open atlas

security-defensive

Defensive Security

Detect, respond, and harden: logging and detection engineering, incident response, defense-in-depth, and the security operations an engineer runs in production.

5 units·18 lessons·~5 h

Start track
00

Start here

The defender's job: turn attacks into signals, contain incidents, and harden by default.
01

Logging, monitoring, detection

Turn activity into signal: what to log, SIEM, MITRE ATT&CK, detection engineering, and alert quality.
02

Incident response

Run an incident without panic: the NIST lifecycle, triage, containment, forensics, and a blameless postmortem.
03

Hardening and defense in depth

Shrink the attack surface by default: host, network, baselines, and patch/vulnerability management.
04

SecOps and governance

Run security as a program: vulnerability management, SBOM/supply chain, and the compliance an engineer meets.

Build with this track

Guided projects that exercise what you learn here.

◆ Projects

Authorized Recon-to-Remediation Lab

Stand up an intentionally-vulnerable target you own — a deliberately-broken app in a local container or a CTF box on your own machine — and run a full offensive engagement against it, end to end, on a scope you signed off yourself. You recon the box, pick one class of vulnerability, prove it with a working exploit in the lab, and then turn around and write the fix and the detection. The point isn't to 'pop a box'; it's to live the whole loop a real engagement runs — scope, evidence, impact, remediation — on a target where nobody gets hurt.

◆ Projects

Cloud Hardening Lab

Take a cloud account you own and drag it from 'it works' to 'it's defensible'. You'll measure the posture you actually have, tighten IAM to least privilege without breaking the app, lock down the network and secrets, and prove every change with a before/after diff. This is the core of cloud security work: not adding features, but removing the standing access and quiet misconfigurations that an attacker would have used.

◆ Projects

Homelab Secure Stack

Stand up a self-hosted media and home-server stack on nas01.example where five services share a single VPN container's network namespace — the kill-switch drops all traffic the moment the tunnel dies, a split-tunnel whitelist carves out LAN access, and three layered access rings (localhost / LAN 10.0.0.0/24 / mesh-VPN 100.64.0.30) keep the right doors open to the right people. Harden the host with SSH key-only auth, fail2ban, and unattended security upgrades; write a rotating, age-encrypted off-site backup; and walk away knowing the stack stays dark if anything breaks.

◆ Projects

Threat-Model and Harden a Small App

Take a small app you fully own and run it through the loop a real security engineer lives in: first map how an attacker would actually break it, then close those paths one by one. You build an attack tree against your own service, then fix authentication, authorization, secrets handling, security headers, and input validation — and write down which fix kills which branch of the tree. This is the whole craft of defensive security in miniature: not a checklist, but a chain from threat to mitigation you can defend out loud.

Next track

Cloud & Infra Security

Securing modern infrastructure: the cloud shared-responsibility model, IAM, container and Kubernetes security, infrastructure-as-code, and cloud posture management.