SEC-120 · Kernel Security
Attack Surface Reduction
Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible.
Who this course is for
Embedded and product engineers shipping a kernel that must be minimal by construction — and able to prove it to an assessor.
Prerequisites
Course outline
Day 1 — Shrinking the kernel itself
- Config auditing: inventorying what your defconfig actually builds
- Removing drivers, filesystems and subsystems you never use — safely
- Module-loading policy: module.sig_enforce, modules_disabled and the load pin
- Lockdown-adjacent controls: hibernation, kexec, /dev/mem and /dev/kmem
- Measuring what you removed: image size, symbol counts and reachable syscall surface
Day 2 — Restricting what userspace can reach
- seccomp-bpf: writing filters, the TSYNC problem and library helpers
- Syscall reduction in practice: what real services and containers actually need
- Restricting /proc with hidepid, /sys permissions and debugfs discipline
- sysctl hardening: dmesg_restrict, kptr_restrict, perf_event_paranoid, unprivileged userns
- Documenting a minimal kernel: the evidence an assessor or regulator asks for
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: Audit a distro defconfig, cut it to a stated hardware profile and prove the system still boots and works
- Lab: Enforce module signatures, attempt to load an unsigned module and document the refusal
- Lab: Write a seccomp-bpf filter for a small service and verify blocked syscalls with strace and the audit log
- Lab: Apply a sysctl and permissions lockdown set, then measure the remaining exposure against a checklist
- Lab: Record the image-size and boot-time effect of your removal set as evidence for the security file
Capstone project
Take a stock kernel configuration down to a documented minimal build for a stated appliance: a removed-subsystem inventory with boot proof, module-loading policy, a seccomp profile for its main service, restricted pseudo-filesystems, and a one-page 'what we removed and why' document suitable for a product security file.
What you leave with
- A config-audit method that distinguishes used from merely present
- Working seccomp-bpf filter-writing skills
- Module-signature and load-restriction setup that survives review
- A minimal-kernel documentation template for regulated products
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Embedded and product engineers shipping a kernel that must be minimal by construction — and able to prove it to an assessor. It sits at advanced level within the Kernel Security track.
What do I need to know already?
Specific prerequisites for this course: Kernel configuration and build experience; Familiarity with modules, init systems and /proc//sys basics; SEC-110 helpful but not required. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 2 full days with hardware on your desk, capped at 14. Online is 4 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 25 Oct – 26 Oct 20262 full days | RiyadhIn person · KAFD Conference Centre | 12 of 14 | — | SAR 6,000 | |
| 1 Nov – 2 Nov 20262 full days | Kuwait CityIn person · Al Hamra Tower | 7 of 14 | — | KWD 500 | |
| 8 Nov – 9 Nov 20262 full days | MuscatIn person · Knowledge Oasis Muscat | 12 of 14 | OMR 560until 9 Oct | ||
| 8 Nov – 11 Nov 20264 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 6 of 20 | US$1,040until 9 Oct | ||
| 9 Nov – 10 Nov 20262 full days | OttawaIn person · Kanata North Tech Park | 7 of 14 | CAD 1,960until 10 Oct | ||
| 16 Nov – 17 Nov 20262 full days | TorontoIn person · MaRS Discovery District | 12 of 14 | CAD 1,960until 17 Oct | ||
| 16 Nov – 19 Nov 20264 half-days | Europe bandLive online · 09:00–13:00 CET | 11 of 20 | US$1,040until 17 Oct | ||
| 16 Nov – 19 Nov 20264 half-days | Americas bandLive online · 13:00–17:00 ET | 16 of 20 | US$1,040until 17 Oct | ||
| 23 Nov – 24 Nov 20262 full days | LondonIn person · Shoreditch Works | 7 of 14 | GBP 1,120until 24 Oct | ||
| 23 Nov – 24 Nov 20262 full days | BerlinIn person · Factory Görlitzer Park | 12 of 14 | EUR 1,320until 24 Oct |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Kernel Security
SEC-1012 days
Reading Kernel CVEs
Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe.
Practitioner-taught
SAR 5,250Next 11 Oct
SEC-1103 days
Exploit Mitigations & Hardening
The mitigations available in a modern kernel, what each actually stops, and what they cost.
Practitioner-taught
SAR 9,000Next 8 Nov
SEC-2013 days
Multi-Branch Backporting
Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team.
Practitioner-taught
SAR 9,000Next 1 Nov
SEC-2102 days
Stable, LTS & Vendor Tree Hygiene
Working with the upstream stable process and keeping a vendor tree that does not rot.
Practitioner-taught
SAR 5,250Next 18 Oct
SEC-2202 days
Building an Advisory Workflow
The process around the engineering: intake, assessment, communication and evidence, on a deadline.
Practitioner-taught
SAR 5,250Next 15 Nov
SEC-3013 days
LSM, SELinux & AppArmor
Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced.
Practitioner-taught
SAR 9,000Next 22 Nov
SEC-3102 days
Landlock & Kernel Lockdown
Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown.
Practitioner-taught
SAR 6,000Next 8 Nov
SEC-3203 days
Integrity: IMA/EVM & dm-verity
Measuring and verifying what runs on the system, from block device to individual file.
Practitioner-taught
SAR 9,000Next 18 Oct