← Back to catalogue

Discipline herald — Security
Discipline herald

Level 3 · Ph.D

Ph.D Advanced Offensive Security & Adversary Research

Security · Live · v0

Doctoral adversary research, CTF-style and detection-first — exploitation science and countermeasure design.

Path type
Security
Enrollment

€39.90

Deadline
Next cohort starts 2027-09-06 (AY 2027/28)
Length
+1 year · 56 phases
Language
English · Español
Content freshness
Curriculum updated 2026-08-24 · content rev 8d5ac490
Cortex Credits (CC)
280 CC · 421 CC across all tiers of this programme
What are Cortex Credits?
Syllabus
View the phase syllabus
  1. From operator to adversary researcher
  2. Adversary emulation & threat-informed defense
  3. The detection-evasion arms race framed formally
  4. Measurement discipline for offense
  5. Telemetry from the attacker's side
  6. Reproducible offensive research
  7. Reading the offensive-security literature
  8. Scan-detection modeling & evasive scanning
  9. Firewall & IDS evasion research
  10. Traffic-analysis resistance
  11. Protocol-level enumeration at depth
  12. Living-off-the-land reconnaissance
  13. Recon-research capstone
  14. Web & service exploitation at research depth
  15. Fuzzing & symbolic execution for discovery
  16. Credential-attack research
  17. Automated exploitation frameworks dissected
  18. Payload & delivery research
  19. Access-research capstone
  20. Machine-code & instruction-level analysis
  21. Privilege rings in practice: ring 3 ↔ ring 0
  22. CPU modes & mode-transition abuse
  23. Extended CPU flags & mitigation bypass
  24. Ring -1: hypervisor & virtualization internals from the attacker's seat
  25. Virtualization bypass / VM-escape concepts
  26. Anti-VM, hypervisor-detection & sandbox evasion
  27. Low-level capstone — ring -2 & the trust boundary
  28. Userland rootkit research
  29. Kernel-level hiding & eBPF for offense
  30. Persistence design space
  31. Anti-forensics research
  32. Capture & credential-harvesting internals
  33. Covert channels & exfil research
  34. Post-ex research capstone
  35. Detection engineering from the adversary's seat
  36. NSM evasion research
  37. Host-telemetry evasion
  38. Timing & operational-security modeling
  39. Adversarial ML for detection evasion
  40. The evasion–detection frontier
  41. Co-evolution capstone
  42. Threat-actor emulation methodology
  43. Full-chain campaign automation
  44. C2 framework research
  45. Purple-team exercise design
  46. Detection-gap discovery
  47. Breach-and-attack-simulation concepts
  48. Verification & adversarial rigor
  49. Emulation-research capstone
  50. Research method
  51. Tooling-provenance & citation hygiene
  52. Cross-checking against the defender
  53. Capstone I — the original contribution
  54. Capstone II — the verified publication
  55. Frontier & what's next
  56. Post-doctoral on-ramp & close
Enrolment prerequisites

What changed

Every release of this programme, newest first.

  1. v0 Pilot Wave A backfill: v0 pilot baseline

Professor: Vacancy available

Sign in to request enrolment

↑↓ to move · ↵ to open · esc to close Sign in to search programmes and course content.