← Back to catalogue

Discipline herald — Security
Discipline herald

Level 2 · M.Sc

MSc Whitehat Defensive Security

Security · Live · v0

Defensive security operations — detection engineering, hardening, incident response, and blue-team practice.

Path type
Security
Requirements
Open entry
Enrollment

€19.90

Deadline
Next cohort starts 2027-09-06 (AY 2027/28)
Length
~1 year · 42 phases
Language
English · Español
Content freshness
Curriculum updated 2026-08-23 · content rev b9f72add
Cortex Credits (CC)
126 CC
What are Cortex Credits?
Syllabus
View the phase syllabus
  1. Provisioning the sovereign host & the Bastion lab
  2. Terminal internals: TTYs, PTYs & session recording
  3. Fonts, keymaps & selections from the CLI
  4. Interactive-prompt handling & automation with expect
  5. fish I: interactive mastery
  6. fish II: scripting, functions & control flow
  7. POSIX sh & bash for portability
  8. The line editors: ed & ex
  9. sed & awk: the super-admin data language
  10. vim, deep
  11. emacs, deep
  12. tmux mastery
  13. The combined workflow: xmonad + tmux + emacs + fish
  14. Git as a content-addressed object store
  15. Branching, merging, reflog & history surgery
  16. Git for defense: signing, hooks & /etc tracking
  17. systemd I: units, lifecycle & journald
  18. systemd II: timers, sandboxing & service hardening
  19. The kernel runtime surface: sysctl, /proc & /sys
  20. dbus & the system message bus
  21. Processes, files & resources
  22. Networking observability
  23. Syscall & library tracing
  24. Performance & kernel tracing
  25. File formats, magic & headers
  26. ELF in depth
  27. Advanced hex editing & binary diffing
  28. Archives, compression & structured data
  29. Identity: users, groups & the permission model
  30. Extended attributes, ACLs, capabilities & immutability
  31. GPG & SSH: keys, certs & trust
  32. Mandatory access control: SELinux
  33. /etc mastery, config-drift & host integrity baselining
  34. Isolation & containers: namespaces → rootless podman
  35. Threat detection: NIDS, HIDS, eBPF monitoring & deception
  36. tty/session monitoring, USB/peripherals & network trust
  37. Kernel modules & rootkit detection (defensive)
  38. OpenBSD as a security appliance: pf, base & the router/firewall
  39. Hardening the server stack: nginx/haproxy/apache + sqlite
  40. Detecting an attacker with an account (the purple-team core)
  41. Toolchain literacy: compile, debug & inspect
  42. Capstone: defend the Bastion + hardening + portal
Enrolment prerequisites
  • A verified account and admissions-committee approval.

What changed

Every release of this programme, newest first.

  1. v0 Pilot Wave A backfill: v0 pilot baseline

Professor: Vacancy available

Sign in to request enrolment

↑↓ to move · ↵ to open · esc to close Sign in to search programmes and course content.