Agentic Security Engineering · Course 01

Build your own
agentic defense

One complete agentic defense system, built by you — carried through a single intrusion, from raw telemetry to a grounded report.

Speaker & trainer at
Wild West Hackin’ FestNorthSec — MontréalBSides MontréalHackfest — Québec CityAntiSyphon Training
What this is

A complete course — and a
system you own at the end.

What it's about Agentic security engineering — building the harness around a model: the part of an agent you actually control. What it sees, what it may do, how it reasons, what it remembers, how the pieces are orchestrated — you decide all of it, and build it to fit your security work rather than a generic one.
The course 19 modules · 125 lessons, each written and on video · 23 hands-on labs. 7 of those lessons are Build It Yourself pages.
What you build A complete agentic defense system in your own repository, assembled piece by piece, module by module.
Who it's for Security practitioners who want to build rather than buy. No coding background required — it starts from the judgment you already have.
How the course works

The rails come off

A lesson explains the idea, in text and on video. A concept lab lets you drive it with the outcome fixed. A system lab runs it for real, on your own key. Then Build It Yourself hands you the piece with no guided path at all.

Syllabus19 modules · 125 lessons · 23 labs
Part I What an agent is
  • Welcome to the Course
  • Unpacking the Two Terms
  • Course Goal
  • How the Course Works
  • Meet the Case
  • The Threat Hunting Kernel
  • What is Threat Hunting?
  • Agent = Model + Harness
  • How Do We Create the Harness?
  • The Three Harness Principles
  • The 9 Core Systems
  • The Golden Rule
  • Overview
  • The Agent Skeleton
  • Keys, Config, and Secrets Hygiene
  • Find the Leak Concept lab
  • State, Stage, Transition
  • The Pipeline, by Hand Concept lab
  • Our First Agent System lab
  • Prompts and the Message Protocol
  • Context Window and Memory
  • Context Window System lab
  • The Agent Loop and Control Flow
  • Build It Yourself: The Skeleton Build It Yourself
Part II What you give it
  • Overview
  • The Problem with Consuming Raw Logs
  • Find the Bad Stuff Concept lab
  • Two Primary Axes
  • Intro to Distillation
  • Candidates
  • Distillation Process Overview
  • Build It Yourself: Athanor Build It Yourself
  • Overview
  • What Is a Tool?
  • The TAO Loop
  • Policies and Boundaries
  • Interactive Triage System lab
  • Access Mechanism
  • Tool Surface Design
  • Give the Agent a Shell System lab
  • Build It Yourself: Tools Build It Yourself
  • Overview
  • MCP Introduction
  • How It Works
  • VirusTotal over MCP System lab
  • MCP is DEAD
  • Steelmanning MCP
  • Overview
  • Introduction to Skills
  • Why Use Skills
  • Skills as the Foundation of the System
  • Complete System Overview
  • Build It Yourself: The Skill Loader Build It Yourself
Part III The hunting system
  • Overview
  • Pre-Initiation
  • Initiation: Seed to Hypothesis
  • Initiation: The Laddered Plan
  • Trigger to Plan Concept lab
  • The Hunt Plan
  • Detection Node Inputs
  • Deterministic Gate Checks
  • Ajv Gates
  • Projection
  • Reflection
  • The Detection Node, Live System lab
  • Build It Yourself: Creating Skills Build It Yourself
  • Overview
  • Introduction to Context Engineering
  • What Context to Provide
  • How to Provide Context
  • Feeding the Starved Node System lab
  • Overview
  • Introduction to the Assessment Skill
  • Columnar DBs
  • Assessment Node Inputs
  • Assessment Node Outputs
  • The Assessment Node, Live System lab
  • Overview
  • Keyword vs Semantic Search
  • Intro to RAG
  • Institutional Memory, On Demand System lab
  • Overview
  • Intro to Orchestration
  • Tips on Learning Orchestration
  • Common Patterns
  • The Board, All at Once System lab
  • Orchestration Patterns Concept lab
  • Overview
  • Intro to Shared State
  • The Storage Landscape
  • Files and Logs
  • Databases as Shared State
  • Crash Night Concept lab
  • Memory Across Hunts
  • The Second Hunt Concept lab
  • Overview
  • Intro to Knowledge Graphs
  • Neo4j
  • Queries
  • Knowledge Graph Concept lab
  • Entity Resolution
  • Edge Provenance
  • Build It Yourself: The Graph Build It Yourself
  • Overview
  • Intro to Narrative Synthesis
  • Two Distinct Phases
  • Walk, Then Weave System lab
Part IV One hunt, end to end
  • One Hunt, End to End
  • The Whole Machine, Running System lab
  • Build It Yourself: The Departure Point Build It Yourself
  • What You Can Now Do
  • Where To From Here
  • Parting Thoughts
  • Feedback Node
  • The Suggestion Queue Concept lab
  • The Threat Hunter Playbook
  • Beacon Definition
  • Distillation Example
  • Distillation Pipeline Concept lab
  • Tool Security
  • Where the Poison Lands Concept lab
  • MCP Security
  • RAG Setup
  • RAG Use
  • RAG 2.0
  • Running the Labs Well
  • The Knowledge Graph Landscape
  • Graph Security
  • Six Example Interfaces
  • Candidate Types in Detail
  • Skill: initiate-hunt
  • Skill: hunt-c2-over-https
  • Skill: assess-severity
  • Skill: assess-behavioral-context
  • Skill: assess-campaign-match
  • Object: HuntTrigger
  • Object: InitiationJudgment
  • Object: HuntPlan
  • Object: HuntCoverageEntry
  • Context: Asset Record
  • Context: Incident History
  • Context: Campaign Profile
  • Context: Compliance Baseline
  • Contract: DetectionFinding
  • Contract: AssessmentFinding
  • Prompts: Detection Engagement
  • Prompts: Assessment Engagement
  • Scorer: beacon
Key

Every lesson comes as both written text and video. Labs are hands-on activities, not videos.

