Sending Logs, Alerts, and Telemetry Through a Data Diode

Find Out How
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

OPSWAT’s Critical Infrastructure Cybersecurity Graduate Fellowship Program

This immersive and hands-on program provides a unique opportunity for graduate students to study and mitigate real-world cybersecurity vulnerabilities affecting critical infrastructure systems.

Program Overview

As a participant, you will:

Identify and replicate known vulnerabilities in a controlled lab environment, leveraging OPSWAT Critical Infrastructure Lab resources.

Develop and test exploits related to these vulnerabilities, gaining insight into hacker tactics and methods.

Produce comprehensive written reports and visual content (video and images) detailing the vulnerabilities, the reasons behind their occurrence, and their potential impact on critical infrastructure.

Scan identified malware and vulnerabilities using OPSWAT's suite of tools, such as Metascan™, Deep CDR™ Technology, Proactive DLP™, MetaDefender Aether™, MetaDefender OT Security™, and Vulnerability Scanners, and document your findings.

Create a defense strategy that outlines protective measures against identified vulnerabilities and similar future threats, backed by your hands-on experience and testing results.

Program Structure

The program consists of 6 modules as below:

Vulnerability Identification and Replication

  • Start with a known vulnerability (to be provided during the program).
  • Replicate the vulnerability in the OPSWAT Critical Infrastructure Lab.

Exploit Development

  • Develop an exploit for the identified vulnerability.
  • Test and refine the exploit.

Analysis and Documentation

  • Investigate and document the reasons the vulnerability occurred and its potential effects on critical infrastructure.
  • Capture your process and findings through video/images, and written reports.

Scanning and Identification

  • Use OPSWAT's Metascan, MetaDefender Aether, MetaDefender OT Security, and Vulnerability Scanners to scan and identify the malware and vulnerabilities.
  • Document your scanning results and analysis.

Defense Strategy

  • Based on your findings, formulate a strategy to defend against the identified vulnerabilities and similar future threats.
  • Write a detailed report and create visual content (diagrams, flowcharts, etc.) to illustrate the defense strategy.

Final Presentation

  • Compile all your findings, reports, and strategies into a comprehensive document and presentation.
  • Present your work to a panel of cybersecurity experts from OPSWAT for feedback and further learning.
  • Create a video and online material to be published on OPSWAT’s and your university’s website.
  • Module 1

    Vulnerability Identification and Replication

    • Start with a known vulnerability (to be provided during the program).
    • Replicate the vulnerability in the OPSWAT Critical Infrastructure Lab.
  • Module 2

    Exploit Development

    • Develop an exploit for the identified vulnerability.
    • Test and refine the exploit.
  • Module 3

    Analysis and Documentation

    • Investigate and document the reasons the vulnerability occurred and its potential effects on critical infrastructure.
    • Capture your process and findings through video/images, and written reports.
  • Module 4

    Scanning and Identification

    • Use OPSWAT's Metascan, MetaDefender Aether, MetaDefender OT Security, and Vulnerability Scanners to scan and identify the malware and vulnerabilities.
    • Document your scanning results and analysis.
  • Module 5

    Defense Strategy

    • Based on your findings, formulate a strategy to defend against the identified vulnerabilities and similar future threats.
    • Write a detailed report and create visual content (diagrams, flowcharts, etc.) to illustrate the defense strategy.
  • Module 6

    Final Presentation

    • Compile all your findings, reports, and strategies into a comprehensive document and presentation.
    • Present your work to a panel of cybersecurity experts from OPSWAT for feedback and further learning.
    • Create a video and online material to be published on OPSWAT’s and your university’s website.

What We Offer You

By the end of this program, you will gain an in-depth understanding of vulnerability analysis, exploit development, and cybersecurity defense strategies within the context of critical infrastructure. This hands-on experience will be invaluable in helping you build and develop your future career in Cybersecurity. You can include this practical exercise in future Master’s and Doctoral Research projects.

CIP Labs Experience

You will have the opportunity to explore and work on OPSWAT’s Critical Infrastructure Labs.

Career Opportunities

Opportunities to become Intern/FTE of OPSWAT after the program.

Compensations & Awards

Monthly allowance (for 3 day working week): gross VND 6,000,000. Award for individual/team with excellence performance.

Friendly Work Environment

Parking at the office building. Enjoy full office facilities, with breakfast & afternoon snacks, as well as other social activities.

What We Need From You

  • Final year student or fresh graduate, major in Cybersecurity, IT or Computer Science with a special interest in Cybersecurity.
  • Good English communication
  • Quantity: 4-6 members/SWAT.
  • Ability to work in the office at least 3 days/week (Mon-Wed-Fri) for a period of 6 weeks in a row.
SWAT 1 Mar 16, 2026 – May 29, 2026
SWAT 2 Jun 22, 2026 – Aug 28, 2026
SWAT 3 Sep 21, 2026 – Nov 27, 2026

Work Location

OPSWAT Vietnam Office

Sai Gon Giai Phong Building, 436-438 Nguyen Thi Minh Khai, Ban Co Ward, Ho Chi Minh City

Sign Up

Showcase

Explore the exceptional projects created by the talented students involved in this program below. This collection is regularly updated to showcase the latest research developments as the program advances.

