SEC-310 · Kernel Security · Advanced

Landlock & Kernel Lockdown — full syllabus

Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown.

Duration2 full days in person · 4 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 6,000 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Application and platform engineers who need sandboxing without root — and architects deciding how far root itself should be restricted on a shipped system.

Prerequisites

Course outline

Day 1 — Landlock

  • What Landlock is for: unprivileged, stackable sandboxing and how it differs from SELinux/AppArmor
  • Rulesets, rule types and the ABI versioning story
  • Filesystem rules: scoping read, write and execute to a directory tree
  • Network rules: bind and connect scoping and their limitations
  • Applying Landlock from an application: the open/inspect/restrict-self pattern
  • Composing Landlock with seccomp and namespaces; what each layer covers

Day 2 — Kernel lockdown

  • The threat model: root vs kernel, and why the distinction matters after secure boot
  • Lockdown modes: none, integrity and confidentiality — what each blocks
  • What integrity mode breaks: unsigned modules, /dev/mem, kexec, hibernation, some BPF
  • Confidentiality mode: additionally blocking anything that could read kernel memory
  • Planning a product around lockdown: what to fix in your stack before enabling it
  • Combining lockdown with module signatures, IMA and dm-verity for a coherent story

Hands-on labs

  1. Lab: Write a small C tool that sandboxes itself with a Landlock filesystem ruleset; probe the boundaries
  2. Lab: Add network bind/connect rules and demonstrate blocked and allowed traffic
  3. Lab: Compose Landlock with a seccomp filter and show what each layer catches that the other misses
  4. Lab: Boot a VM in lockdown=integrity, attempt a list of root operations and document each refusal
  5. Lab: Audit a product's userspace for lockdown-incompatible behaviours and produce a fix list

Capstone project

Harden a provided application two ways: self-applied Landlock sandboxing (filesystem plus network) verified by boundary probes, and a system-level plan for enabling lockdown=integrity on its host — including the audit of what breaks and the remediation order — delivered as code plus a written deployment plan.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
8 Nov – 9 Nov 20262 full days RiyadhIn person · KAFD Conference Centre 3 of 14 SAR 5,400until 9 OctSAR 6,000
8 Nov – 9 Nov 20262 full days Kuwait CityIn person · Al Hamra Tower 8 of 14 KWD 450until 9 OctKWD 500
15 Nov – 16 Nov 20262 full days MuscatIn person · Knowledge Oasis Muscat 3 of 14 OMR 560until 16 OctOMR 620
22 Nov – 25 Nov 20264 half-days Gulf bandLive online · 09:00–13:00 GMT+3 9 of 20 US$1,040until 23 OctUS$1,150
23 Nov – 24 Nov 20262 full days OttawaIn person · Kanata North Tech Park 8 of 14 CAD 1,960until 24 OctCAD 2,180
23 Nov – 24 Nov 20262 full days TorontoIn person · MaRS Discovery District 3 of 14 CAD 1,960until 24 OctCAD 2,180
23 Nov – 26 Nov 20264 half-days Europe bandLive online · 09:00–13:00 CET 14 of 20 US$1,040until 24 OctUS$1,150
30 Nov – 1 Dec 20262 full days LondonIn person · Shoreditch Works 8 of 14 GBP 1,120until 31 OctGBP 1,250
30 Nov – 3 Dec 20264 half-days Americas bandLive online · 13:00–17:00 ET 3 of 20 US$1,040until 31 OctUS$1,150
7 Dec – 8 Dec 20262 full days BerlinIn person · Factory Görlitzer Park 3 of 14 EUR 1,320until 7 NovEUR 1,470

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.