What you'll walk away with

A working system

Security data goes in one end. A written verdict, with the evidence behind it, comes out the other. You build every part of it yourself.

The case
One intrusion,
end to end.

An AI assistant hallucinates a package; an attacker publishes it first; a quiet beacon starts hiding in a busy network. You carry this one intrusion from raw telemetry to a grounded, evidence-cited report — through every system you build along the way.

One case rather than a catalogue, and that is the deliberate part. A pile of samples trains you to recognise what you have already seen. Carrying a single investigation the whole way is the only way to practise the hard part — deciding what matters on incomplete evidence, and then defending the call.

It is also what makes the system measurable. Every piece you build meets the same evidence, so you can see exactly what each one added — a comparison you never get by switching datasets each module. And the case is built so that the obvious answer is the wrong one.

Who decides

There's a difference between being handed the system and having built it. Handed one, you work inside whatever it allows.
Having built one, you decided what it allows.

Learn to build now, and you won't just adapt to the agentic era. You'll help define it.

The instructor
Faan Rossouw

Faan Rossouw

Security Researcher

Faan has taught thousands of defenders how to find adversaries in network and endpoint telemetry. He sees the agentic era as a genuine inflection point for security — and built AionSec to give defenders the discipline to meet it.

Speaker & trainer at
Wild West Hackin’ FestNorthSec — MontréalBSides MontréalHackfest — Québec CityAntiSyphon Training
Read the story
The future is already here
it's just not evenly distributed.
—  William Gibson
What students say
"

One of the best training classes I've taken in years. As someone who has been using Agentic AI on a daily basis since late last year, I can confidently say this class is for all levels. The labs have a great flow. I paid for this class myself and I'm glad that I did.

Jack A.· Security Analyst
"

Faan's in-depth knowledge and his amazing way of explaining things in the KISS format makes complex topics genuinely accessible. I highly recommend his trainings and will definitely be attending more sessions.

Amarjit L.· Threat Emulation Lead
"

I've attended all of Faan's workshops, and you can tell he's passionate about what he's talking about. I'd participate in any of Faan's trainings with my eyes closed.

Kelly A.
"

It's a rare pleasure to encounter a teacher with the alacrity, patience, and capacity to package such dense subject matter in such an accessible format as Faan.

Anthony A.· Senior IT System Engineer
"

The course is clear, well-structured, and presented with a strong, confident grasp of the material. If you want to learn agentic AI and apply it to security in a methodical and hands-on way, he's someone who can genuinely help you deepen your understanding and elevate your practice.

Marc-Andre L.· Cybersecurity Advisor
"

Each lesson is well designed to bring students of all levels up to speed and make complex concepts digestible. His experience and passion impart a contagious desire for learning—fun and thoughtful while maintaining lightheartedness through high-level technical material.

Miles G.· Penetration Tester
"

Very well presented. I would sign up for any future courses by Faan in a heartbeat.

Chris S.· Security Engineer
"

Your passion for this is obvious, and it made the practical stuff actually stick. Thanks, Faan.

Hermon W.· Network Threat Hunter
Start building

The whole system, built end to end.

One payment. Everything below is yours to keep.

The course

19 modules, 125 lessons (each written and on video), and 23 hands-on labs.

The working repository

A complete pre-built harness you configure, run against your own telemetry, and extend as you learn.

Lifetime access

Access while AionSec operates and supports this course, with material course updates included at no extra course fee.

A private community

A space to connect with other defenders building agentic systems.

Monthly live Q&A

Bring your questions, your environment, your edge cases.

14-day refund

No questions asked. If it is not what you expected, you get your money back.

$499
one-time · lifetime
Frequently asked

Both end up inside it, but neither alone is the point. You build defensive systems that use an agentic layer — and the moment your system reasons with models, they're part of your attack surface, while AI-augmented adversaries are already table stakes. The course teaches the whole system, end to end.

No. The repository ships with pre-built components you configure, run, and extend. The focus is architecture and judgment, not software development.

Model-agnostic — works with frontier APIs all the way down to a locally-run open-weight model. Bring your own key (free options work).

Basic familiarity with security-operations concepts and a willingness to get hands-on. The course walks you through setup.

No — a one-time $499 purchase. Lifetime access means access while AionSec continues to operate and support this course. Material updates to this course are included without another course fee; separately sold courses and third-party or API costs are not included. If the course is permanently discontinued, you will receive reasonable advance notice and an opportunity to retain materials AionSec can legally and technically provide.

Yes. If you're not satisfied within 14 days of purchase, contact us for a full refund.

Threat hunters, SOC analysts, detection engineers, and blue-team leads ready to build, not just adopt.

The future belongs to those who build.