Skip to content
Macksofy Technologies
EC-Council Accredited Training Center · India

CEH v13 Training in India

Master ethical hacking on EC-Council’s AI-powered Certified Ethical Hacker v13 — 20 modules, 221 hands-on labs and the 312-50 exam, taught live by consultants who run real security assessments the rest of the week.

  • EC-Council Accredited Training Center
  • CERT-In empanelled auditor
  • Mumbai BKC, since 2014
  • Live online across India
In short

What is CEH v13 training?

CEH v13 training prepares you for EC-Council's Certified Ethical Hacker certification — 20 modules covering reconnaissance through cloud, IoT and cryptography, with 221 hands-on labs and AI-assisted testing workflows. Macksofy delivers it live across India as an EC-Council Accredited Training Center, including the 312-50 exam voucher.

The certification

What is CEH v13?

Certified Ethical Hacker is EC-Council's foundational offensive-security certification. Version 13 keeps the 20-module structure and adds AI-assisted working across it.

An ethical hacker attacks systems with the owner’s permission in order to find weaknesses before someone malicious does. CEH is the certification that formalises that work into a repeatable method: reconnaissance, scanning, gaining access, maintaining access and covering tracks — the five phases every module maps back to.

CEH v13 covers twenty modules, from footprinting through web applications, SQL injection, wireless, mobile, IoT and OT, cloud and cryptography. EC-Council publishes 221 hands-on labs, 550 attack techniques and exposure to more than 4,000 hacking and security tools across the programme. The distinguishing feature of v13 is that AI is threaded through the existing modules as an assistive skill — there is no separate AI module.

It is a breadth certification, and that is its value. It gives you the vocabulary and the map of the whole attack surface. Depth on any one part of it — the kind OSCP demands — comes afterwards.

20
modules, in a fixed order
221
hands-on labs
550
attack techniques covered
4,000+
tools introduced

Figures published by EC-Council for CEH v13.

v12 → v13

What changed in CEH v13

Only the differences EC-Council itself positions. The module count and exam format did not change.

Comparison of CEH v12 and CEH v13 across curriculum, labs and exam format
AreaCEH v12CEH v13
AI in the curriculumNot positioned as an AI-integrated course.AI is threaded through all 20 modules as an assistive skill — there is no standalone AI module.
Module count20 modules.20 modules — the structure is retained, the content within it is refreshed.
Hands-on scopeLab-heavy, delivered through EC-Council's lab environment.221 labs, 550 attack techniques and exposure to 4,000+ hacking and security tools.
Attack surfacesCloud, IoT/OT, mobile and web already present.Same surfaces, with contemporary techniques and tooling refreshed throughout.
Exam format312-50 knowledge exam, plus the separate CEH Practical.Unchanged — 125 multiple-choice questions over 4 hours, with CEH Practical still separate.
AI-powered ethical hacking

Where AI actually helps an ethical hacker

AI in CEH v13 is an assistive layer over an authorised testing workflow. It compresses the slow, high-volume steps so the tester spends their time on judgement.

  1. Reconnaissance

    Summarise large OSINT and DNS datasets, cluster related assets, and surface the handful of hosts worth manual attention.

  2. Enumeration

    Normalise noisy service output across hundreds of hosts and flag version patterns a human would skim past.

  3. Analysis

    Cross-reference findings against known weakness classes and draft a first-pass severity rationale for the tester to accept or reject.

  4. Attack paths

    Propose plausible chains between findings so the tester can test the chain rather than reporting isolated issues.

  5. Testing

    Generate and adapt payload variations for authorised targets, and script repetitive verification steps.

  6. Reporting

    Draft finding descriptions and remediation wording, leaving evidence, proof and the final judgement with the tester.

AI does not hack systems on its own here. Every step above happens inside an engagement someone has authorised in writing, against a scope someone agreed, with a human accountable for what is run and what is reported. The skill CEH v13 is teaching is directing the tool — and knowing when its output is wrong.

Curriculum

All 20 CEH v13 modules

EC-Council's module list in its official order, with what each one covers and what you practise in the lab.

Introduction to Ethical Hacking

Security fundamentals, the five phases of hacking, hacker and attack classes, the Cyber Kill Chain and MITRE ATT&CK, plus the compliance framing behind authorised testing.

