Level 2 · M.Sc
MSc Whitehat Defensive Security
Security · Live · v0
Defensive security operations — detection engineering, hardening, incident response, and blue-team practice.
- Path type
- Security
- Requirements
- Open entry
- Enrollment
-
€19.90
- Deadline
- Next cohort starts 2027-09-06 (AY 2027/28)
- Length
- ~1 year · 42 phases
- Language
- English · Español
- Content freshness
- Curriculum updated 2026-08-23 · content rev b9f72add
- Cortex Credits (CC)
-
126 CC
What are Cortex Credits? - Syllabus
-
View the phase syllabus
- Provisioning the sovereign host & the Bastion lab
- Terminal internals: TTYs, PTYs & session recording
- Fonts, keymaps & selections from the CLI
- Interactive-prompt handling & automation with expect
- fish I: interactive mastery
- fish II: scripting, functions & control flow
- POSIX sh & bash for portability
- The line editors: ed & ex
- sed & awk: the super-admin data language
- vim, deep
- emacs, deep
- tmux mastery
- The combined workflow: xmonad + tmux + emacs + fish
- Git as a content-addressed object store
- Branching, merging, reflog & history surgery
- Git for defense: signing, hooks & /etc tracking
- systemd I: units, lifecycle & journald
- systemd II: timers, sandboxing & service hardening
- The kernel runtime surface: sysctl, /proc & /sys
- dbus & the system message bus
- Processes, files & resources
- Networking observability
- Syscall & library tracing
- Performance & kernel tracing
- File formats, magic & headers
- ELF in depth
- Advanced hex editing & binary diffing
- Archives, compression & structured data
- Identity: users, groups & the permission model
- Extended attributes, ACLs, capabilities & immutability
- GPG & SSH: keys, certs & trust
- Mandatory access control: SELinux
- /etc mastery, config-drift & host integrity baselining
- Isolation & containers: namespaces → rootless podman
- Threat detection: NIDS, HIDS, eBPF monitoring & deception
- tty/session monitoring, USB/peripherals & network trust
- Kernel modules & rootkit detection (defensive)
- OpenBSD as a security appliance: pf, base & the router/firewall
- Hardening the server stack: nginx/haproxy/apache + sqlite
- Detecting an attacker with an account (the purple-team core)
- Toolchain literacy: compile, debug & inspect
- Capstone: defend the Bastion + hardening + portal
- Enrolment prerequisites
-
- A verified account and admissions-committee approval.
What changed
Every release of this programme, newest first.
- v0 Pilot Wave A backfill: v0 pilot baseline
Professor: Vacancy available
Sign in to request enrolment