CS 410/510: System Administration and DevOps
Location: FAB 47 (MW 09:15-11:35)
Instructor: D. Kevin McGrath
- PDX username: dmcgrath
- Office hours:
- Location: FAB 120-15
- Times:
- Tuesday: Code Party! 18:00 - 22:00 (Fishbowl)
- Whenever you see me in my office with the door open
- By appointment
- Times:
- Location: FAB 120-15
- CS 410/510: System Administration and DevOps
- Recordings
- Weekly Schedule
- Week 1 — Infrastructure as Code and Threat Modeling
- Week 2 — OS Hardening and Secrets Management
- Week 3 — Container Security I: Threat Model and Image Hardening
- Week 4 — Container Security II: Scanning, Supply Chain, and Monitoring
- Week 5 — Shift-Left Security Tooling
- Week 6 — Policy, Access Control, and Host Firewall
- Week 7 — Detection and Monitoring
- Week 8 — Incident Response and Capstone
- Pages
- Useful links for learning
- Homework
- Evaluation of Student Performance
- Course Policies
- Academic or Student Support Services
Recordings
While not all lectures will be recorded, some will be. You will likely have to login to your PDX MediaSpace account to view these.
- Week 1 - Lecture 1
- Week 1 - Lecture 2
- Week 2 - Lecture 1
- Week 2 - Lecture 2: class canceled due to illness
- Week 3 - Lecture 1: missing recording
- Week 3 - Lecture 2: no recording
- Week 4 - Lecture 1: no recording
- Week 4 - Lecture 2: no recording
- Week 5 - Lecture 1: no recording
- Week 5 - Lecture 2: no recording
- Week 6 - Lecture 1: no recording
- Week 6 - Lecture 2: no recording
- Week 7 - Lecture 1: no recording
- Week 7 - Lecture 2: no recording
- Week 8 - Lecture 1: no recording
- Week 8 - Lecture 2: no recording
Weekly Schedule
The course is a single continuous build: each week hardens, scans, or instruments the lab environment so that the next week has something to defend, detect, or attack. Every week is two sessions; click a week for the full walkthrough, and use the linked reference pages for the background theory.
Week 1 — Infrastructure as Code and Threat Modeling
Establish the two foundations the rest of the course builds on: a reproducible, version-controlled environment, and a threat model that explains why every later control matters. You cannot harden what you haven’t defined.
| Session | Focus | Reference reading |
|---|---|---|
| 1 · Infrastructure as Code | Terraform, declarative/idempotent provisioning, the Proxmox lab, baseline snapshots | Infrastructure as Code |
| 2 · Threat Modeling with STRIDE | STRIDE, data flow diagrams, threat scoring, the DVWA target system | Threat Modeling · DevSecOps Fundamentals |
Week 2 — OS Hardening and Secrets Management
Reduce the attack surface of the freshly provisioned Ubuntu server — removing what isn’t needed, locking down what remains — then replace plaintext credentials with a proper secrets manager.
| Session | Focus | Reference reading |
|---|---|---|
| 3 · Linux OS Hardening | Attack-surface mindset, SSH lockdown, service minimization, SUID auditing, sudo-rs, fail2ban |
OS Hardening |
| 4 · Secrets Management with OpenBao | Why env vars aren’t enough, OpenBao’s security model, policies, dynamic vs. static credentials | OpenBao · CI/CD, Secrets, and GitOps |
Week 3 — Container Security I: Threat Model and Image Hardening
Understand what containers actually isolate (and what they don’t), harden the DVWA and nginx images, and apply runtime constraints that limit what a compromised container can do.
| Session | Focus | Reference reading |
|---|---|---|
| 5 · Container Threat Model & Image Hardening | Isolation boundaries, the DVWA threat surface, Dockerfile hardening, non-root execution, layer inspection for secrets | Containerization · Container Security |
| 6 · Container Runtime Hardening | Defense in depth, Linux capabilities, seccomp syscall filtering, the Compose file as security policy, network segmentation | Container Security |
Week 4 — Container Security II: Scanning, Supply Chain, and Monitoring
Look inside the containers — scanning for known CVEs in OS packages and dependencies — and bring the Wazuh agent online so everything from here on is observed.
| Session | Focus | Reference reading |
|---|---|---|
| 7 · Image Scanning & Supply Chain | The software supply chain, CVSS scoring, Trivy scanning and triage, the SBOM | Vulnerability Management · Container Security |
| 8 · Networking, Secrets Integration & Wazuh Agent | Secrets in containers done right, verifying network isolation, registering the Wazuh agent | Wazuh SIEM |
Week 5 — Shift-Left Security Tooling
Move detection earlier in the lifecycle: static analysis and secrets scanning at commit time, plus a structured vulnerability-management and host-audit workflow.
| Session | Focus | Reference reading |
|---|---|---|
| 9 · SAST and Secrets Detection | What static analysis is and isn’t, Bandit, Semgrep with custom rules, triage, gitleaks |
SAST and Secrets Detection · Vulnerability Management · DevSecOps Fundamentals |
| 10 · Vulnerability Management & OS Audit | The VM lifecycle, Lynis host-hardening audit, connecting findings to the threat model, patch strategy | Vulnerability Management |
Week 6 — Policy, Access Control, and Host Firewall
Add the final layer of host-side controls: policy-as-code, least-privilege access, and a host firewall with automated response.
