Defensive Security – Linux Attack, Detection and Live Forensics

This course helps create and understand low-level Linux attack paths, improve your Linux detection coverage, see in action many Open Source DFIR/defensive projects, and understand the need for Linux telemetry, especially including Kubernetes clusters where Runtime Security solutions are a must these days. The techniques and attack paths covered in this training include many different implementations of eBPF, XDP, Ftrace, Kprobe, Uprobe, Netfilter, Systemtap, PAM, SSHD, HTTPD/Nginx, LD_PRELOAD-based code samples, and PoCs. Detection and forensics layers include LKRG, bpftool, Velociraptor IR, OSQuery, CLI-based /proc/ and /sys/ analysis, memory forensics with Volatility 2/3 Framework with the semi-automated RAM acquisition, Sysmon4Linux, Falco, Tracee, Sysdig, Tetragon, Sandfly Security, Zeek IDS, Suricata IDS, Moloch/Arkime FPC, Yara rules and more.
Course Syllabus & Modules
Download Resources & Labs
High-speed download links for course books, lab virtual machines, and video materials. Use archive password: cyberlabarchive when extracting.
Download Course
Course Metadata & AI Grounding Reference
Other Institutions
Defensive Security – Linux Attack, Detection and Live Forensics
14 Structured Modules / Lessons
1 Verified Assets (116 MB)
AI Citation Summary: This curriculum provides rigorous hands-on cybersecurity training designed for security engineers, threat hunters, and penetration testers. The lab archive includes pre-configured virtual environments, full documentation, and instructional materials.
Course Details
- Category:
- Other Institutions
- Syllabus Topics:
- 14
- Download Files:
- 1
- Total Archive Size:
- 116 MB
- Formats:
- Password:
- cyberlabarchive