SEC-110 · Kernel Security

Exploit Mitigations & Hardening

The mitigations available in a modern kernel, what each actually stops, and what they cost.

Advanced 3 days in person6 half-days online Max 14 in person

Who this course is for

Kernel and platform engineers choosing which exploit mitigations to enable on a shipping product — who need to know what each one stops, what bypasses exist and what it costs.

Prerequisites

Ability to configure, build and boot a kernel (QEMU is fine)C and enough assembly to follow an exploit write-upBasic x86-64 or arm64 architecture knowledge

Course outline

Day 1 — Execution-control mitigations

  • KASLR: what it randomises, what it does not, and information-leak bypasses
  • SMEP, SMAP and PAN: ret2usr and its modern descendants
  • KPTI: the Meltdown fix and its syscall and context-switch overhead
  • Stack protector and stackleak: strengths and gaps
  • Kernel CFI: forward-edge coverage, clang CFI and what FineIBT-style schemes add
  • Structure randomisation (randstruct) and its compatibility cost

Day 2 — Memory-safety and transient-execution mitigations

  • Hardened usercopy: what CONFIG_HARDENED_USERCOPY catches at copy time
  • Slab freelist hardening and pointer obfuscation; SLAB vs SLUB behaviour
  • init_on_alloc/init_on_free and the detection story: KASAN, KFENCE
  • Spectre/Meltdown class: retpolines, IBRS, mitigations= and measuring the overhead
  • Reading the kernel's own hardening documentation and Kconfig defaults critically

Day 3 — Choosing and defending a baseline

  • Cost accounting: boot time, latency and throughput per mitigation
  • Attack-surface removal vs mitigation: what you fix by deletion instead
  • Baseline profiles: general-purpose distro vs embedded product vs cloud host
  • kconfig-hardened-check style audits and gap analysis
  • Writing the hardening rationale document a security review will ask for

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: Enable and boot-test KASLR, KPTI and stack-protector variants; measure the overhead of each
  2. Lab: Demonstrate a hardened-usercopy violation with a deliberately bad copy_to_user and read the splat
  3. Lab: Corrupt a slab freelist in a test module with and without freelist hardening; compare the outcomes
  4. Lab: Benchmark a workload with mitigations=off against your proposed baseline and present the cost table
  5. Lab: Audit a supplied defconfig against a hardening checklist and produce a gap list with justifications

Capstone project

Produce a hardening baseline for a stated product profile (gateway, automotive head unit or cloud host): a defconfig fragment, a measured cost table from your own lab benchmarks, a bypass-aware statement of what each chosen mitigation does and does not stop, and a written rationale you can defend in a security review.

What you leave with

  • A mitigation-by-mitigation map: mechanism, bypass class, cost
  • Overhead evidence from your own measurements, not vendor slides
  • A defconfig fragment and rationale template reusable on products
  • Fluency reading Kconfig hardening options and upstream hardening docs

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Kernel and platform engineers choosing which exploit mitigations to enable on a shipping product — who need to know what each one stops, what bypasses exist and what it costs. It sits at advanced level within the Kernel Security track.

What do I need to know already?

Specific prerequisites for this course: Ability to configure, build and boot a kernel (QEMU is fine); C and enough assembly to follow an exploit write-up; Basic x86-64 or arm64 architecture knowledge. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
8 Nov – 10 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 11 of 14 SAR 8,100until 9 OctSAR 9,000
15 Nov – 17 Nov 20263 full days Kuwait CityIn person · Al Hamra Tower 6 of 14 KWD 670until 16 OctKWD 740
22 Nov – 24 Nov 20263 full days MuscatIn person · Knowledge Oasis Muscat 11 of 14 OMR 830until 23 OctOMR 920
22 Nov – 29 Nov 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 7 of 20 US$1,580until 23 OctUS$1,750
23 Nov – 25 Nov 20263 full days OttawaIn person · Kanata North Tech Park 6 of 14 CAD 2,930until 24 OctCAD 3,260
30 Nov – 2 Dec 20263 full days TorontoIn person · MaRS Discovery District 11 of 14 CAD 2,930until 31 OctCAD 3,260
30 Nov – 7 Dec 20266 half-days Europe bandLive online · 09:00–13:00 CET 12 of 20 US$1,580until 31 OctUS$1,750
7 Dec – 9 Dec 20263 full days LondonIn person · Shoreditch Works 6 of 14 GBP 1,680until 7 NovGBP 1,870
7 Dec – 14 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 17 of 20 US$1,580until 7 NovUS$1,750
14 Dec – 16 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 11 of 14 EUR 1,990until 14 NovEUR 2,210

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Kernel Security

SEC-1012 days Reading Kernel CVEs Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe. Practitioner Practitioner-taught SAR 5,250Next 11 Oct SEC-1202 days Attack Surface Reduction Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible. Advanced Practitioner-taught SAR 6,000Next 25 Oct SEC-2013 days Multi-Branch Backporting Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team. Advanced Practitioner-taught SAR 9,000Next 1 Nov SEC-2102 days Stable, LTS & Vendor Tree Hygiene Working with the upstream stable process and keeping a vendor tree that does not rot. Practitioner Practitioner-taught SAR 5,250Next 18 Oct SEC-2202 days Building an Advisory Workflow The process around the engineering: intake, assessment, communication and evidence, on a deadline. Practitioner Practitioner-taught SAR 5,250Next 15 Nov SEC-3013 days LSM, SELinux & AppArmor Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced. Advanced Practitioner-taught SAR 9,000Next 22 Nov SEC-3102 days Landlock & Kernel Lockdown Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown. Advanced Practitioner-taught SAR 6,000Next 8 Nov SEC-3203 days Integrity: IMA/EVM & dm-verity Measuring and verifying what runs on the system, from block device to individual file. Advanced Practitioner-taught SAR 9,000Next 18 Oct