| Session | Focus | Reference reading |
|---|---|---|
| 11 · Policy-as-Code with auditd & AppArmor | What policy-as-code means, auditd framework, Wazuh integration, AppArmor MAC, host-level zero trust |
OS Hardening |
| 12 · IAM, Firewall, and Automated Response | Least privilege end to end, nftables host firewall, fail2ban active response, IAM concepts applied locally |
Identity and Access Management · Firewalls and IPS |
Week 7 — Detection and Monitoring
Build the detection layer on top of the preventive controls: knowing when an attack is happening, what it’s doing, and how to respond.
| Session | Focus | Reference reading |
|---|---|---|
| 13 · Wazuh Rules, Tuning & Active Response | The detection problem, writing and calibrating Wazuh rules, active-response architecture, closing the detection gap | Monitoring and Observability · SIEM, SOC, and Threat Detection |
| 14 · Suricata Integration & File Integrity Monitoring | Network vs. host detection, Suricata IDS rules, FIM as the last line, correlating detection layers | Suricata IDS/IPS · Wazuh SIEM |
Week 8 — Incident Response and Capstone
Close the loop: respond to an incident when prevention fails, then prove the whole stack with a red/blue capstone against your own system.
| Session | Focus | Reference reading |
|---|---|---|
| 15 · Incident Response | IR as more than a technical problem, NIST SP 800-61r2 lifecycle, triage, snapshot-before-touching containment, writing a runbook | Incident Response · SIEM, SOC, and Threat Detection |
| 16 · Red/Blue Capstone | Structured offense, structured analysis, an honest post-mortem, and revisiting the Week 1 threat model | Threat Modeling |
Pages
Course-specific reference pages
These are not specific to any one lecture, but offer significant reference material that we will use as we move through the course.
Lab environment
- Proxmox setup – provisioning and configuring the Proxmox host
- Terraform config for lab VMs – provisions Kali, Ubuntu server, and Wazuh VMs
- Ansible playbook for initial host configuration – installs all lab tools
Reference pages (background reading by week)
- Infrastructure as Code – Terraform, Pulumi, Ansible (Week 1)
- Ansible: Writing Playbooks From Scratch – modules, idempotency, variables and precedence, templates, roles, Vault and
no_log(Week 1) - Threat Modeling – STRIDE, PASTA, attack trees, DFDs (Week 1)
- DevSecOps Fundamentals – CIA triad, zero trust, shift-left, pipeline security (Weeks 1–2)
- CI/CD, Secret Management, and GitOps – OpenBao, SOPS, GitOps (Week 2)
- Containerization – namespaces, cgroups, Docker fundamentals (Weeks 3–4)
- SAST and Secrets Detection – Semgrep custom rules and taint mode, triage, Bandit, gitleaks (Week 5)
- Vulnerability Management – CVE scoring, Lynis, OpenVAS, patching (Week 5)
- Identity and Access Management – RBAC, least privilege, service accounts (Week 6)
- Monitoring and Observability – metrics, logging, alerting (Week 7)
- SIEM, SOC, and Threat Detection – Wazuh, Elastic Security, auditd, Falco (Weeks 7–8)
- Incident Response – IR lifecycle, NIST SP 800-61, runbooks (Week 8)
- Firewalls and IPS – iptables, nftables, pf, ipfw, OPNsense, Security Onion (Week 6)
- Suricata IDS/IPS – installation, rules, EVE JSON, Wazuh integration (Week 7)
- Proxmox setup – a brief introduction to setting up Proxmox VE
- Introduction to Networking – a brief introduction to networking concepts
- Introduction to network reconnaissance – a brief introduction to network reconnaissance and using nmap
nmapcheatsheet- Capturing packets – a brief introduction to capturing packets
- Using
wireshark– a brief introduction to usingwireshark - Ansible Tips and Tricks
- Ansible Documentation
Configuration and Tooling
- SSH
- tmux
- SSH Tunnel for Windows RDP
- Unix Text Processing: sed and awk – substitution, in-place editing, validation, and pipeline patterns
tmuxcheatsheettmuxconfig – configuration file fortmuxfrom the Software Configuration page- Linux Handbook on
tmux - Technical Writing
- Powershell profile
Other stuff
- TunnelVision exploit against VPNs – an exploit a malicious network admin could use to render most VPNs useless.
- Useful SANS resources
- VM Setup on Windows with Hyper-V – an alternative hypervisor to VirtualBox
Useful links for learning
- tmux cheatsheet
- Linux Handbook on tmux
- Markdown
- The C Book
- The GNU
makemanual - Managing projects with
make - The
chmodcalculator - The Python tutor
- The Linux Command Line (direct PDF download)
- Adventures with the Linux Command Line
- The Linux Development Platform
- gdb tutorial
- gef manual
Homework
Each homework will build on the previous assignment. These aren’t your typical “write answers to questions” type assignments, but rather are intended to be more hands-on. We will be adding to, modifying, or otherwise doing something to the VM environment to enable us to do something else. The first assignment will be to get the VM environment set up and configured. Subsequent assignments will build on this.
