EC-Council's CEH v13 is the first major version that genuinely integrates AI across the curriculum — not as a marketing chapter, but as concrete content on AI-driven recon, prompt-injection attacks, AI-assisted exploitation and defensive uses of LLMs in SOC operations. Whether that makes it worth your time in 2026 is a more interesting question than 'is CEH still relevant?' Let's break it down.
What's actually new in v13
- AI-driven reconnaissance (LLM-assisted OSINT, target profiling)
- Prompt-injection attacks against LLM-integrated applications
- AI-assisted exploitation (LLMs for fuzzing, pattern matching, payload generation)
- Detection-engineering use cases — LLMs in SOC playbooks
- Updated OWASP Top 10 mappings (covers LLM Top 10 separately)
- Refreshed labs around modern cloud, container and Kubernetes attacks
Pricing in India 2026
| Item | List price (₹) | With ATC |
|---|---|---|
| CEH v13 self-paced | 55,000 | — |
| CEH v13 instructor-led (5-day) | 75,000 | 55,000–60,000 |
| CEH Master (CEH + CEH Practical) | 85,000 | 65,000–70,000 |
| Exam voucher only | 30,000 | 30,000 |
| iLabs add-on | 15,000 | Included with ATC |
CEH v13 syllabus — all 20 modules
CEH v13 is organised into 20 modules that follow the five phases of ethical hacking — reconnaissance, scanning, gaining access, maintaining access and covering tracks. EC-Council puts the course at 221 hands-on labs, 550 attack techniques and over 4,000 tools. The module names below are EC-Council's own; the coverage column summarises what each one actually spends its time on.
| # | Module | What it covers |
|---|---|---|
| 01 | Introduction to Ethical Hacking | Security fundamentals, the five phases, hacker and attack classes, Cyber Kill Chain and MITRE ATT&CK, plus the compliance framing (PCI DSS, HIPAA, SOX, GDPR). |
| 02 | Footprinting and Reconnaissance | Passive and active intelligence gathering — WHOIS and DNS, search-engine and social-media OSINT, competitive intelligence, AI-assisted recon. |
| 03 | Scanning Networks | Host discovery, port and service scanning, OS fingerprinting, and evading scan detection. |
| 04 | Enumeration | Pulling usernames, shares and service detail via NetBIOS, SNMP, LDAP, NTP, SMTP and DNS. |
| 05 | Vulnerability Analysis | Vulnerability classification, CVSS scoring, scanner operation — and reading the output rather than dumping it. |
| 06 | System Hacking | Password attacks, privilege escalation, execution, hiding artefacts and clearing logs. |
| 07 | Malware Threats | Trojans, viruses, worms, fileless malware, APT behaviour, and the basics of static and dynamic analysis. |
| 08 | Sniffing | Packet capture, ARP poisoning, MAC flooding, DNS spoofing, and how defenders detect each. |
| 09 | Social Engineering | Pretexting, phishing, impersonation, insider threat, and human-layer countermeasures. |
| 10 | Denial-of-Service | DoS and DDoS techniques, botnets, amplification, and mitigation approaches. |
| 11 | Session Hijacking | Application and network-level hijacking, token theft, replay attacks and defences. |
| 12 | Evading IDS, Firewalls, and Honeypots | Detection-evasion techniques, and how defenders spot them being used. |
| 13 | Hacking Web Servers | Server misconfiguration, patch-management failure, and web-server attack methodology. |
| 14 | Hacking Web Applications | The web application attack surface — authentication, authorisation, input handling and the OWASP-aligned flaw classes. |
| 15 | SQL Injection | Injection types, detection, exploitation, and parameterisation as the real defence. |
| 16 | Hacking Wireless Networks | Wi-Fi encryption weaknesses, rogue access points, and wireless attack tooling. |
| 17 | Hacking Mobile Platforms | Android and iOS attack surface, mobile malware, MDM, and application-layer flaws. |
| 18 | IoT and OT Hacking | IoT and OT protocols and architecture, ICS/SCADA exposure, and the safety constraints that make OT testing different. |
| 19 | Cloud Computing | Cloud service models, container and serverless concerns, misconfiguration, and shared-responsibility boundaries. |
| 20 | Cryptography | Algorithms, PKI, encryption in transit and at rest, cryptanalysis and crypto-attack classes. |
CEH v13 module list as published by EC-Council. Confirm the current outline against EC-Council before enrolling — course content is revised between versions.
Exam mechanics
- 125 multiple-choice questions in 4 hours
- Cut score: 60–85%, calibrated per exam form — there is no single fixed pass mark
- CEH Practical: 20 real-world challenges in 6 hours, same cut-score range
- Format: online proctored or at Pearson VUE centres in Mumbai/Delhi/Bangalore
Where CEH v13 actually helps in India
- BFSI hiring filters — most banks list CEH as required for SOC / pentest roles
- Government & PSU bidding — DoD 8570 equivalent, often mandatory
- Big-4 audit & advisory — CEH + CISA = audit/advisory hiring stack
- Foreign work visas — recognised globally, easier paperwork
How to pick an EC-Council ATC in India
- Verify the ATC status directly on EC-Council's website
- Ask for the trainer's CEI (Certified EC-Council Instructor) credentials
- Check whether iLabs is included or separately priced
- Look for places running CEH Master tracks (CEH + Practical) — proof of depth
- Avoid centres advertising 'CEH v13 dump' — these guarantee failure on AI-aware questions
Macksofy runs CEH v13 as a classroom and live-online ethical hacking course in Mumbai — official EC-Council courseware, iLabs access, one exam voucher, and mentorship that runs until you clear the exam.
