SEC-120 · Kernel Security · Advanced

Attack Surface Reduction — full syllabus

Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible.

Duration2 full days in person · 4 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 6,000 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Embedded and product engineers shipping a kernel that must be minimal by construction — and able to prove it to an assessor.

Prerequisites

Course outline

Day 1 — Shrinking the kernel itself

  • Config auditing: inventorying what your defconfig actually builds
  • Removing drivers, filesystems and subsystems you never use — safely
  • Module-loading policy: module.sig_enforce, modules_disabled and the load pin
  • Lockdown-adjacent controls: hibernation, kexec, /dev/mem and /dev/kmem
  • Measuring what you removed: image size, symbol counts and reachable syscall surface

Day 2 — Restricting what userspace can reach

  • seccomp-bpf: writing filters, the TSYNC problem and library helpers
  • Syscall reduction in practice: what real services and containers actually need
  • Restricting /proc with hidepid, /sys permissions and debugfs discipline
  • sysctl hardening: dmesg_restrict, kptr_restrict, perf_event_paranoid, unprivileged userns
  • Documenting a minimal kernel: the evidence an assessor or regulator asks for

Hands-on labs

  1. Lab: Audit a distro defconfig, cut it to a stated hardware profile and prove the system still boots and works
  2. Lab: Enforce module signatures, attempt to load an unsigned module and document the refusal
  3. Lab: Write a seccomp-bpf filter for a small service and verify blocked syscalls with strace and the audit log
  4. Lab: Apply a sysctl and permissions lockdown set, then measure the remaining exposure against a checklist
  5. Lab: Record the image-size and boot-time effect of your removal set as evidence for the security file

Capstone project

Take a stock kernel configuration down to a documented minimal build for a stated appliance: a removed-subsystem inventory with boot proof, module-loading policy, a seccomp profile for its main service, restricted pseudo-filesystems, and a one-page 'what we removed and why' document suitable for a product security file.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
25 Oct – 26 Oct 20262 full days RiyadhIn person · KAFD Conference Centre 12 of 14 —SAR 6,000
1 Nov – 2 Nov 20262 full days Kuwait CityIn person · Al Hamra Tower 7 of 14 —KWD 500
8 Nov – 9 Nov 20262 full days MuscatIn person · Knowledge Oasis Muscat 12 of 14 OMR 560until 9 OctOMR 620
8 Nov – 11 Nov 20264 half-days Gulf bandLive online · 09:00–13:00 GMT+3 6 of 20 US$1,040until 9 OctUS$1,150
9 Nov – 10 Nov 20262 full days OttawaIn person · Kanata North Tech Park 7 of 14 CAD 1,960until 10 OctCAD 2,180
16 Nov – 17 Nov 20262 full days TorontoIn person · MaRS Discovery District 12 of 14 CAD 1,960until 17 OctCAD 2,180
16 Nov – 19 Nov 20264 half-days Europe bandLive online · 09:00–13:00 CET 11 of 20 US$1,040until 17 OctUS$1,150
16 Nov – 19 Nov 20264 half-days Americas bandLive online · 13:00–17:00 ET 16 of 20 US$1,040until 17 OctUS$1,150
23 Nov – 24 Nov 20262 full days LondonIn person · Shoreditch Works 7 of 14 GBP 1,120until 24 OctGBP 1,250
23 Nov – 24 Nov 20262 full days BerlinIn person · Factory Görlitzer Park 12 of 14 EUR 1,320until 24 OctEUR 1,470

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.