SEC-301 · Kernel Security · Advanced

LSM, SELinux & AppArmor — full syllabus

Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced.

Duration3 full days in person · 6 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 9,000 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

System and security engineers who must confine real services with mandatory access control — and debug the denials without reaching for permissive mode.

Prerequisites

Course outline

Day 1 — The LSM framework

  • Why discretionary access control is not enough: confused deputies and ambient authority
  • The LSM hook architecture: where hooks live and what they can decide
  • Stacking and ordering: which LSM wins when several are loaded
  • Major vs minor LSMs; enabling and ordering at boot with lsm=
  • Security blobs: the inode, task and cred security fields

Day 2 — SELinux

  • Type enforcement: types, domains and the allow rule
  • Transitions: domain and file transitions, entrypoints and the exec path
  • Roles, users and MLS in one honest hour
  • Policy modules: building and loading your own with semodule
  • Debugging with audit.log, ausearch and audit2allow — and when audit2allow lies

Day 3 — AppArmor and confining a real service

  • AppArmor profiles: paths vs labels, and the trade-offs that follow
  • Profile modes: enforce, complain, kill, unconfined; aa-status and aa-genprof
  • File, capability, network and mount rules in practice
  • Choosing SELinux vs AppArmor for a product: maintenance, tooling and team skills
  • Confining a real service end to end: from strace-derived profile to enforced and tested

Hands-on labs

  1. Lab: Inspect LSM hooks in the source and trace a permission decision with ftrace or bpftrace
  2. Lab: Boot a VM with different LSM stacking orders and document the behavioural difference
  3. Lab: Write and load an SELinux policy module for a custom daemon; fix the denials from audit logs
  4. Lab: Build an AppArmor profile for a network service, then attack it and close the gaps
  5. Lab: Take one service from unconfined to enforced with a denial-log trail proving each step

Capstone project

Confine a provided multi-process service end to end: choose SELinux or AppArmor with a written justification, develop the policy iteratively from audit logs, demonstrate that legitimate function survives and that two scripted attacks are now denied — and deliver the policy plus the denial-log evidence trail.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
22 Nov – 24 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 3 of 14 SAR 8,100until 23 OctSAR 9,000
29 Nov – 1 Dec 20263 full days Kuwait CityIn person · Al Hamra Tower 8 of 14 KWD 670until 30 OctKWD 740
6 Dec – 8 Dec 20263 full days MuscatIn person · Knowledge Oasis Muscat 3 of 14 OMR 830until 6 NovOMR 920
6 Dec – 13 Dec 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 11 of 20 US$1,580until 6 NovUS$1,750
7 Dec – 9 Dec 20263 full days OttawaIn person · Kanata North Tech Park 8 of 14 CAD 2,930until 7 NovCAD 3,260
14 Dec – 16 Dec 20263 full days TorontoIn person · MaRS Discovery District 3 of 14 CAD 2,930until 14 NovCAD 3,260
14 Dec – 21 Dec 20266 half-days Europe bandLive online · 09:00–13:00 CET 16 of 20 US$1,580until 14 NovUS$1,750
14 Dec – 21 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 5 of 20 US$1,580until 14 NovUS$1,750
21 Dec – 23 Dec 20263 full days LondonIn person · Shoreditch Works 8 of 14 GBP 1,680until 21 NovGBP 1,870
21 Dec – 23 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 3 of 14 EUR 1,990until 21 NovEUR 2,210

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.