← Back to the catalogue

Level 2 · M.Sc

Whitehat Defensive Security

Syllabus · 42 phases · ~1 year

Every unit this programme teaches, in the order it is taught. Headlines only — the material itself opens once you are enrolled.

  1. Phase 0 Provisioning the sovereign host & the Bastion lab
  2. Phase 1 Terminal internals: TTYs, PTYs & session recording
  3. Phase 2 Fonts, keymaps & selections from the CLI
  4. Phase 3 Interactive-prompt handling & automation with expect
  5. Phase 4 fish I: interactive mastery
  6. Phase 5 fish II: scripting, functions & control flow
  7. Phase 6 POSIX sh & bash for portability
  8. Phase 7 The line editors: ed & ex
  9. Phase 8 sed & awk: the super-admin data language
  10. Phase 9 vim, deep
  11. Phase 10 emacs, deep
  12. Phase 11 tmux mastery
  13. Phase 12 The combined workflow: xmonad + tmux + emacs + fish
  14. Phase 13 Git as a content-addressed object store
  15. Phase 14 Branching, merging, reflog & history surgery
  16. Phase 15 Git for defense: signing, hooks & /etc tracking
  17. Phase 16 systemd I: units, lifecycle & journald
  18. Phase 17 systemd II: timers, sandboxing & service hardening
  19. Phase 18 The kernel runtime surface: sysctl, /proc & /sys
  20. Phase 19 dbus & the system message bus
  21. Phase 20 Processes, files & resources
  22. Phase 21 Networking observability
  23. Phase 22 Syscall & library tracing
  24. Phase 23 Performance & kernel tracing
  25. Phase 24 File formats, magic & headers
  26. Phase 25 ELF in depth
  27. Phase 26 Advanced hex editing & binary diffing
  28. Phase 27 Archives, compression & structured data
  29. Phase 28 Identity: users, groups & the permission model
  30. Phase 29 Extended attributes, ACLs, capabilities & immutability
  31. Phase 30 GPG & SSH: keys, certs & trust
  32. Phase 31 Mandatory access control: SELinux
  33. Phase 32 /etc mastery, config-drift & host integrity baselining
  34. Phase 33 Isolation & containers: namespaces → rootless podman
  35. Phase 34 Threat detection: NIDS, HIDS, eBPF monitoring & deception
  36. Phase 35 tty/session monitoring, USB/peripherals & network trust
  37. Phase 36 Kernel modules & rootkit detection (defensive)
  38. Phase 37 OpenBSD as a security appliance: pf, base & the router/firewall
  39. Phase 38 Hardening the server stack: nginx/haproxy/apache + sqlite
  40. Phase 39 Detecting an attacker with an account (the purple-team core)
  41. Phase 40 Toolchain literacy: compile, debug & inspect
  42. Phase 41 Capstone: defend the Bastion + hardening + portal

↑↓ to move · ↵ to open · esc to close Sign in to search programmes and course content.