people share one console.

  • 12 weeks · 180 contact hours
  • In person · I2W office, Noida
  • +91-9821893190 · info@i2w.co.in

Morning batch

Monday to Friday · limited seats

9:00 AM – 12:00 PM

Afternoon batch

Monday to Friday · limited seats

2:00 PM – 5:00 PM

Every Saturday

Group discussion on the week's labs

Doubt clearing + weekly test

Admission

Five steps from enquiry to your first lab.

01

Register your interest

Fill the form below, write to info@i2w.co.in or call +91-9821893190.

02

Free counselling and batch selection

We talk through your background and pick the morning or afternoon batch.

03

Short aptitude conversation

No entrance exam. Basic computer familiarity is enough to start.

04

Confirm your seat

Seats per batch are capped so every learner gets real lab time.

05

Start your 12-week journey

In person at the I2W office in Noida, hands-on from week one.

Enrolment enquiry

Tell us where you are starting from.

There is no entrance exam. A counsellor reviews what you send, calls you within one business day, and tells you honestly whether this programme fits your background and the batch you want.

Your details are used only to discuss this programme. No mailing list, no reselling, no calls you did not ask for.

Questions we get asked

I have no security background at all. Can I still join?

Yes. Month 1 starts at networking fundamentals and assumes only basic computer familiarity. What you do need is attendance — the labs build on each other week by week.

Is this online or classroom?

In person at the I2W office in Noida. The labs run on our training infrastructure, and a large part of the value is being in the room with consultants who handle live incidents.

What certificate do I get?

A Certificate of Completion from I2W Consultants Pvt. Ltd., awarded at 80% or higher overall score and 90% attendance. Assessment is weekly labs 30%, mid-programme practical 20%, capstone drill 30% and final practical 20%.

Do you guarantee a job?

No honest institute can. What we do provide is 100% placement support: resume building, mock interviews with working analysts, referrals into our network, and an internship with I2W operations for top performers of each batch.

Can our college run a dedicated batch?

Yes. We run campus partnerships with dedicated batches, semester tie-ups and faculty coordination. Choose 'College / university partnership' in the form and we will get back with a proposal.