SEC-120 · Kernel Security · Advanced
Attack Surface Reduction — full syllabus
Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible.
Who this course is for
Embedded and product engineers shipping a kernel that must be minimal by construction — and able to prove it to an assessor.
Prerequisites
- Kernel configuration and build experience
- Familiarity with modules, init systems and /proc//sys basics
- SEC-110 helpful but not required
Course outline
Day 1 — Shrinking the kernel itself
- Config auditing: inventorying what your defconfig actually builds
- Removing drivers, filesystems and subsystems you never use — safely
- Module-loading policy: module.sig_enforce, modules_disabled and the load pin
- Lockdown-adjacent controls: hibernation, kexec, /dev/mem and /dev/kmem
- Measuring what you removed: image size, symbol counts and reachable syscall surface
Day 2 — Restricting what userspace can reach
- seccomp-bpf: writing filters, the TSYNC problem and library helpers
- Syscall reduction in practice: what real services and containers actually need
- Restricting /proc with hidepid, /sys permissions and debugfs discipline
- sysctl hardening: dmesg_restrict, kptr_restrict, perf_event_paranoid, unprivileged userns
- Documenting a minimal kernel: the evidence an assessor or regulator asks for
Hands-on labs
- Lab: Audit a distro defconfig, cut it to a stated hardware profile and prove the system still boots and works
- Lab: Enforce module signatures, attempt to load an unsigned module and document the refusal
- Lab: Write a seccomp-bpf filter for a small service and verify blocked syscalls with strace and the audit log
- Lab: Apply a sysctl and permissions lockdown set, then measure the remaining exposure against a checklist
- Lab: Record the image-size and boot-time effect of your removal set as evidence for the security file
Capstone project
Take a stock kernel configuration down to a documented minimal build for a stated appliance: a removed-subsystem inventory with boot proof, module-loading policy, a seccomp profile for its main service, restricted pseudo-filesystems, and a one-page 'what we removed and why' document suitable for a product security file.
What you leave with
- A config-audit method that distinguishes used from merely present
- Working seccomp-bpf filter-writing skills
- Module-signature and load-restriction setup that survives review
- A minimal-kernel documentation template for regulated products
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 25 Oct – 26 Oct 20262 full days | RiyadhIn person · KAFD Conference Centre | 12 of 14 | — | SAR 6,000 | |
| 1 Nov – 2 Nov 20262 full days | Kuwait CityIn person · Al Hamra Tower | 7 of 14 | — | KWD 500 | |
| 8 Nov – 9 Nov 20262 full days | MuscatIn person · Knowledge Oasis Muscat | 12 of 14 | OMR 560until 9 Oct | ||
| 8 Nov – 11 Nov 20264 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 6 of 20 | US$1,040until 9 Oct | ||
| 9 Nov – 10 Nov 20262 full days | OttawaIn person · Kanata North Tech Park | 7 of 14 | CAD 1,960until 10 Oct | ||
| 16 Nov – 17 Nov 20262 full days | TorontoIn person · MaRS Discovery District | 12 of 14 | CAD 1,960until 17 Oct | ||
| 16 Nov – 19 Nov 20264 half-days | Europe bandLive online · 09:00–13:00 CET | 11 of 20 | US$1,040until 17 Oct | ||
| 16 Nov – 19 Nov 20264 half-days | Americas bandLive online · 13:00–17:00 ET | 16 of 20 | US$1,040until 17 Oct | ||
| 23 Nov – 24 Nov 20262 full days | LondonIn person · Shoreditch Works | 7 of 14 | GBP 1,120until 24 Oct | ||
| 23 Nov – 24 Nov 20262 full days | BerlinIn person · Factory Görlitzer Park | 12 of 14 | EUR 1,320until 24 Oct |
Book a seat, or bring this course to your team
Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.
Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.