Submission
All work will be submitted via MarkDown documents within an internal gitlab repo. You will be using this repo for the rest of the term. This repo exists on the CECS intranet. You will need to add the TA and me to this repo as Developers. Grades and feedback will be done via a merge request from the TA.
Assignments
- Lab - Week 1
- Lab - Week 2
- Lab - Week 3
- Lab - Week 4
- Lab - Weeks 5-6
- Lab - Week 7
- Verification Script
- Wazuh dashboard
- Capstone Exercise
Evaluation of Student Performance
This course uses a weighted average of assignments. All assignments will be graded out of 100 points, with the following weights towards the final grade:
- Final Project: 40%
- Lab Assignments: 60%
- While attendance will not be explicitly graded, it is expected that you will be involved in the classes. Recordings will only be available to those students who attend class.
Letter Grade
Letter grades will be assigned based on standard ranges with (optionally) +/- steps.
| Grade | Percent Range |
|---|---|
| A | 90-100 |
| B | 80-90 |
| C | 70-80 |
| D | 60-70 |
| F | <60 |
Course Policies
Late Work Policy
No late work will be accepted without prior discussion. I understand that life happens, but request for late hand-in must be submitted prior to the due date. Permission will be granted dependent upon reasons, current state of completion, etc.
Incompletes
Incomplete (I) grades will be granted only in emergency cases (usually only for a death in the family, major illness or injury, or birth/adoption of a child), and if the student has turned in 90% of the points possible AT THE TIME OF REQUEST. In other words, if you have been keeping up, but a major life event occurs, let me know as soon as possible. If you are having any difficulty that might prevent you completing the coursework, please don’t wait until the end of the term; let me know right away.
Academic or Student Support Services
Accommodations
Accommodations for students with disabilities are determined and approved by Disability Resource Center (DRC). If you, as a student, believe you are eligible for accommodations but have not obtained approval please contact DRC immediately at 503-725-4150, drc@pdx.edu, or https://www.pdx.edu/disability-resource-center. DRC notifies students and faculty members of approved academic accommodations and coordinates implementation of those accommodations. If you have accommodations through DRC and wish to take the Midterm or Final Exam in the testing center, I strongly recommend that you schedule it before the end of week 1. If you are not registered with the DRC, you cannot register to take an exam in the testing center.
I want to make this class an open and welcoming environment for all. Your success is my goal.
Religious Observance
Portland State University strives to respect all religious practices. If you have religious holidays that conflict with any of the requirements of this class, please see me immediately so that we can make alternative arrangements.
Reach Out for Success
The PSU Center for Student Health and Counseling (SHAC) is staffed with folks who care and can help with a wide range of personal challenges. Here at PSU, there is never a need to tough things out alone.
As a student you may experience a range of issues that can cause barriers to learning, such as strained relationships, increased anxiety, alcohol/drug problems, feeling down, difficulty concentrating and/or lack of motivation. These mental health concerns or stressful events may lead to diminished academic performance or reduce a student’s ability to participate in daily activities. PSU is committed to advancing the mental health and well-being of its students. If you or someone you know is feeling overwhelmed, depressed, and/or in need of support, services are available. You can learn more about the broad range of confidential mental health services available on campus via SHAC https://www.pdx.edu/health-counseling/.
SHAC also has resources for physical health, including flu shots. You can check out their COVID-19 resources page here: https://www.pdx.edu/health-counseling/covid-19-resources (including testing).
Get Food Now Here at PSU, there is never a need to tough things out alone. Those who can, give, so those who need, have.
Housing / financial crisis help Here at PSU, there is never a need to tough things out alone. Emergency Housing, etc.
Title IX
As an instructor, students frequently come to me for assistance in matters that are not related to the course material. Please be aware that PSU’s policies require instructors to report any instance of sexual harassment, sexual and relationship violence and/or other forms of prohibited discrimination to University Officials, who keep the information private. If you would rather share information about these experiences with a PSU staff member who does not have these reporting responsibilities and can keep the information confidential, please contact one of the following campus resources.
- Confidential Advocates: 503.894.7982, or by scheduling on-line (for matters regarding sexual harassment and sexual and relationship violence)
- Center for Student Health and Counseling (SHAC): 1880 SW 6th Ave, 503.725.2800
- Student Legal Services: 1825 SW Broadway, (SMSU) M343, 503.725.4556
PSU Sexual Misconduct Response website gives you comprehensive information about how to support and/or report an incident.
Please complete the required student module Understanding Sexual Misconduct and Resources in Canvas, which provides information about PSU policy and resources.
You may also report sexual and relationship violence to law enforcement on campus with Campus Public Safety Office (CPSO)
Or you may file an anonymous report with Campus Public Safety Office or a Bias Incident report with the Bias Review Team (BRT). PSU does not typically investigate the reports that are made through these two avenues. These reports help PSU understand what students and employees are experiencing on and around campus and provide support where needed.