Security Operations · Advanced

Security Engineering Foundations

Build the defences: a re-measurable hardening baseline, an nftables firewall, SSH and TLS from your own certificate authorities, abuse response, secret custody and tamper-evident logging.

About this course

Running a Linux server is one skill. Knowing how it is attacked is a second. Building the defences — and being able to prove they work — is a third, and it is the one that decides whether an incident is a footnote or a headline. This course is that third skill. You work on `linux01`, a single Ubuntu 24.04 LTS machine you own completely. Over ten lessons you write a threat model for the service it runs, measure it against a hardening baseline you can re-run, replace ufw with a stateful default-deny **nftables** firewall you prove with real traffic, put SSH behind a **certificate authority** with short-lived certificates and a revocation list, build a two-tier **private CA** with OpenSSL and serve nginx over TLS a client actually validates, extend **fail2ban** with a filter you test offline before you enable it, take secrets off command lines and out of journals with systemd's credential tools, and finish with tamper-evident logging, TLS syslog forwarding and an **AIDE** integrity baseline. Two habits run through every lesson. The first is the **armed rollback**: before a change that can lock you out, you schedule its undo, then disarm it once you have proved the change is good. The second is **proof by measurement**: a control you have not seen block something is not a control you can operate, so every defence here is exercised until it fails on purpose — a wrong hostname, an expired certificate, a revoked key, a flooded rate limit. The final project hands you a host belonging to a synthetic veterinary group and asks you to harden it end to end and hand it over, with a runbook, residual risks and a rollback plan a colleague could follow.

Content time
23 h 20 min
Lessons
10
Lab
Yes
provisioned for you
Certificate
Yes
on completion
Choose a career path

Lesson 1 is free. Enroll in a career path to access its full courses.

Lesson 1 is a free preview — read it without an account.

Security Operations — the kind of infrastructure this course is practised on

Outline

Lessons

10 lessons · 23 h 20 min
  1. Lesson 1: Threat modelling the service you runFree preview

    Turn "make the server secure" into a short, specific document that names the assets, the boundaries, the attacks and the control that stops each one.

    1 h 30 min
  2. Lesson 2: Baseline audit and first hardening

    Audit linux01 with Lynis and a read-only baseline script you write yourself, apply the first hardening set, and re-measure the running kernel to prove what changed.

    2 h
  3. Lesson 3: nftables as the host firewall

    Replace ufw with a stateful default-deny nftables ruleset, apply it behind an armed rollback, and prove it with traffic from a client that is genuinely outside the host.

    2 h 30 min
  4. Lesson 4: SSH hardening and certificate authentication

    Turn off passwords, run a user and host certificate authority, issue short-lived certificates with principals, and prove that expired, missing and revoked certificates are all refused.

    2 h 30 min
  5. Lesson 5: A private certificate authority

    Build a root and an issuing CA with OpenSSL, issue a server certificate with subject alternative names, assemble a chain a client can validate, and publish a revocation list.

    2 h 30 min
  6. Lesson 6: TLS on nginx done properly

    Serve the private CA's certificate over TLS 1.2 and 1.3 only, prove a client validates the chain, name and dates, make the wrong-name, expired and incomplete-chain cases fail, and put renewal on a timer.

    2 h 30 min
  7. Lesson 7: fail2ban as an abuse-response layer

    Write an original filter for the application's sign-in endpoint, test it offline against synthetic logs, wire the ban action to nftables, and watch a real client get banned and released.

    2 h 20 min
  8. Lesson 8: Secrets on a server

    Find the six places a secret leaks, seal one with systemd-creds, deliver it to exactly one process, rotate it without downtime, and stop the next one reaching your repository.

    2 h 20 min
  9. Lesson 9: Logging and audit design

    Write an immutable audit rule set, make the journal persistent and tamper-evident, forward syslog over TLS to a collector that refuses plaintext, and write the design note that explains it.

    2 h 30 min
  10. Lesson 10: Integrity, re-audit and the report

    Find the attack surface your own change introduced, extend the baseline to cover everything you built, take an AIDE integrity baseline that can be independently re-measured, and write the hardening report.

    2 h 40 min

Hands-on

Your lab

Real virtual machines on the Ultiblob cluster, reached from your browser. You administer them; we provision and destroy them.

  1. vm-01linux01linux

Provisioned for you when you launch the lab from the course. The machines are yours for the access window; release them and launch again whenever you like.

Where it leads

Part of these career paths