Level 3 · Ph.D
Ph.D Advanced Whitehat Defensive Security
Security · Live · v0
Doctoral defensive security — detection science, large-scale telemetry, and original blue-team research.
- Path type
- Security
- Requirements
- MSc Advanced Whitehat Defensive Security
- Enrollment
-
€39.90
- Deadline
- Next cohort starts 2027-09-06 (AY 2027/28)
- Length
- +1 year · 56 phases
- Language
- English · Español
- Content freshness
- Curriculum updated 2026-08-23 · content rev d7bd4b17
- Cortex Credits (CC)
-
280 CC
· 421 CC across all tiers of this programme
What are Cortex Credits? - Syllabus
-
View the phase syllabus
- From admin to defensive-systems researcher
- The defender's threat model, applied
- Measurement discipline for defense
- Linux kernel architecture for defenders
- eBPF foundations for security observability
- Reading & reproducing defensive research
- The privilege-ring model for defenders
- CPU security flags as hardening primitives
- MSRs, model-specific registers & microcode trust
- Machine-code & opcode-level tamper detection
- ELF at defensive depth
- Ring-0 kernel rootkit detection
- Ring −1 / ring −2 stealth & detection
- Low-level defense capstone
- Process memory & the /proc forensic surface at depth
- Acquisition & analysis (DFIR toolchain)
- Live-response methodology
- Runtime tampering detection
- Persistence hunting at depth
- Anti-forensics & counter-anti-forensics
- Forensics capstone
- Log architecture & the SIEM (CLI side)
- Host telemetry at depth
- Network detection at research depth
- eBPF runtime detection & HIDS
- Detection-engineering methodology
- Threat-detection content, honestly
- Detection-engineering capstone
- SELinux internals & policy engineering at depth
- The LSM framework & comparative MAC
- seccomp-bpf & syscall filtering
- Namespaces, cgroups v2 & container internals at depth
- Sandboxing technologies compared
- Compiler & binary hardening
- Isolation capstone
- Firewall engines at research depth
- OpenBSD as a security research platform
- Network intrusion detection at depth: encrypted traffic and flow features
- The hardened edge: relayd, TLS termination & WAF
- DNS, PKI & trust-infrastructure defense
- Segmentation & zero-trust for the Bastion
- Traffic capture & analysis at depth
- Network-defense capstone: rampart as a research-grade monitored edge
- The purple-team model formalized
- Adversary emulation & detection validation
- Deception at depth: honeypots, canarytokens & tarpits
- Post-compromise detection research
- Supply-chain & package integrity
- Integrity at rest/in motion, resilience & hardware roots of trust
- Formal & systematic assurance
- Assurance capstone
- Research method
- Capstone I: the original contribution
- Capstone II: the verified publication
- Frontier & what's next
- Program close + portal integration
- Enrolment prerequisites
-
- A verified account and admissions-committee approval.
- Completion of MSc Advanced Whitehat Defensive Security.
What changed
Every release of this programme, newest first.
- v0 Pilot Wave A backfill: v0 pilot baseline
Professor: Vacancy available
Sign in to request enrolment