You practise Frame an engagement legally and map an attack to a recognised kill-chain stage.

Footprinting and Reconnaissance

Passive and active intelligence gathering — WHOIS and DNS, search-engine and social-media OSINT, competitive intelligence, and AI-assisted reconnaissance.

You practise Build an accurate external attack-surface picture before touching a target.

Scanning Networks

Host discovery, port and service scanning, OS fingerprinting, and evading scan detection.

You practise Run and interpret a scan rather than dumping raw tool output.

Enumeration

Pulling usernames, shares and service detail via NetBIOS, SNMP, LDAP, NTP, SMTP and DNS.

You practise Turn open ports into named users, shares and versions worth attacking.

Vulnerability Analysis

Vulnerability classification, CVSS scoring and scanner operation — with emphasis on reading the output rather than forwarding it.

You practise Separate a real finding from scanner noise and score it defensibly.

System Hacking

Password attacks, privilege escalation, execution, hiding artefacts and clearing logs.

You practise Chain a foothold into privileged access on Windows and Linux.

Malware Threats

Trojans, viruses, worms, fileless malware, APT behaviour, and the basics of static and dynamic analysis.

You practise Recognise malware behaviour and describe it in an incident context.

Sniffing

Packet capture, ARP poisoning, MAC flooding and DNS spoofing — and how defenders detect each.

You practise Capture and read traffic, and explain the detection that catches it.

Social Engineering

Pretexting, phishing, impersonation, insider threat and human-layer countermeasures.

You practise Design an authorised phishing test and brief the awareness fix.

Denial-of-Service

DoS and DDoS techniques, botnets, amplification and mitigation approaches.

You practise Explain availability risk without running destructive tests on live systems.

Session Hijacking

Application and network-level hijacking, token theft, replay attacks and defences.

You practise Identify weak session handling and prove impact safely.

Evading IDS, Firewalls, and Honeypots

Detection-evasion techniques, and how defenders spot them being used.

You practise Test whether monitoring actually fires — the purple-team half of CEH.

Hacking Web Servers

Server misconfiguration, patch-management failure, and web-server attack methodology.

You practise Assess the server layer beneath an application.

Hacking Web Applications

The web application attack surface — authentication, authorisation, input handling and the OWASP-aligned flaw classes.

You practise Work a web app methodically instead of scanning and hoping.

SQL Injection

Injection types, detection, exploitation, and parameterisation as the real defence.

You practise Find, prove and correctly remediate injection.

Hacking Wireless Networks

Wi-Fi encryption weaknesses, rogue access points and wireless attack tooling.

You practise Assess a corporate wireless deployment.

Hacking Mobile Platforms

Android and iOS attack surface, mobile malware, MDM and application-layer flaws.

You practise Reason about mobile risk beyond the app binary.

IoT and OT Hacking

IoT and OT protocols and architecture, ICS/SCADA exposure, and the safety constraints that make OT testing different.

You practise Understand why OT testing is not IT testing with different ports.

Cloud Computing

Cloud service models, container and serverless concerns, misconfiguration and shared-responsibility boundaries.

You practise Locate the customer's half of the shared-responsibility line.

Cryptography

Algorithms, PKI, encryption in transit and at rest, cryptanalysis and crypto-attack classes.

You practise Judge whether a control is genuinely protecting data.

Want the syllabus in more depth, with exam weighting and cost? Read our full CEH v13 syllabus guide.

Hands-on

What you actually do in the labs

221 labs across the programme. Every one runs in an isolated, authorised training environment — never against systems you do not own or have written permission to test.

  • Reconnaissance and OSINT
  • Network scanning and enumeration
  • Vulnerability analysis
  • System hacking and privilege escalation
  • Malware behaviour
  • Sniffing and traffic analysis
  • Social engineering
  • Web servers and web applications
  • SQL injection
  • Wireless networks
  • Mobile platforms
  • IoT and OT
  • Cloud environments
  • Cryptography
How the programme runs

From first module to working the job

  1. Learn

    Instructor-led sessions across the 20 modules, taught against how each technique appears in a real assessment.

  2. Practice

    Guided exercises after each module so the technique is used, not just watched.

  3. Lab

    Hands-on lab work in an isolated, authorised environment — the core of the course.

