Level 3 · Ph.D
Advanced Whitehat Defensive Security
Ph.D syllabus · 56 phases · +1 year
Every unit this programme teaches, in the order it is taught. Headlines only — the material itself opens once you are enrolled.
- Phase 0 From admin to defensive-systems researcher
- Phase 1 The defender's threat model, applied
- Phase 2 Measurement discipline for defense
- Phase 3 Linux kernel architecture for defenders
- Phase 4 eBPF foundations for security observability
- Phase 5 Reading & reproducing defensive research
- Phase 6 The privilege-ring model for defenders
- Phase 7 CPU security flags as hardening primitives
- Phase 8 MSRs, model-specific registers & microcode trust
- Phase 9 Machine-code & opcode-level tamper detection
- Phase 10 ELF at defensive depth
- Phase 11 Ring-0 kernel rootkit detection
- Phase 12 Ring −1 / ring −2 stealth & detection
- Phase 13 Low-level defense capstone
-
Phase 14
Process memory & the
/procforensic surface at depth - Phase 15 Acquisition & analysis (DFIR toolchain)
- Phase 16 Live-response methodology
- Phase 17 Runtime tampering detection
- Phase 18 Persistence hunting at depth
- Phase 19 Anti-forensics & counter-anti-forensics
- Phase 20 Forensics capstone
- Phase 21 Log architecture & the SIEM (CLI side)
- Phase 22 Host telemetry at depth
- Phase 23 Network detection at research depth
- Phase 24 eBPF runtime detection & HIDS
- Phase 25 Detection-engineering methodology
- Phase 26 Threat-detection content, honestly
- Phase 27 Detection-engineering capstone
- Phase 28 SELinux internals & policy engineering at depth
- Phase 29 The LSM framework & comparative MAC
- Phase 30 seccomp-bpf & syscall filtering
- Phase 31 Namespaces, cgroups v2 & container internals at depth
- Phase 32 Sandboxing technologies compared
- Phase 33 Compiler & binary hardening
- Phase 34 Isolation capstone
- Phase 35 Firewall engines at research depth
- Phase 36 OpenBSD as a security research platform
- Phase 37 Network intrusion detection at depth: encrypted traffic and flow features
- Phase 38 The hardened edge: relayd, TLS termination & WAF
- Phase 39 DNS, PKI & trust-infrastructure defense
- Phase 40 Segmentation & zero-trust for the Bastion
- Phase 41 Traffic capture & analysis at depth
- Phase 42 Network-defense capstone: rampart as a research-grade monitored edge
- Phase 43 The purple-team model formalized
- Phase 44 Adversary emulation & detection validation
- Phase 45 Deception at depth: honeypots, canarytokens & tarpits
- Phase 46 Post-compromise detection research
- Phase 47 Supply-chain & package integrity
- Phase 48 Integrity at rest/in motion, resilience & hardware roots of trust
- Phase 49 Formal & systematic assurance
- Phase 50 Assurance capstone
- Phase 51 Research method
- Phase 52 Capstone I: the original contribution
- Phase 53 Capstone II: the verified publication
- Phase 54 Frontier & what's next
- Phase 55 Program close + portal integration