← Back to catalogue

Discipline herald — Security
Discipline herald

Level 2 · M.Sc

MSc Advanced Whitehat Defensive Security

Security · Live · v0

Doctoral defensive security — detection science, large-scale telemetry, and original blue-team research.

Path type
Security
Enrollment

€39.90

Deadline
Next cohort starts 2027-09-06 (AY 2027/28)
Length
~1 year · 42 phases
Language
English · Español
Content freshness
Curriculum updated 2026-08-23 · content rev d7bd4b17
Cortex Credits (CC)
126 CC · 421 CC across all tiers of this programme
What are Cortex Credits?
Syllabus
View the phase syllabus
  1. From admin to defensive-systems researcher
  2. The defender's threat model, applied
  3. Measurement discipline for defense
  4. Linux kernel architecture for defenders
  5. eBPF foundations for security observability
  6. Reading & reproducing defensive research
  7. The privilege-ring model for defenders
  8. CPU security flags as hardening primitives
  9. MSRs, model-specific registers & microcode trust
  10. Machine-code & opcode-level tamper detection
  11. ELF at defensive depth
  12. Ring-0 kernel rootkit detection
  13. Ring −1 / ring −2 stealth & detection
  14. Low-level defense capstone
  15. Process memory & the /proc forensic surface at depth
  16. Acquisition & analysis (DFIR toolchain)
  17. Live-response methodology
  18. Runtime tampering detection
  19. Persistence hunting at depth
  20. Anti-forensics & counter-anti-forensics
  21. Forensics capstone
  22. Log architecture & the SIEM (CLI side)
  23. Host telemetry at depth
  24. Network detection at research depth
  25. eBPF runtime detection & HIDS
  26. Detection-engineering methodology
  27. Threat-detection content, honestly
  28. Detection-engineering capstone
  29. SELinux internals & policy engineering at depth
  30. The LSM framework & comparative MAC
  31. seccomp-bpf & syscall filtering
  32. Namespaces, cgroups v2 & container internals at depth
  33. Sandboxing technologies compared
  34. Compiler & binary hardening
  35. Isolation capstone
  36. Firewall engines at research depth
  37. OpenBSD as a security research platform
  38. Network intrusion detection at depth: encrypted traffic and flow features
  39. The hardened edge: relayd, TLS termination & WAF
  40. DNS, PKI & trust-infrastructure defense
  41. Segmentation & zero-trust for the Bastion
  42. Traffic capture & analysis at depth
Enrolment prerequisites

What changed

Every release of this programme, newest first.

  1. v0 Pilot Wave A backfill: v0 pilot baseline

Professor: Vacancy available

Sign in to request enrolment

↑↓ to move · ↵ to open · esc to close Sign in to search programmes and course content.