Defending Linux Against Real Attackers

No ratings

Presented at BSides Toronto 2026 by

Linux powers much of today's infrastructure, from cloud platforms and Kubernetes clusters to enterprise servers and home labs. While countless hardening guides and benchmark checklists exist, they often explain what to configure rather than why it matters. This session takes a practical look at Linux security through the eyes of an attacker. We'll explore common attack paths, the defensive controls that disrupt them, and how to build multiple layers of protection using built-in Linux features and open source tools. Whether you're securing a single server or an entire fleet, you'll leave with practical techniques you can immediately apply.