  4. Assess

    Mock questions under exam conditions to expose weak modules while there is still time to fix them.

  5. Certify

    Sit the CEH (312-50) knowledge exam; optionally continue to CEH Practical.

  6. Apply

    Take the methodology into SOC, VAPT or security-analyst work — the point of the certificate.

Audience

Who CEH v13 is for

What each kind of learner gets out of the same 40 hours.

Students and fresh graduates

A structured, vendor-recognised entry into security that HR filters actually screen for, plus lab hours you can talk about in an interview.

IT and system administrators

The attacker's view of the infrastructure you already run — usually the fastest route from IT into security.

Network engineers

Scanning, sniffing, evasion and wireless mapped onto the networks you design and defend.

SOC and security analysts

Offensive context for the alerts you triage; module 12 in particular explains what evasion looks like in your telemetry.

Aspiring penetration testers

The breadth layer and vocabulary that hands-on certifications assume you already have.

Developers and DevOps engineers

The web, SQL injection, cloud and cryptography modules, from the perspective of the person who will attack your build.

Career switchers

A defined syllabus and a recognised credential, with an honest view of the networking and Linux groundwork required first.

Compliance and audit professionals

Enough technical fluency to read a VAPT report critically and challenge a weak one.

Before you start

Prerequisites — and the honest version

There is a difference between what you need to follow the course and what EC-Council requires to sit the exam.

To follow the training

  • TCP/IP fundamentals — ports, protocols, the three-way handshake
  • Subnetting and basic routing concepts
  • DNS resolution and HTTP request/response structure
  • Basic Linux: filesystem, permissions, processes, reading logs
  • Comfort with a command line — no programming required

To sit the exam

EC-Council sets its own eligibility route for the 312-50 exam, and attending official training through an Accredited Training Center is the standard path. Eligibility rules are EC-Council’s to set and they revise them — we confirm the current requirement for your situation at enrolment rather than publishing a rule here that may age.

If you have no security background at all, plan a couple of weeks on networking and Linux first. That preparation changes the experience of the course more than anything else you can do.

Certification

The CEH exam, and what comes after

CEH v13 examination details
Awarding bodyEC-Council
Knowledge examCEH (312-50)
Format125 multiple-choice questions
Duration4 hours
Pass markCalibrated per exam form — EC-Council does not publish a single fixed pass percentage across all versions
Practical examCEH Practical — 20 challenges over 6 hours, sat separately
CEH MasterAwarded on holding both the knowledge certification and CEH Practical

Considering the hands-on exam as well? See CEH Practical training. Exam mechanics are EC-Council’s and can change — we confirm current details at enrolment.

Delivery

CEH v13 training across India

One national cohort, delivered live online — plus classroom delivery at our Mumbai facility.

Live online, nationwide

Instructor-led sessions delivered live — not recordings — with the same lab access, doubt-clearing and mentor support wherever you are. Learners join from Delhi, Bengaluru, Hyderabad, Pune, Chennai, Kolkata, Ahmedabad, Gurugram and Noida alongside Mumbai. Weekend cohorts exist for people in full-time work.

Classroom — Mumbai

In-person delivery runs at our Bandra Kurla Complex facility in Mumbai. That is our only classroom location — we would rather say so than imply centres we do not operate. Corporate cohorts can be delivered on-site at your offices anywhere in India by arrangement.

CEH training in Mumbai — dates and fees
Why train here

Why learn CEH v13 with Macksofy

Macksofy Technologies has run cybersecurity engagements out of Mumbai since 2014. The training division teaches from that work.

Taught by working consultants

The people teaching module 14 spend the rest of the week testing real web applications. Techniques arrive with the context of where they actually work, where they fail, and what a client asks next.

EC-Council Accredited Training Center

Official EC-Council courseware, lab access through our ATC status, and the 312-50 exam voucher included in the programme fee.

A security firm, not only a training company

Macksofy is a CERT-In empanelled information security auditing organisation delivering VAPT, red teaming and compliance audits. Training is taught out of that practice.

Lab-first delivery

Sessions are built around doing the technique in an isolated authorised environment, not watching it. Slides are the smaller half of the 40 hours.

Mentor support until you sit the exam

Weak-area reviews and doubt-clearing continue after the taught hours, so preparation does not stop when the cohort ends.

