Advanced Linux security
The offensive-informed defense capstone. Understand how an attacker moves on a Linux host — the local privilege-escalation paths, the places they persist, the rootkits they hide behind — then build the visibility to see it: audit pipelines, osquery, eBPF, and Falco on bare hosts. Finish with detections that survive contact, threat hunting, and Linux forensics and incident response. Seventeen lessons across six sections, each ending with a self-test.
Progress is saved in this browser only — no account required.
Final exam
Test yourself on everything
51 questions drawn from all 6 sections — every answer explained as you pick.