Module 8 · Security Operations
Security wasn’t a bolt-on in this curriculum — you’ve been hardening since Module 2, segmenting since Module 3, and minding secrets since Module 0. This module makes security a discipline: you’ll assess your own lab like an attacker, build the monitoring and detection an operator needs, and then run a purple-team exercise — attack your own homelab and hunt yourself in the logs. That single exercise teaches operations and security better than anything else in the curriculum.
Everything here is done against your own infrastructure, which is what makes it both safe and uniquely instructive: you have full context on the target because you built it.
The lessons
Section titled “The lessons”| Lesson | Topic | Time |
|---|---|---|
| 8.0 · Rules of Engagement | Ethics, law, authorization, and a safe practice lab | 2–3 hrs |
| 8.1 · Assess | Recon, scanning, vulnerability assessment, the fix loop | 5–7 hrs |
| 8.2 · Identity & Secrets | Access hygiene, MFA, and secrets that leak | 3–4 hrs |
| 8.3 · Monitor & Detect | Prometheus/Grafana, central logs, detection rules | 6–8 hrs |
| 8.4 · Purple Team & Incident Response | Attack your lab, find it in the logs, write the post-mortem | 6–8 hrs |
| Labs | The six graded exercises | 10–14 hrs |
Total: roughly 35–45 hours, or 4–5 weeks part-time.
The idea that ties it together
Section titled “The idea that ties it together”Security operations is a loop, not a checklist:
graph LR
Assess[Assess<br/>scan, find weaknesses] --> Harden[Harden<br/>fix them]
Harden --> Monitor[Monitor & Detect<br/>watch for attacks]
Monitor --> Test[Purple team<br/>attack, verify detection]
Test --> Respond[Respond<br/>investigate, post-mortem]
Respond --> Assess
You assess, you harden, you watch, you test that your watching works, you respond and learn — and then you go around again. The purple-team exercise is the hinge: it’s where you prove your monitoring actually catches something, by being the attacker yourself.
Checkpoint
Section titled “Checkpoint”- I can state, precisely, what I am and am not legally allowed to test
- I regularly scan my own lab and remediate findings, with before/after proof
- No secret lives in plaintext or in git history; I know how to rotate one
- My homelab has metrics dashboards and alerts that reach me
- My hosts ship logs centrally and I have at least one working detection rule
- I’ve run a purple-team exercise and found (most of) my own attack in the logs
- I can write a clear, blameless post-mortem
Deliverable
Section titled “Deliverable”A purple-team report + post-mortem: your attack narrative, the detection evidence (dashboard and log screenshots), an honest account of what you missed, the gaps you closed, and a blameless incident write-up. This is the single most impressive artifact for a security-track interview. Full spec in the labs.
Resources
Section titled “Resources”- TryHackMe / Hack The Box — legal, sandboxed practice targets
- OWASP Top 10 — the vulnerabilities you’ll actually meet
- Wazuh / Security Onion — free SIEM platforms for the home lab
- MITRE ATT&CK — the shared language of detection