All Modules LINUX

Linux · Complete Guide

Eight chapters from filesystem and permissions foundations through users and authentication, syslog and journald analysis, persistence mechanisms, live process and network internals, shell tradecraft, container and Docker security, and closing with Linux incident response and hardening. Built for analysts who need to investigate and defend Linux servers and containers, not just Windows endpoints.

8 CHAPTERS
~12 HRS CONTENT
BEGINNER to ADVANCED SKILL RANGE
SEP 2026 LAST UPDATED
MODULE PROGRESS 0 / 8 chapters complete
filesystem hierarchy users and auth syslog and journald persistence process and network internals shell tradecraft containers incident response

ALL CHAPTERS

/
01
BEGINNER 25 min

Linux Foundations: Filesystem Hierarchy, Permissions & the Process Model

The Linux filesystem hierarchy, the permissions model including setuid, the PID/PPID process model, and shell basics.

filesystem hierarchy permissions model process model
02
INTERMEDIATE 30 min

Users, Authentication & Privilege: passwd, shadow, PAM & sudo

User account structure, PAM authentication, sudo versus su, common privilege escalation vectors, and privileged group membership.

user accounts PAM sudo
03
INTERMEDIATE 30 min

Logging and Syslog Analysis: rsyslog, journald & Key Log Files

Logging architecture (syslog versus journald), key log files, reading authentication events, journalctl, and log tampering as a detectable technique.

syslog journald auth log
04
INTERMEDIATE 35 min

Persistence Mechanisms: Cron, systemd, Shell Profiles & SSH Keys

Cron persistence, systemd service and timer persistence, shell profile files, SSH authorized_keys persistence, and a hunting checklist.

cron persistence systemd persistence SSH key persistence
05
INTERMEDIATE 35 min

Process and Network Internals: /proc, Process Trees & Socket Visibility

The /proc filesystem, process tree analysis, network visibility with ss and netstat, and open file visibility with lsof.

/proc filesystem process trees lsof
06
INTERMEDIATE 35 min

Shell Tradecraft and Detection: Reverse Shells, History Manipulation & Linux LOLBins

Reverse shell concepts, bash history manipulation, the Linux living-off-the-land parallel to LOLBAS, and layered detection strategy.

reverse shells history manipulation Linux LOLBins
07
ADVANCED 40 min

Container and Docker Security: Fundamentals, Escape Techniques & Hardening

Namespaces and cgroups, Docker architecture and risk, container escape technique categories, Kubernetes security basics, and hardening practices.

container fundamentals Docker security Kubernetes basics
08
ADVANCED 40 min

Linux Incident Response and Hardening: Investigation Workflow & Baseline Controls

Linux live response priorities, an incident response workflow, common Linux incident patterns, and baseline hardening controls.

Linux incident response live response hardening baseline

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • No prior Linux administration experience required, Chapter 1 builds the filesystem, permissions, and process fundamentals from scratch
  • Digital Forensics and Windows are good companion modules, since several chapters cross-link back to order of volatility and the LOLBAS/living-off-the-land concept
  • Basic command-line comfort is useful but not assumed
  • No specific distribution expertise required, this module covers concepts that transfer across Debian, RedHat, and other major families

WHAT YOU WILL KNOW AFTER

  • The Linux filesystem hierarchy, permissions model, and process model that every later chapter builds on
  • How user accounts, PAM authentication, and sudo/privilege escalation actually work
  • Where Linux logging evidence lives across syslog and journald, and how to read it
  • The persistence mechanisms attackers abuse: cron, systemd, shell profiles, and SSH keys
  • How to investigate a live host through /proc, process trees, network sockets, and open files
  • How to recognize reverse shells, history manipulation, and Linux living-off-the-land tradecraft
  • How containers and Docker actually isolate (and sometimes fail to isolate) workloads, and how to harden them
  • A repeatable Linux incident response workflow and the baseline hardening controls that prevent a repeat

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.