24-week learner plan
Use this page as the student’s calendar. Each week assumes five 90-minute sessions: 20 minutes of retrieval, 15 minutes of concept study, 40 minutes on one bounded lab step, and 15 minutes of writing and teach-back. The lab environment must be disposable or explicitly authorized. A week is complete only when its evidence is redacted, reproducible, and reviewed against the assessment rubric.
Availability: this calendar describes the intended course. Many chapters are still outlines; see what is written and what is missing.
| Week | Focus and prerequisite | Bounded lab deliverable | Evidence and promotion gate |
|---|---|---|---|
| 1 | Orientation and foundations | Scope a disposable lab and write an observation/inference/proof inventory | Scope statement, baseline, and teach-back on uncertainty |
| 2 | Linux processes and permissions | Trace one local process, file, user, and permission decision | Redacted commands, expected versus observed result, rollback note |
| 3 | Networking fundamentals | Compare a successful local request with a controlled DNS, route, or TCP failure | Path diagram and failure classification; no unbounded scans |
| 4 | Windows identity | Capture the test account’s token and local policy context | Lab identity, command output, and explanation of local versus domain scope |
| 5 | Active Directory objects and trust | Draw one authorized object relationship and its defensive choke point | Object types, relationship evidence, and unresolved assumptions |
| 6 | Kerberos | Diagram ticket flow and inspect only the dedicated lab ticket cache | Principal/service/timestamp evidence; no export, replay, forging, or cracking |
| 7 | Remote administration prerequisites | Compare SMB, WinRM, RDP, task, and service prerequisites | Decision table with protocol, authorization, telemetry, and cleanup |
| 8 | Lateral-movement path | Perform one harmless identity query between two lab machines | Reproducible path, one failed attempt, and bounded defensive claim |
| 9 | Detection and response | Replay one harmless lab event and write a detection hypothesis | Event fields, baseline, false-positive comparison, and blind spot |
| 10 | Web request lifecycle | Exercise a local vulnerable fixture with a test account | Request/response metadata, reset state, and component owning the decision |
| 11 | Web authorization and reporting | Test one object boundary and write a bounded finding | Clean-reset reproduction, impact limits, remediation, and evidence refs |
| 12 | Programming for security work | Build a small parser with typed inputs, errors, and tests | Repository diff, fixture cases, test output, and safe-default rationale |
| 13 | Cloud identity and policy | Model one local or synthetic control-plane/data-plane decision | Policy/resource graph, denied case, and least-privilege explanation |
| 14 | Containers and isolation | Inspect one disposable container’s user, image digest, mounts, and network | Inspection output, image identity, cleanup, and blast-radius analysis |
| 15 | Static analysis | Hash and inspect an instructor-provided sample without executing it | Hash, tool versions, strings/imports, and hypotheses with uncertainty |
| 16 | Malware behavior reasoning | Compare static observations with a synthetic runtime trace | Evidence table separating capability, behavior, and unsupported inference |
| 17 | Wireless assessment | Perform passive inventory in a shielded or explicitly authorized lab | Frequency/device/firmware notes, safety owner, and no-active-test decision |
| 18 | SCADA and industrial security: 15, 16, 17 | Draw the control architecture, analyze seven synthetic requests, and correlate maintenance evidence | Five sessions: one architecture, two protocol analysis, two investigation; no unsupported physical-impact claim |
| 19 | OSINT and human factors | Triangulate one fictional organization across three independent sources | Dates, contradictions, confidence, and data-minimization rationale |
| 20 | Threat hunting | Turn one observed behavior into a query and test a false positive | Query input, expected telemetry, result, and known blind spot |
| 21 | DFIR timeline | Build a timeline from synthetic evidence with preserved hashes | Chain of custody, parser version, timezone, corroboration, uncertainty |
| 22 | AI security and supply chain | Test a local fixture for prompt/data/tool trust-boundary confusion | Demonstrate that retrieved text cannot invoke tools; record model/revision |
| 23 | Cryptography and secure engineering | Verify a known test vector and review a small security invariant | Input bytes, algorithm/version, digest, property test, and key-ownership explanation |
| 24 | Capstone integration | Reproduce the authorized AD lateral-movement investigation | Reviewer sign-off, clean reset, defensive control, failed attempt, teach-back |
Promotion rule
At the end of each week, score recall, execution, and explanation separately. Promote only when the evidence meets the rubric, the safety boundary was respected, and the learner can state what would falsify the main claim. A failed or deliberately deferred experiment is valid evidence when the missing prerequisite or safety constraint is explained. Carry incomplete work into the next week; never convert an opened page or copied command into completion.
Weekly review record
Week and concept ID:
Authorization owner and lab boundary:
Prediction before reading:
Bounded step and reset point:
Observed result (redacted):
Interpretation and alternative explanation:
Defensive implication:
Recall / execution / explanation (0–4):
What would falsify the claim:
Reviewer decision and next review: