SEC-120 · Kernel Security

Attack Surface Reduction

Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible.

Advanced 2 days in person4 half-days online Max 14 in person

Who this course is for

Embedded and product engineers shipping a kernel that must be minimal by construction — and able to prove it to an assessor.

Prerequisites

Kernel configuration and build experienceFamiliarity with modules, init systems and /proc//sys basicsSEC-110 helpful but not required

Course outline

Day 1 — Shrinking the kernel itself

  • Config auditing: inventorying what your defconfig actually builds
  • Removing drivers, filesystems and subsystems you never use — safely
  • Module-loading policy: module.sig_enforce, modules_disabled and the load pin
  • Lockdown-adjacent controls: hibernation, kexec, /dev/mem and /dev/kmem
  • Measuring what you removed: image size, symbol counts and reachable syscall surface

Day 2 — Restricting what userspace can reach

  • seccomp-bpf: writing filters, the TSYNC problem and library helpers
  • Syscall reduction in practice: what real services and containers actually need
  • Restricting /proc with hidepid, /sys permissions and debugfs discipline
  • sysctl hardening: dmesg_restrict, kptr_restrict, perf_event_paranoid, unprivileged userns
  • Documenting a minimal kernel: the evidence an assessor or regulator asks for

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: Audit a distro defconfig, cut it to a stated hardware profile and prove the system still boots and works
  2. Lab: Enforce module signatures, attempt to load an unsigned module and document the refusal
  3. Lab: Write a seccomp-bpf filter for a small service and verify blocked syscalls with strace and the audit log
  4. Lab: Apply a sysctl and permissions lockdown set, then measure the remaining exposure against a checklist
  5. Lab: Record the image-size and boot-time effect of your removal set as evidence for the security file

Capstone project

Take a stock kernel configuration down to a documented minimal build for a stated appliance: a removed-subsystem inventory with boot proof, module-loading policy, a seccomp profile for its main service, restricted pseudo-filesystems, and a one-page 'what we removed and why' document suitable for a product security file.

What you leave with

  • A config-audit method that distinguishes used from merely present
  • Working seccomp-bpf filter-writing skills
  • Module-signature and load-restriction setup that survives review
  • A minimal-kernel documentation template for regulated products

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Embedded and product engineers shipping a kernel that must be minimal by construction — and able to prove it to an assessor. It sits at advanced level within the Kernel Security track.

What do I need to know already?

Specific prerequisites for this course: Kernel configuration and build experience; Familiarity with modules, init systems and /proc//sys basics; SEC-110 helpful but not required. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 2 full days with hardware on your desk, capped at 14. Online is 4 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
25 Oct – 26 Oct 20262 full days RiyadhIn person · KAFD Conference Centre 12 of 14 —SAR 6,000
1 Nov – 2 Nov 20262 full days Kuwait CityIn person · Al Hamra Tower 7 of 14 —KWD 500
8 Nov – 9 Nov 20262 full days MuscatIn person · Knowledge Oasis Muscat 12 of 14 OMR 560until 9 OctOMR 620
8 Nov – 11 Nov 20264 half-days Gulf bandLive online · 09:00–13:00 GMT+3 6 of 20 US$1,040until 9 OctUS$1,150
9 Nov – 10 Nov 20262 full days OttawaIn person · Kanata North Tech Park 7 of 14 CAD 1,960until 10 OctCAD 2,180
16 Nov – 17 Nov 20262 full days TorontoIn person · MaRS Discovery District 12 of 14 CAD 1,960until 17 OctCAD 2,180
16 Nov – 19 Nov 20264 half-days Europe bandLive online · 09:00–13:00 CET 11 of 20 US$1,040until 17 OctUS$1,150
16 Nov – 19 Nov 20264 half-days Americas bandLive online · 13:00–17:00 ET 16 of 20 US$1,040until 17 OctUS$1,150
23 Nov – 24 Nov 20262 full days LondonIn person · Shoreditch Works 7 of 14 GBP 1,120until 24 OctGBP 1,250
23 Nov – 24 Nov 20262 full days BerlinIn person · Factory Görlitzer Park 12 of 14 EUR 1,320until 24 OctEUR 1,470

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Kernel Security

SEC-1012 days Reading Kernel CVEs Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe. Practitioner Practitioner-taught SAR 5,250Next 11 Oct SEC-1103 days Exploit Mitigations & Hardening The mitigations available in a modern kernel, what each actually stops, and what they cost. Advanced Practitioner-taught SAR 9,000Next 8 Nov SEC-2013 days Multi-Branch Backporting Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team. Advanced Practitioner-taught SAR 9,000Next 1 Nov SEC-2102 days Stable, LTS & Vendor Tree Hygiene Working with the upstream stable process and keeping a vendor tree that does not rot. Practitioner Practitioner-taught SAR 5,250Next 18 Oct SEC-2202 days Building an Advisory Workflow The process around the engineering: intake, assessment, communication and evidence, on a deadline. Practitioner Practitioner-taught SAR 5,250Next 15 Nov SEC-3013 days LSM, SELinux & AppArmor Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced. Advanced Practitioner-taught SAR 9,000Next 22 Nov SEC-3102 days Landlock & Kernel Lockdown Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown. Advanced Practitioner-taught SAR 6,000Next 8 Nov SEC-3203 days Integrity: IMA/EVM & dm-verity Measuring and verifying what runs on the system, from block device to individual file. Advanced Practitioner-taught SAR 9,000Next 18 Oct