Security Operations · Advanced
Security Engineering Foundations
Build the defences: a re-measurable hardening baseline, an nftables firewall, SSH and TLS from your own certificate authorities, abuse response, secret custody and tamper-evident logging.
About this course
Running a Linux server is one skill. Knowing how it is attacked is a second. Building the defences — and being able to prove they work — is a third, and it is the one that decides whether an incident is a footnote or a headline. This course is that third skill. You work on `linux01`, a single Ubuntu 24.04 LTS machine you own completely. Over ten lessons you write a threat model for the service it runs, measure it against a hardening baseline you can re-run, replace ufw with a stateful default-deny **nftables** firewall you prove with real traffic, put SSH behind a **certificate authority** with short-lived certificates and a revocation list, build a two-tier **private CA** with OpenSSL and serve nginx over TLS a client actually validates, extend **fail2ban** with a filter you test offline before you enable it, take secrets off command lines and out of journals with systemd's credential tools, and finish with tamper-evident logging, TLS syslog forwarding and an **AIDE** integrity baseline. Two habits run through every lesson. The first is the **armed rollback**: before a change that can lock you out, you schedule its undo, then disarm it once you have proved the change is good. The second is **proof by measurement**: a control you have not seen block something is not a control you can operate, so every defence here is exercised until it fails on purpose — a wrong hostname, an expired certificate, a revoked key, a flooded rate limit. The final project hands you a host belonging to a synthetic veterinary group and asks you to harden it end to end and hand it over, with a runbook, residual risks and a rollback plan a colleague could follow.
- Content time
- 23 h 20 min
- Lessons
- 10
- Lab
- Yes
- provisioned for you
- Certificate
- Yes
- on completion
Lesson 1 is free. Enroll in a career path to access its full courses.
Lesson 1 is a free preview — read it without an account.

Outline
Lessons
Lesson 1: Threat modelling the service you runFree preview
Turn "make the server secure" into a short, specific document that names the assets, the boundaries, the attacks and the control that stops each one.
1 h 30 minLesson 2: Baseline audit and first hardening
Audit linux01 with Lynis and a read-only baseline script you write yourself, apply the first hardening set, and re-measure the running kernel to prove what changed.
2 hLesson 3: nftables as the host firewall
Replace ufw with a stateful default-deny nftables ruleset, apply it behind an armed rollback, and prove it with traffic from a client that is genuinely outside the host.
2 h 30 minLesson 4: SSH hardening and certificate authentication
Turn off passwords, run a user and host certificate authority, issue short-lived certificates with principals, and prove that expired, missing and revoked certificates are all refused.
2 h 30 minLesson 5: A private certificate authority
Build a root and an issuing CA with OpenSSL, issue a server certificate with subject alternative names, assemble a chain a client can validate, and publish a revocation list.
2 h 30 minLesson 6: TLS on nginx done properly
Serve the private CA's certificate over TLS 1.2 and 1.3 only, prove a client validates the chain, name and dates, make the wrong-name, expired and incomplete-chain cases fail, and put renewal on a timer.
2 h 30 minLesson 7: fail2ban as an abuse-response layer
Write an original filter for the application's sign-in endpoint, test it offline against synthetic logs, wire the ban action to nftables, and watch a real client get banned and released.
2 h 20 minLesson 8: Secrets on a server
Find the six places a secret leaks, seal one with systemd-creds, deliver it to exactly one process, rotate it without downtime, and stop the next one reaching your repository.
2 h 20 minLesson 9: Logging and audit design
Write an immutable audit rule set, make the journal persistent and tamper-evident, forward syslog over TLS to a collector that refuses plaintext, and write the design note that explains it.
2 h 30 minLesson 10: Integrity, re-audit and the report
Find the attack surface your own change introduced, extend the baseline to cover everything you built, take an AIDE integrity baseline that can be independently re-measured, and write the hardening report.
2 h 40 min
Hands-on
Your lab
Real virtual machines on the Ultiblob cluster, reached from your browser. You administer them; we provision and destroy them.
- vm-01linux01linux
Provisioned for you when you launch the lab from the course. The machines are yours for the access window; release them and launch again whenever you like.
Where it leads