SEC-310 · Kernel Security

Landlock & Kernel Lockdown

Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown.

Advanced 2 days in person4 half-days online Max 14 in person

Who this course is for

Application and platform engineers who need sandboxing without root — and architects deciding how far root itself should be restricted on a shipped system.

Prerequisites

C programming against Linux APIsNamespaces, capabilities and seccomp basicsA recent kernel for the labs (provided VM)

Course outline

Day 1 — Landlock

  • What Landlock is for: unprivileged, stackable sandboxing and how it differs from SELinux/AppArmor
  • Rulesets, rule types and the ABI versioning story
  • Filesystem rules: scoping read, write and execute to a directory tree
  • Network rules: bind and connect scoping and their limitations
  • Applying Landlock from an application: the open/inspect/restrict-self pattern
  • Composing Landlock with seccomp and namespaces; what each layer covers

Day 2 — Kernel lockdown

  • The threat model: root vs kernel, and why the distinction matters after secure boot
  • Lockdown modes: none, integrity and confidentiality — what each blocks
  • What integrity mode breaks: unsigned modules, /dev/mem, kexec, hibernation, some BPF
  • Confidentiality mode: additionally blocking anything that could read kernel memory
  • Planning a product around lockdown: what to fix in your stack before enabling it
  • Combining lockdown with module signatures, IMA and dm-verity for a coherent story

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: Write a small C tool that sandboxes itself with a Landlock filesystem ruleset; probe the boundaries
  2. Lab: Add network bind/connect rules and demonstrate blocked and allowed traffic
  3. Lab: Compose Landlock with a seccomp filter and show what each layer catches that the other misses
  4. Lab: Boot a VM in lockdown=integrity, attempt a list of root operations and document each refusal
  5. Lab: Audit a product's userspace for lockdown-incompatible behaviours and produce a fix list

Capstone project

Harden a provided application two ways: self-applied Landlock sandboxing (filesystem plus network) verified by boundary probes, and a system-level plan for enabling lockdown=integrity on its host — including the audit of what breaks and the remediation order — delivered as code plus a written deployment plan.

What you leave with

  • Working Landlock code you can lift into your own applications
  • The open/inspect/restrict-self pattern and ABI-version discipline
  • A clear map of what lockdown blocks and what it breaks
  • A layered-confinement design method: Landlock, seccomp, namespaces, lockdown

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Application and platform engineers who need sandboxing without root — and architects deciding how far root itself should be restricted on a shipped system. It sits at advanced level within the Kernel Security track.

What do I need to know already?

Specific prerequisites for this course: C programming against Linux APIs; Namespaces, capabilities and seccomp basics; A recent kernel for the labs (provided VM). We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 2 full days with hardware on your desk, capped at 14. Online is 4 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
8 Nov – 9 Nov 20262 full days RiyadhIn person · KAFD Conference Centre 3 of 14 SAR 5,400until 9 OctSAR 6,000
8 Nov – 9 Nov 20262 full days Kuwait CityIn person · Al Hamra Tower 8 of 14 KWD 450until 9 OctKWD 500
15 Nov – 16 Nov 20262 full days MuscatIn person · Knowledge Oasis Muscat 3 of 14 OMR 560until 16 OctOMR 620
22 Nov – 25 Nov 20264 half-days Gulf bandLive online · 09:00–13:00 GMT+3 9 of 20 US$1,040until 23 OctUS$1,150
23 Nov – 24 Nov 20262 full days OttawaIn person · Kanata North Tech Park 8 of 14 CAD 1,960until 24 OctCAD 2,180
23 Nov – 24 Nov 20262 full days TorontoIn person · MaRS Discovery District 3 of 14 CAD 1,960until 24 OctCAD 2,180
23 Nov – 26 Nov 20264 half-days Europe bandLive online · 09:00–13:00 CET 14 of 20 US$1,040until 24 OctUS$1,150
30 Nov – 1 Dec 20262 full days LondonIn person · Shoreditch Works 8 of 14 GBP 1,120until 31 OctGBP 1,250
30 Nov – 3 Dec 20264 half-days Americas bandLive online · 13:00–17:00 ET 3 of 20 US$1,040until 31 OctUS$1,150
7 Dec – 8 Dec 20262 full days BerlinIn person · Factory Görlitzer Park 3 of 14 EUR 1,320until 7 NovEUR 1,470

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Kernel Security

SEC-1012 days Reading Kernel CVEs Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe. Practitioner Practitioner-taught SAR 5,250Next 11 Oct SEC-1103 days Exploit Mitigations & Hardening The mitigations available in a modern kernel, what each actually stops, and what they cost. Advanced Practitioner-taught SAR 9,000Next 8 Nov SEC-1202 days Attack Surface Reduction Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible. Advanced Practitioner-taught SAR 6,000Next 25 Oct SEC-2013 days Multi-Branch Backporting Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team. Advanced Practitioner-taught SAR 9,000Next 1 Nov SEC-2102 days Stable, LTS & Vendor Tree Hygiene Working with the upstream stable process and keeping a vendor tree that does not rot. Practitioner Practitioner-taught SAR 5,250Next 18 Oct SEC-2202 days Building an Advisory Workflow The process around the engineering: intake, assessment, communication and evidence, on a deadline. Practitioner Practitioner-taught SAR 5,250Next 15 Nov SEC-3013 days LSM, SELinux & AppArmor Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced. Advanced Practitioner-taught SAR 9,000Next 22 Nov SEC-3203 days Integrity: IMA/EVM & dm-verity Measuring and verifying what runs on the system, from block device to individual file. Advanced Practitioner-taught SAR 9,000Next 18 Oct