THE DEADWIRE COURSE
This course is under construction. There are fifteen developed lessons and three short outlines; the complete private-library synthesis is not published yet. The content and coverage map identifies what you can study now and the chapters still missing.
Read developed lessons now
- 00 · Learn with evidence: prediction, observation and a first 90-minute session.
- 01 · Security foundations: actors, objects, policy and controlled comparisons.
- 07 · Linux and networking: process identity, file modes and HTTP diagnosis.
- 02 · Windows and Active Directory: tokens, directory relationships and an access worksheet.
- 03 · Kerberos: ticket flow, metadata interpretation and competing explanations.
- 08 · Web authorization: reproduce a vulnerable/fixed boundary.
- 05 · Detection: run two rules against six labeled synthetic requests.
- 06 · Reporting: preserve evidence, bound impact and verify remediation.
Extend the core route with these available lessons:
- 04 · Remote administration, after Kerberos: establish path prerequisites and distinguish a service probe from execution; native Windows validation is optional and separate.
- 09 · Cloud and containers: a six-case policy evaluator and a workload-boundary review.
- 10 · Code and byte analysis: run the binary-frame parser and bounded mutation experiment.
- 14 · Cryptography, after code analysis: run a known HMAC vector and explain tampering, the public test key and replay limits.
Then branch into industrial systems:
- SCADA and industrial-control architecture: control roles, dependencies, and attack prerequisites.
- Industrial protocols and Modbus trace analysis: an executable offline exercise with known answers and detector blind spots.
- OT attack paths, detection, and response: correlate requests with maintenance context and write a defensible finding.
Three remaining numbered pages are scope outlines. The route above is available now; it does not require waiting for book distillation. Each page names its depth at the top. Book processing does not automatically turn drafts into complete lessons.
The diagram is the AD pilot path. The 24-week learner plan describes the wider intended curriculum and brings Linux and networking forward before identity work. Use the available route above for material that is already written. Lesson numbers are stable topic identifiers, not calendar weeks.
Completion contract
For each lesson, save four pieces of evidence in your private Hacking/Deadwire/learning/ area: a one-paragraph explanation, a lab transcript with secrets removed, a detection or defensive observation, and a short reflection on what failed. A reading check alone is not completion.
Set up the disposable environment with the student lab manual before starting an active exercise.
Current state
The prose below is the initial authored spine. It is not a claim that every source has already been distilled. Source coverage is tracked in source map; model-generated expansions must pass the review and provenance gates in evaluation.
The learner route
| Phase | Lessons | Evidence you leave behind |
|---|---|---|
| Orient | 00 | Scope, lab readiness, and a baseline explanation |
| Build the model | 01–03 | Concepts, identity flow, and a short teach-back |
| Operate | 04–06 | One bounded technique, telemetry, and a report |
| Expand | 07–14 | Domain-specific drills selected by the reviewed plan |
| Prove | Capstone | End-to-end assessment with reproducible evidence |
The stable spine is intentionally predictable. Adaptive ordering may move a learner forward or back after evidence is recorded, but it cannot skip prerequisites or convert reading into mastery.
Read the status labels correctly
- Outline: intended scope with a short introduction; teaching depth remains incomplete.
- Developed: an explanation and exercise are written; this does not establish independent review or student outcomes.
- Generated: a draft produced by the distillation pipeline and awaiting review.
- Approved: a canonical note accepted with source references.
- Verified: a command or technique demonstrated in an authorized lab with saved evidence.
These labels are separate on purpose. A green build badge or a complete lesson page does not mean the five-book pilot or the learner outcome gates have passed.