Kernel Security
Triage, backport, harden, respond.
Running a credible kernel security practice: reading vulnerabilities correctly, backporting fixes across branches, hardening configurations, and responding on a regulatory clock.
Vulnerabilities3 courses
SEC-1012 days
Reading Kernel CVEs
Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe.
Practitioner-taught
SAR 5,250Next 11 Oct
SEC-1103 days
Exploit Mitigations & Hardening
The mitigations available in a modern kernel, what each actually stops, and what they cost.
Practitioner-taught
SAR 9,000Next 8 Nov
SEC-1202 days
Attack Surface Reduction
Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible.
Practitioner-taught
SAR 6,000Next 25 OctResponse process3 courses
SEC-2013 days
Multi-Branch Backporting
Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team.
Practitioner-taught
SAR 9,000Next 1 Nov
SEC-2102 days
Stable, LTS & Vendor Tree Hygiene
Working with the upstream stable process and keeping a vendor tree that does not rot.
Practitioner-taught
SAR 5,250Next 18 Oct
SEC-2202 days
Building an Advisory Workflow
The process around the engineering: intake, assessment, communication and evidence, on a deadline.
Practitioner-taught
SAR 5,250Next 15 NovFrameworks3 courses
SEC-3013 days
LSM, SELinux & AppArmor
Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced.
Practitioner-taught
SAR 9,000Next 22 Nov
SEC-3102 days
Landlock & Kernel Lockdown
Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown.
Practitioner-taught
SAR 6,000Next 8 Nov
SEC-3203 days
Integrity: IMA/EVM & dm-verity
Measuring and verifying what runs on the system, from block device to individual file.
Practitioner-taught
SAR 9,000Next 18 OctWant this track delivered to your team?
Any combination of these courses can run privately, on-site or online, adapted to your stack.