A route onward, not a dead end

CEH is the breadth layer. We will tell you honestly whether CEH Practical, a SOC track or a hands-on penetration-testing path is the right next step for your goal.

More on the consulting side of the business: VAPT, CERT-In empanelled audits and how we work.

From our assessment team

What our testers tell CEH candidates

Editorial guidance from the Macksofy assessment practice — the things that change outcomes, which no certification brochure covers.

Learn these before day one

The candidates who struggle are almost never short on enthusiasm — they are short on networking. Before the course starts, be comfortable with the TCP/IP model, what a three-way handshake looks like in a packet capture, subnetting, DNS resolution order, and HTTP request and response structure. Add basic Linux: navigating a filesystem, permissions, processes, and reading a log with grep. A fortnight on those makes the difference between following module 3 and copying it.

The mistakes we see most often

Three recur. Memorising tool flags instead of the methodology — the exam and the job both reward knowing why you scan before you enumerate. Skipping the labs because the slides feel clear; the technique only becomes yours once you have run it and had it fail. And treating scanner output as findings: an unvalidated scanner result is a hypothesis, and the whole value of a tester is separating the two.

Build practical depth alongside the certificate

CEH gives breadth. Depth comes from repetition on your own. Keep a home lab of two or three virtual machines, work through deliberately vulnerable applications, and write a short report for every box you finish — findings, evidence, impact, fix. That reporting habit is what separates a candidate who has passed an exam from one who can be put in front of a client.

What CEH covers, and what real testing adds

CEH teaches the technique catalogue. A real engagement adds everything around it: agreeing scope and rules of engagement, working within a change window, deciding not to run a test because the system is fragile, evidencing a finding so a developer can reproduce it, and defending a severity rating to someone who would rather it were lower. Expect the certificate to open the door and the first year of supervised work to teach the judgement.

Choosing

CEH v13 vs other security certifications

Each of these is the right answer for a different person. None of them is a competitor to be talked down.

CEH v13 compared with Security+, eJPT, PenTest+ and OSCP
CertificationBuilt forDepthExamWhere it fits
CEH v13Breadth-first entrants and defendersWide coverage, guided labs125 MCQ, 4 hoursRecognised on Indian and Gulf job filters; the standard first security certificate.
CompTIA Security+Absolute beginners and compliance-adjacent rolesFoundational, vendor-neutral conceptsMultiple choice and performance-basedBroader security fundamentals with less offensive focus than CEH.
eJPTBeginners who want hands-on immediatelyPractical, entry-level penetration testingFully hands-onCheaper and more practical, with far less HR recognition in India.
CompTIA PenTest+Testers who want a vendor-neutral practical optionTesting lifecycle including scoping and reportingMultiple choice and performance-basedSits between CEH and OSCP in practical demand.
OSCPWorking or aspiring penetration testersDeep, unguided, exploitation-focused24-hour hands-on plus a reportThe credential hiring managers trust for pen-test roles; assumes CEH-level breadth already.
After the exam

Roles CEH v13 opens up

CEH is most often used as a screening credential for these roles. We do not publish salary figures or placement percentages we cannot substantiate.

SOC Analyst (L1/L2)

Triage and investigate alerts. CEH's attacker context is directly useful — you are looking at the other half of what you learned.

Cybersecurity Analyst

Vulnerability management, security reviews and control validation across an organisation's estate.

Vulnerability Assessment Analyst

Run and interpret assessments, prioritise findings and track remediation to closure.

Junior Penetration Tester

Execute scoped tests under supervision. CEH is a common entry filter; the hands-on depth comes after.

Security Engineer

Build and harden controls, using attack knowledge to decide what actually needs defending.

Security Consultant

Advise clients on risk and remediation — where the breadth CEH gives you pays off most.

FAQs

CEH v13 questions, answered

CEH v13 is version 13 of EC-Council's Certified Ethical Hacker certification. It covers 20 modules of offensive security technique — reconnaissance through cloud, IoT/OT and cryptography — taught with hands-on labs, and is positioned around using AI as an assistive tool inside an authorised testing workflow.
References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • 20,000+ professionals trained
  • India + UAE engagements

CEH v13 Training

EC-Council ATC · live online

Enquire