Python for security automation
For people who have finished Bash for ops and know little Python. You learn enough of the language to write maintainable automation on Ubuntu Server 26.04 with CPython 3.14: virtual environments, values and collections, functions and exceptions. Then the automation core: files and safe writes, subprocess without a shell, regular expressions, JSON, CSV, YAML and TOML, streaming logs, logging and retries, HTTP APIs with timeouts and TLS, secrets, hashing and HMAC. It ends with argparse, pytest, packaging with a hash-locked install, and an IOC sweep tool built end to end. Every example ran on the lab machine against local fixtures and a local HTTPS API.
01Python and virtual environments on Ubuntu 26.04python3, python3-venv, PEP 668 and running a venv from cron or systemd.35 min02Python for Bash users: values, collections and loopsStrings, numbers, lists, dicts, sets, loops and f-strings, mapped from Bash.25 min03Functions, modules and exceptionsdef, imports, __main__, with, try/except and reading a traceback.30 min
01Files, paths and safe writespathlib, encodings, atomic replace, file modes and untrusted paths.30 min02Running commands safelysubprocess.run with a list, timeouts, errors, option injection and the environment.40 min03Regular expressions for logs and tool outputNamed groups, readable patterns, ReDoS and validating with ipaddress.20 min04JSON, CSV, YAML and TOMLParse and write the formats tools speak, and load untrusted YAML safely.35 min05Streaming big logs with generatorsGenerators, rotated gzip files, Ubuntu 26.04 log lines and constant memory.30 min
01Logging, retries and failure designCustom exceptions, logging to stderr, and retries with backoff, jitter and a deadline.30 min02Calling HTTP APIs safelyTimeouts, status checks, TLS with your own CA, pagination limits and 429 handling.45 min03Secrets: where they come from and where they leakFiles, credentials, stdin and env compared, plus argv, log and child-process leaks.35 min04Hashes, HMAC and password storageFile checksums, webhook HMAC verification, tokens and why sha256 is wrong for passwords.35 min
01Command-line tools with argparseArguments, subcommands, stdin, an exit-code contract and an honest dry-run.45 min02Testing your automation with pytestFixtures, tmp_path, monkeypatch, stub commands, a local HTTP server and exit codes.30 min03Packaging, pinning and auditing your toolpyproject.toml, a wheel, a hash-locked install, pip-audit and pipx.35 min04Capstone: an IOC sweep toolConfig, secrets, hashing, an HTTPS API, subprocess, output, tests and install.85 min
Progress is saved in this browser only — no account required.
Quick reference
Final exam
Test yourself on everything
46 questions drawn from all 4 sections — every answer explained as you pick.