All courses

Advanced Linux security

A defensive course for engineers who already harden Linux servers. It explains how attackers work on a Linux host, only as deeply as detection needs: the intrusion chain, privilege escalation paths, and containers seen from the host. Then it builds the visibility to catch them with the audit pipeline, osquery, eBPF and Falco, writes detections that survive contact, hunts, and finishes with live triage, forensic artefacts and incident response. Commands were run on Ubuntu Server 26.04 LTS with RHEL 10 differences noted. Fifteen lessons across five sections, each with a self-test, and a final exam.

Advanced5 sections · 15 lessons · ~6h total · 53-question self-test

Progress is saved in this browser only — no account required.

Quick reference

Final exam
Test yourself on everything
53 questions drawn from all 5 sections — every answer explained as you pick.
Start final exam