Skip to content

24-week learner plan

Use this page as the student’s calendar. Each week assumes five 90-minute sessions: 20 minutes of retrieval, 15 minutes of concept study, 40 minutes on one bounded lab step, and 15 minutes of writing and teach-back. The lab environment must be disposable or explicitly authorized. A week is complete only when its evidence is redacted, reproducible, and reviewed against the assessment rubric.

Availability: this calendar describes the intended course. Many chapters are still outlines; see what is written and what is missing.

Week Focus and prerequisite Bounded lab deliverable Evidence and promotion gate
1 Orientation and foundations Scope a disposable lab and write an observation/inference/proof inventory Scope statement, baseline, and teach-back on uncertainty
2 Linux processes and permissions Trace one local process, file, user, and permission decision Redacted commands, expected versus observed result, rollback note
3 Networking fundamentals Compare a successful local request with a controlled DNS, route, or TCP failure Path diagram and failure classification; no unbounded scans
4 Windows identity Capture the test account’s token and local policy context Lab identity, command output, and explanation of local versus domain scope
5 Active Directory objects and trust Draw one authorized object relationship and its defensive choke point Object types, relationship evidence, and unresolved assumptions
6 Kerberos Diagram ticket flow and inspect only the dedicated lab ticket cache Principal/service/timestamp evidence; no export, replay, forging, or cracking
7 Remote administration prerequisites Compare SMB, WinRM, RDP, task, and service prerequisites Decision table with protocol, authorization, telemetry, and cleanup
8 Lateral-movement path Perform one harmless identity query between two lab machines Reproducible path, one failed attempt, and bounded defensive claim
9 Detection and response Replay one harmless lab event and write a detection hypothesis Event fields, baseline, false-positive comparison, and blind spot
10 Web request lifecycle Exercise a local vulnerable fixture with a test account Request/response metadata, reset state, and component owning the decision
11 Web authorization and reporting Test one object boundary and write a bounded finding Clean-reset reproduction, impact limits, remediation, and evidence refs
12 Programming for security work Build a small parser with typed inputs, errors, and tests Repository diff, fixture cases, test output, and safe-default rationale
13 Cloud identity and policy Model one local or synthetic control-plane/data-plane decision Policy/resource graph, denied case, and least-privilege explanation
14 Containers and isolation Inspect one disposable container’s user, image digest, mounts, and network Inspection output, image identity, cleanup, and blast-radius analysis
15 Static analysis Hash and inspect an instructor-provided sample without executing it Hash, tool versions, strings/imports, and hypotheses with uncertainty
16 Malware behavior reasoning Compare static observations with a synthetic runtime trace Evidence table separating capability, behavior, and unsupported inference
17 Wireless assessment Perform passive inventory in a shielded or explicitly authorized lab Frequency/device/firmware notes, safety owner, and no-active-test decision
18 SCADA and industrial security: 15, 16, 17 Draw the control architecture, analyze seven synthetic requests, and correlate maintenance evidence Five sessions: one architecture, two protocol analysis, two investigation; no unsupported physical-impact claim
19 OSINT and human factors Triangulate one fictional organization across three independent sources Dates, contradictions, confidence, and data-minimization rationale
20 Threat hunting Turn one observed behavior into a query and test a false positive Query input, expected telemetry, result, and known blind spot
21 DFIR timeline Build a timeline from synthetic evidence with preserved hashes Chain of custody, parser version, timezone, corroboration, uncertainty
22 AI security and supply chain Test a local fixture for prompt/data/tool trust-boundary confusion Demonstrate that retrieved text cannot invoke tools; record model/revision
23 Cryptography and secure engineering Verify a known test vector and review a small security invariant Input bytes, algorithm/version, digest, property test, and key-ownership explanation
24 Capstone integration Reproduce the authorized AD lateral-movement investigation Reviewer sign-off, clean reset, defensive control, failed attempt, teach-back

Promotion rule

At the end of each week, score recall, execution, and explanation separately. Promote only when the evidence meets the rubric, the safety boundary was respected, and the learner can state what would falsify the main claim. A failed or deliberately deferred experiment is valid evidence when the missing prerequisite or safety constraint is explained. Carry incomplete work into the next week; never convert an opened page or copied command into completion.

Weekly review record

Week and concept ID:
Authorization owner and lab boundary:
Prediction before reading:
Bounded step and reset point:
Observed result (redacted):
Interpretation and alternative explanation:
Defensive implication:
Recall / execution / explanation (0–4):
What would falsify the claim:
Reviewer decision and next review: