Skip to content
Macksofy Technologies
EC-Council CEH v13

CEH v13 AI Training in India 2026 — Syllabus, Cost, Institutes & Career Guide

EC-Council's CEH v13 added AI throughout the curriculum. India 2026 guide — what's new, real cost in INR, exam mechanics, hiring impact and how to pick an EC-Council ATC.

CEH CEH v13 EC-Council AI
Macksofy Editorial29 April 2026 15 min read
CEH v13 AI Training in India 2026 — Syllabus, Cost, Institutes & Career Guide — Certification Guides · Macksofy
In short

What is the CEH v13 syllabus?

The CEH v13 syllabus is EC-Council's 20-module curriculum following the five phases of ethical hacking — reconnaissance, scanning, gaining access, maintaining access and covering tracks. It runs from footprinting and system hacking through web, wireless, mobile, IoT/OT, cloud and cryptography, with AI threaded across modules rather than added as one. Macksofy is an EC-Council Accredited Training Center.

EC-Council's CEH v13 is the first major version that genuinely integrates AI across the curriculum — not as a marketing chapter, but as concrete content on AI-driven recon, prompt-injection attacks, AI-assisted exploitation and defensive uses of LLMs in SOC operations. Whether that makes it worth your time in 2026 is a more interesting question than 'is CEH still relevant?' Let's break it down.

What's actually new in v13

  • AI-driven reconnaissance (LLM-assisted OSINT, target profiling)
  • Prompt-injection attacks against LLM-integrated applications
  • AI-assisted exploitation (LLMs for fuzzing, pattern matching, payload generation)
  • Detection-engineering use cases — LLMs in SOC playbooks
  • Updated OWASP Top 10 mappings (covers LLM Top 10 separately)
  • Refreshed labs around modern cloud, container and Kubernetes attacks

Pricing in India 2026

ItemList price (₹)With ATC
CEH v13 self-paced55,000
CEH v13 instructor-led (5-day)75,00055,000–60,000
CEH Master (CEH + CEH Practical)85,00065,000–70,000
Exam voucher only30,00030,000
iLabs add-on15,000Included with ATC

CEH v13 syllabus — all 20 modules

CEH v13 is organised into 20 modules that follow the five phases of ethical hacking — reconnaissance, scanning, gaining access, maintaining access and covering tracks. EC-Council puts the course at 221 hands-on labs, 550 attack techniques and over 4,000 tools. The module names below are EC-Council's own; the coverage column summarises what each one actually spends its time on.

#ModuleWhat it covers
01Introduction to Ethical HackingSecurity fundamentals, the five phases, hacker and attack classes, Cyber Kill Chain and MITRE ATT&CK, plus the compliance framing (PCI DSS, HIPAA, SOX, GDPR).
02Footprinting and ReconnaissancePassive and active intelligence gathering — WHOIS and DNS, search-engine and social-media OSINT, competitive intelligence, AI-assisted recon.
03Scanning NetworksHost discovery, port and service scanning, OS fingerprinting, and evading scan detection.
04EnumerationPulling usernames, shares and service detail via NetBIOS, SNMP, LDAP, NTP, SMTP and DNS.
05Vulnerability AnalysisVulnerability classification, CVSS scoring, scanner operation — and reading the output rather than dumping it.
06System HackingPassword attacks, privilege escalation, execution, hiding artefacts and clearing logs.
07Malware ThreatsTrojans, viruses, worms, fileless malware, APT behaviour, and the basics of static and dynamic analysis.
08SniffingPacket capture, ARP poisoning, MAC flooding, DNS spoofing, and how defenders detect each.
09Social EngineeringPretexting, phishing, impersonation, insider threat, and human-layer countermeasures.
10Denial-of-ServiceDoS and DDoS techniques, botnets, amplification, and mitigation approaches.
11Session HijackingApplication and network-level hijacking, token theft, replay attacks and defences.
12Evading IDS, Firewalls, and HoneypotsDetection-evasion techniques, and how defenders spot them being used.
13Hacking Web ServersServer misconfiguration, patch-management failure, and web-server attack methodology.
14Hacking Web ApplicationsThe web application attack surface — authentication, authorisation, input handling and the OWASP-aligned flaw classes.
15SQL InjectionInjection types, detection, exploitation, and parameterisation as the real defence.
16Hacking Wireless NetworksWi-Fi encryption weaknesses, rogue access points, and wireless attack tooling.
17Hacking Mobile PlatformsAndroid and iOS attack surface, mobile malware, MDM, and application-layer flaws.
18IoT and OT HackingIoT and OT protocols and architecture, ICS/SCADA exposure, and the safety constraints that make OT testing different.
19Cloud ComputingCloud service models, container and serverless concerns, misconfiguration, and shared-responsibility boundaries.
20CryptographyAlgorithms, PKI, encryption in transit and at rest, cryptanalysis and crypto-attack classes.

CEH v13 module list as published by EC-Council. Confirm the current outline against EC-Council before enrolling — course content is revised between versions.

Exam mechanics

  • 125 multiple-choice questions in 4 hours
  • Cut score: 60–85%, calibrated per exam form — there is no single fixed pass mark
  • CEH Practical: 20 real-world challenges in 6 hours, same cut-score range
  • Format: online proctored or at Pearson VUE centres in Mumbai/Delhi/Bangalore

Where CEH v13 actually helps in India

  • BFSI hiring filters — most banks list CEH as required for SOC / pentest roles
  • Government & PSU bidding — DoD 8570 equivalent, often mandatory
  • Big-4 audit & advisory — CEH + CISA = audit/advisory hiring stack
  • Foreign work visas — recognised globally, easier paperwork

How to pick an EC-Council ATC in India

  1. Verify the ATC status directly on EC-Council's website
  2. Ask for the trainer's CEI (Certified EC-Council Instructor) credentials
  3. Check whether iLabs is included or separately priced
  4. Look for places running CEH Master tracks (CEH + Practical) — proof of depth
  5. Avoid centres advertising 'CEH v13 dump' — these guarantee failure on AI-aware questions
Train with an EC-Council ATC in Mumbai

Macksofy runs CEH v13 as a classroom and live-online ethical hacking course in Mumbai — official EC-Council courseware, iLabs access, one exam voucher, and mentorship that runs until you clear the exam.

See the ethical hacking course in Mumbai
FAQ

Quick answers.

Different goals. CEH passes HR filters; OSCP closes technical interviews. If you have the budget, do CEH first (5 days, fast résumé add) then OSCP (3-6 months, real depth).
Three years. Renewal requires 120 ECE credits — Macksofy alumni get free webinars that count toward this.
Yes, especially with prior IT background. But the labs (iLabs) only come with the official course bundle, and EC-Council requires a 2-year experience attestation if you skip the official training.
References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements