Advanced Linux security
A defensive course for engineers who already harden Linux servers. It explains how attackers work on a Linux host, only as deeply as detection needs: the intrusion chain, privilege escalation paths, and containers seen from the host. Then it builds the visibility to catch them with the audit pipeline, osquery, eBPF and Falco, writes detections that survive contact, hunts, and finishes with live triage, forensic artefacts and incident response. Commands were run on Ubuntu Server 26.04 LTS with RHEL 10 differences noted. Fifteen lessons across five sections, each with a self-test, and a final exam.
01Local privilege escalation: SUID, sudo and capabilitiesHow the paths work and what they leave behind.16 min02Kernel exploits and credential discoveryUnpatched kernels, weak jobs and leaked secrets.14 min03Finding escalation paths before an attacker doesBaseline and diff the risky surfaces.14 min04Containers and namespaces from the hostMap container processes and spot escapes.16 min
Progress is saved in this browser only — no account required.
Quick reference
Final exam
Test yourself on everything
53 questions drawn from all 5 sections — every answer explained as you pick.