Latest Works

  • Comprehensive Analysis of CVE-2024-6778: Race Condition Vulnerability in Chrome DevTools

    Our extensive analysis of CVE-2024-6778, a vulnerability in Chromium-based browsers, particularly affecting Chrome DevTools. Learn more about the potential impact and mitigation strategies.

    Meet 2025 - SWAT 1 - Team 1
    Luong Ho Trong Nghia
    HCMC University of Information Technology, Vietnam
    Nguyen Minh Tri
    HCMC University of Science, Vietnam
    HOW OPSWAT HELPS PROTECT
    MetaDefender Endpoint
  • IngressNightmare: CVE-2025-1974 Remote Code Execution Vulnerability & Remediation

    May 2025 marked the public disclosure of a critical security vulnerability, CVE-2025-1974, dubbed IngressNightmare, affecting the Kubernetes ingress-nginx controller widely deployed across cloud native infrastructures.

    Meet 2025 - SWAT 1 - Team 2
    Tran Phuoc An
    Academy of Cryptography Techniques, Vietnam
    Lam Nguyen Quang Tue
    HCMC University of Technology, Vietnam
    HOW OPSWAT HELPS PROTECT
    MetaDefender Core
  • Comprehensive Breakdown of CVE-2024-38063: A Critical Threat in the Windows TCP/IP Stack

    On Aug 13, 2024, MSTC (Microsoft Security Response Center) disclosed CVE-2024-38063, a critical vulnerability in the Windows that can compromise vital networking functions. Join OPSWAT fellows in examining the vulnerability details, potential impact, and recommended mitigation strategies.

    Meet 2024 - SWAT 4 - Team 2
    Pham Ngoc Thien
    HCMC University of Information Technology, Vietnam
    HOW OPSWAT HELPS PROTECT
    MetaDefender Endpoint

Browse All

2025 - SWAT 1 - Team 1
Luong Ho Trong Nghia & Nguyen Minh Tri
Comprehensive Analysis of CVE-2024-6778: Race Condition Vulnerability in Chrome DevTools
2025 - SWAT 1 - Team 2
Tran Phuoc An & Lam Nguyen Quang Tue
IngressNightmare: CVE-2025-1974 Remote Code Execution Vulnerability & Remediation
2024 - SWAT 4 - Team 2
Pham Ngoc Thien
Comprehensive Breakdown of CVE-2024-38063: A Critical Threat in the Windows TCP/IP Stack
2024 - SWAT 4 - Team 1
Ho Viet Bao Long & Phung Sieu Dat
CVE-2024-36401 in Open-Source GeoServer Exposes Systems to Remote Code Execution
2024 - SWAT 3 - Team 1
Nguyen Phu Hung & Tran Anh Huy
Safeguarding Against Deserialization Attacks in Spring for Apache Kafka 
2024 - SWAT 3 - Team 2
Pham Quang Minh & Do Nhat Thai
Analyzing and Remediating Git Vulnerability CVE-2024-32002 
2024 - SWAT 2 - Team 2
Dang Duong Minh Nhat & Tran Huynh Trang
Protecting OT Systems from Remote Attacks: How MetaDefender OT Security™ Protects the Micrologix™ 1400 Controller from CVE-2021-22659
2024 - SWAT 2 - Team 1
Do Hoai Nam & Le Minh Quan
Remediating the CVE-2024-0517 Vulnerability in Google Chrome  
2024 - SWAT 1 - Team 2
Bui Duc Hoang & Tran Quang Tien
Analyzing the CVE-2023-33733 Vulnerability with MetaDefender Core
2024 - SWAT 1 - Team 1
Tran Tan Tai & Bui Tan Hai Dang
Revealing and Remediating a Dompdf Library Vulnerability with OPSWAT MetaDefender Core
2023 - SWAT 1 - Team 3
Luong Thien Tri & Ta Quang Khoi
Remediate Google Chrome CVE-2019-13720 Vulnerability with OPSWAT
2023 - SWAT 1 - Team 1
Doan Trong Khang & Pham Van Hien
Decoding the WinRAR CVE-2023-38831 Vulnerability with OPSWAT 
2023 - SWAT 1 - Team 2
Tran Hai Dang & Vo Van Khanh
Strengthening OT Security Against CVE-2018-17924 with OPSWAT
2023 - SWAT 2 - Team 1
Pham Kha Luan & Tran Lac Viet
Safeguarding Against OT Attacks on Rockwell Automation PLCs
2023 - SWAT 2 - Team 2
To Duy Thai & Tran Tan Tai
How to Recognize and Remediate this Common Foxit PDF Reader Vulnerability
CYBERSECURITY ATTACKS ARE ON THE RISE

Join the OPSWAT’s Critical Infrastructure Cybersecurity Graduate Fellowship Program