← Back to the catalogue

Level 2 · M.Sc

Advanced Whitehat Defensive Security

MSc syllabus · 42 phases · ~1 year

Every unit this programme teaches, in the order it is taught. Headlines only — the material itself opens once you are enrolled.

  1. Phase 0 From admin to defensive-systems researcher
  2. Phase 1 The defender's threat model, applied
  3. Phase 2 Measurement discipline for defense
  4. Phase 3 Linux kernel architecture for defenders
  5. Phase 4 eBPF foundations for security observability
  6. Phase 5 Reading & reproducing defensive research
  7. Phase 6 The privilege-ring model for defenders
  8. Phase 7 CPU security flags as hardening primitives
  9. Phase 8 MSRs, model-specific registers & microcode trust
  10. Phase 9 Machine-code & opcode-level tamper detection
  11. Phase 10 ELF at defensive depth
  12. Phase 11 Ring-0 kernel rootkit detection
  13. Phase 12 Ring −1 / ring −2 stealth & detection
  14. Phase 13 Low-level defense capstone
  15. Phase 14 Process memory & the /proc forensic surface at depth
  16. Phase 15 Acquisition & analysis (DFIR toolchain)
  17. Phase 16 Live-response methodology
  18. Phase 17 Runtime tampering detection
  19. Phase 18 Persistence hunting at depth
  20. Phase 19 Anti-forensics & counter-anti-forensics
  21. Phase 20 Forensics capstone
  22. Phase 21 Log architecture & the SIEM (CLI side)
  23. Phase 22 Host telemetry at depth
  24. Phase 23 Network detection at research depth
  25. Phase 24 eBPF runtime detection & HIDS
  26. Phase 25 Detection-engineering methodology
  27. Phase 26 Threat-detection content, honestly
  28. Phase 27 Detection-engineering capstone
  29. Phase 28 SELinux internals & policy engineering at depth
  30. Phase 29 The LSM framework & comparative MAC
  31. Phase 30 seccomp-bpf & syscall filtering
  32. Phase 31 Namespaces, cgroups v2 & container internals at depth
  33. Phase 32 Sandboxing technologies compared
  34. Phase 33 Compiler & binary hardening
  35. Phase 34 Isolation capstone
  36. Phase 35 Firewall engines at research depth
  37. Phase 36 OpenBSD as a security research platform
  38. Phase 37 Network intrusion detection at depth: encrypted traffic and flow features
  39. Phase 38 The hardened edge: relayd, TLS termination & WAF
  40. Phase 39 DNS, PKI & trust-infrastructure defense
  41. Phase 40 Segmentation & zero-trust for the Bastion
  42. Phase 41 Traffic capture & analysis at depth

↑↓ to move · ↵ to open · esc to close Sign in to search programmes and course content.