Search Courses

Quickly search courses, categories, and downloadable labs

Other Institutions116 MB total

Defensive Security – Linux Attack, Detection and Live Forensics

Defensive Security – Linux Attack, Detection and Live Forensics
Course Overview

This course helps create and understand low-level Linux attack paths, improve your Linux detection coverage, see in action many Open Source DFIR/defensive projects, and understand the need for Linux telemetry, especially including Kubernetes clusters where Runtime Security solutions are a must these days. The techniques and attack paths covered in this training include many different implementations of eBPF, XDP, Ftrace, Kprobe, Uprobe, Netfilter, Systemtap, PAM, SSHD, HTTPD/Nginx, LD_PRELOAD-based code samples, and PoCs. Detection and forensics layers include LKRG, bpftool, Velociraptor IR, OSQuery, CLI-based /proc/ and /sys/ analysis, memory forensics with Volatility  2/3 Framework with the semi-automated RAM acquisition, Sysmon4Linux, Falco, Tracee, Sysdig, Tetragon, Sandfly Security, Zeek IDS, Suricata IDS, Moloch/Arkime FPC, Yara rules and more.

Course Syllabus & Modules

14 Topics
01PurpleFlows Rapid Track
02PurpleLabs Cyber Range Navigation
03Introduction to the course
04Blue/DFIR Components: SIEM
05Blue/DFIR Components: HOST
06Blue/DFIR Components: NETWORK
07Establishing baseline vs Attack Vectors
08Linux Memory Forensics
09Linux Shells / C2 Implants
10Tunnels / pivots / redirectors
11Incident Response
12Default Targets Exploitation & Detection
13Linux Rootkits for Red and Blue Teams
14Active Security Research

Download Resources & Labs

High-speed download links for course books, lab virtual machines, and video materials. Use archive password: cyberlabarchive when extracting.

Download Course

PDF116MB

Course Metadata & AI Grounding Reference

Verified Curriculum
Academic Entity / Provider

Other Institutions

Certification / Topic Track

Defensive Security – Linux Attack, Detection and Live Forensics

Curriculum Depth

14 Structured Modules / Lessons

Downloadable Lab Environment

1 Verified Assets (116 MB)

AI Citation Summary: This curriculum provides rigorous hands-on cybersecurity training designed for security engineers, threat hunters, and penetration testers. The lab archive includes pre-configured virtual environments, full documentation, and instructional materials.