SEC-301 · Kernel Security

LSM, SELinux & AppArmor

Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced.

Advanced 3 days in person6 half-days online Max 14 in person

Who this course is for

System and security engineers who must confine real services with mandatory access control — and debug the denials without reaching for permissive mode.

Prerequisites

Solid Linux administrationC reading ability for the LSM hook walk-throughA VM you can break (provided)

Course outline

Day 1 — The LSM framework

  • Why discretionary access control is not enough: confused deputies and ambient authority
  • The LSM hook architecture: where hooks live and what they can decide
  • Stacking and ordering: which LSM wins when several are loaded
  • Major vs minor LSMs; enabling and ordering at boot with lsm=
  • Security blobs: the inode, task and cred security fields

Day 2 — SELinux

  • Type enforcement: types, domains and the allow rule
  • Transitions: domain and file transitions, entrypoints and the exec path
  • Roles, users and MLS in one honest hour
  • Policy modules: building and loading your own with semodule
  • Debugging with audit.log, ausearch and audit2allow — and when audit2allow lies

Day 3 — AppArmor and confining a real service

  • AppArmor profiles: paths vs labels, and the trade-offs that follow
  • Profile modes: enforce, complain, kill, unconfined; aa-status and aa-genprof
  • File, capability, network and mount rules in practice
  • Choosing SELinux vs AppArmor for a product: maintenance, tooling and team skills
  • Confining a real service end to end: from strace-derived profile to enforced and tested

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: Inspect LSM hooks in the source and trace a permission decision with ftrace or bpftrace
  2. Lab: Boot a VM with different LSM stacking orders and document the behavioural difference
  3. Lab: Write and load an SELinux policy module for a custom daemon; fix the denials from audit logs
  4. Lab: Build an AppArmor profile for a network service, then attack it and close the gaps
  5. Lab: Take one service from unconfined to enforced with a denial-log trail proving each step

Capstone project

Confine a provided multi-process service end to end: choose SELinux or AppArmor with a written justification, develop the policy iteratively from audit logs, demonstrate that legitimate function survives and that two scripted attacks are now denied — and deliver the policy plus the denial-log evidence trail.

What you leave with

  • A working model of LSM hooks and stacking order
  • SELinux policy-module authoring and audit-log debugging skills
  • AppArmor profiling from strace and aa-genprof to enforcement
  • A defensible SELinux-vs-AppArmor selection method
  • An enforced confinement for a real service, with evidence

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

System and security engineers who must confine real services with mandatory access control — and debug the denials without reaching for permissive mode. It sits at advanced level within the Kernel Security track.

What do I need to know already?

Specific prerequisites for this course: Solid Linux administration; C reading ability for the LSM hook walk-through; A VM you can break (provided). We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
22 Nov – 24 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 3 of 14 SAR 8,100until 23 OctSAR 9,000
29 Nov – 1 Dec 20263 full days Kuwait CityIn person · Al Hamra Tower 8 of 14 KWD 670until 30 OctKWD 740
6 Dec – 8 Dec 20263 full days MuscatIn person · Knowledge Oasis Muscat 3 of 14 OMR 830until 6 NovOMR 920
6 Dec – 13 Dec 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 11 of 20 US$1,580until 6 NovUS$1,750
7 Dec – 9 Dec 20263 full days OttawaIn person · Kanata North Tech Park 8 of 14 CAD 2,930until 7 NovCAD 3,260
14 Dec – 16 Dec 20263 full days TorontoIn person · MaRS Discovery District 3 of 14 CAD 2,930until 14 NovCAD 3,260
14 Dec – 21 Dec 20266 half-days Europe bandLive online · 09:00–13:00 CET 16 of 20 US$1,580until 14 NovUS$1,750
14 Dec – 21 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 5 of 20 US$1,580until 14 NovUS$1,750
21 Dec – 23 Dec 20263 full days LondonIn person · Shoreditch Works 8 of 14 GBP 1,680until 21 NovGBP 1,870
21 Dec – 23 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 3 of 14 EUR 1,990until 21 NovEUR 2,210

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Kernel Security

SEC-1012 days Reading Kernel CVEs Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe. Practitioner Practitioner-taught SAR 5,250Next 11 Oct SEC-1103 days Exploit Mitigations & Hardening The mitigations available in a modern kernel, what each actually stops, and what they cost. Advanced Practitioner-taught SAR 9,000Next 8 Nov SEC-1202 days Attack Surface Reduction Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible. Advanced Practitioner-taught SAR 6,000Next 25 Oct SEC-2013 days Multi-Branch Backporting Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team. Advanced Practitioner-taught SAR 9,000Next 1 Nov SEC-2102 days Stable, LTS & Vendor Tree Hygiene Working with the upstream stable process and keeping a vendor tree that does not rot. Practitioner Practitioner-taught SAR 5,250Next 18 Oct SEC-2202 days Building an Advisory Workflow The process around the engineering: intake, assessment, communication and evidence, on a deadline. Practitioner Practitioner-taught SAR 5,250Next 15 Nov SEC-3102 days Landlock & Kernel Lockdown Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown. Advanced Practitioner-taught SAR 6,000Next 8 Nov SEC-3203 days Integrity: IMA/EVM & dm-verity Measuring and verifying what runs on the system, from block device to individual file. Advanced Practitioner-taught SAR 9,000Next 18 Oct