Opens mid-September 2026. Join the list for $100 off — $399 instead of $499. Join the list ›
Agentic Security Engineering · Course 01

Build your own
agentic defense.

One complete agentic defense system, built by you — carried through a single intrusion, from raw telemetry to a grounded report.

Speaker & trainer at
Wild West Hackin’ FestNorthSec — MontréalBSides MontréalHackfest — Québec CityAntiSyphon Training
What this is

A complete course — and a
system you own at the end.

What it's about Agentic security engineering — building the harness around a model: the part of an agent you actually control. What it sees, what it may do, how it reasons, what it remembers, how the pieces are orchestrated — you decide all of it, and build it to fit your security work rather than a generic one.
The course 17 modules · 106 lessons · 21 hands-on labs, every one written and on video. 7 of those lessons are Build It Yourself pages.
What you build A complete agentic defense system — the one this course is named for — in your own repository, assembled piece by piece, module by module.
Who it's for Security practitioners who want to build rather than buy. No coding background required — it starts from the judgment you already have.
How the course works

The rails come off

A lesson explains the idea, in text and on video. A simulation lab lets you drive it with the outcome fixed. A live lab runs it for real, on your own key. Then Build It Yourself hands you the piece with no guided path at all.

Syllabus17 modules · 106 lessons · 21 labs
Key

Every lesson and every lab comes as both written text and video.

Part I What an agent is
  • Welcome to the Course
  • Unpacking the Two Terms
  • Course Goal
  • How the Course Works
  • Running the Labs Well
  • Meet the Case
  • The Threat Hunting Kernel
  • What Threat Hunting Is — and Its Main Limitation
  • Agent = Model + Harness
  • How Do We Create the Harness?
  • The Three Harness Principles
  • The 9 Core Systems
  • The Golden Rule
  • Overview
  • The Agent Skeleton
  • Keys, Config, and Secrets Hygiene
  • State, Stage, Transition
  • Our First Agent Live lab
  • Prompts and the Message Protocol
  • Context Window and Memory
  • Context Window Live lab
  • The Agent Loop and Control Flow
  • Build It Yourself: The Skeleton Build It Yourself
Part II What you give it
  • Overview
  • The Problem with Consuming Raw Logs
  • Find the Bad Stuff Simulation lab
  • Two Primary Axes
  • Six Example Interfaces
  • Intro to Distillation
  • Distillation Candidates
  • Course Candidates
  • Distillation Process Overview
  • Beacon Definition
  • Distillation Example
  • Distillation Pipeline Simulation lab
  • Build It Yourself: Athanor Build It Yourself
  • Overview
  • What Is a Tool?
  • The TAO Loop
  • Policies and Boundaries
  • Interactive Triage Live lab
  • Access Mechanism
  • Tool Surface Design
  • Give the Agent a Shell Live lab
  • Tool Security
  • Where the Poison Lands Simulation lab
  • Build It Yourself: Tools Build It Yourself
  • Overview
  • MCP Introduction
  • How It Works
  • VirusTotal over MCP Live lab
  • MCP is DEAD
  • Steelmanning MCP
  • MCP Security
  • Overview
  • Introduction to Skills
  • Why Use Skills
  • The Threat Hunting Playbook
  • Skills as the Foundation of the System
  • Pre-Initiation
  • Initiation
  • Trigger to Plan Simulation lab
  • Detection Skill
  • Assessment
  • Narrative
  • Feedback
  • The Suggestion Queue Simulation lab
  • Build It Yourself: The Skill Loader Build It Yourself
Part III The hunting system
  • Overview
  • The Hunt Plan
  • Detection Node Inputs
  • Deterministic Gate Checks
  • Ajv Gates
  • Projection
  • Reflection
  • The Detection Node, Live Live lab
  • Build It Yourself: Creating Skills Build It Yourself
  • Overview
  • Introduction to Context Engineering
  • What Context to Provide
  • How to Provide Context
  • Feeding the Starved Node Live lab
  • Overview
  • Introduction to the Assessment Skill
  • Columnar DBs
  • Assessment Node Inputs
  • Assessment Node Outputs
  • The Assessment Node, Live Live lab
  • Overview
  • Keyword vs Semantic Search
  • Intro to RAG
  • RAG Setup
  • RAG Use
  • Institutional Memory, On Demand Live lab
  • RAG 2.0
  • Overview
  • Intro to Orchestration
  • Tips on Learning Orchestration
  • Common Patterns
  • The Board, All at Once Live lab
  • Orchestration Patterns Simulation lab
  • Overview
  • Intro to Shared State
  • Files and Logs
  • Databases as Shared State
  • Crash Night Simulation lab
  • Memory Across Hunts
  • The Second Hunt Simulation lab
  • Overview
  • Intro to Knowledge Graphs
  • The Knowledge Graph Landscape
  • Neo4j
  • Queries
  • Knowledge Graph Simulation lab
  • Entity Resolution
  • Edge Provenance
  • Graph Security
  • Build It Yourself: The Graph Build It Yourself
  • Overview
  • Intro to Narrative Synthesis
  • Two Distinct Phases
  • Walk, Then Weave Live lab
Part IV One hunt, end to end
  • One Hunt, End to End
  • The Complete Hunt Live lab
  • Build It Yourself: The Departure Point Build It Yourself
  • Where To From Here
  • Parting Thoughts
What you'll walk away with
A working system

Security data goes in one end. A written verdict, with the evidence behind it, comes out the other. You build every part of it yourself.

The case
One intrusion, end to end.

An AI assistant hallucinates a package; an attacker publishes it first; a quiet beacon starts hiding in a busy network. You carry this one intrusion from raw telemetry to a grounded, evidence-cited report — through every system you build along the way.

One case rather than a catalogue, and that is the deliberate part. A pile of samples trains you to recognise what you have already seen. Carrying a single investigation the whole way is the only way to practise the hard part — deciding what matters on incomplete evidence, and then defending the call.

It is also what makes the system measurable. Every piece you build meets the same evidence, so you can see exactly what each one added — a comparison you never get by switching datasets each module. And the case is built so that the obvious answer is the wrong one.

Who decides

There's a difference between being handed the system and having built it. Handed one, you work inside whatever it allows.
Having built one, you decided what it allows.

Learn to build now, and you won't just adapt to the agentic era. You'll help define it.

The future is already here it's just not evenly distributed.
—  William Gibson
What students say
"

One of the best training classes I've taken in years. As someone who has been using Agentic AI on a daily basis since late last year, I can confidently say this class is for all levels. The labs have a great flow. I paid for this class myself and I'm glad that I did.

Jack A.· Security Analyst
"

Faan's in-depth knowledge and his amazing way of explaining things in the KISS format makes complex topics genuinely accessible. I highly recommend his trainings and will definitely be attending more sessions.

Amarjit L.· Threat Emulation Lead
"

I've attended all of Faan's workshops, and you can tell he's passionate about what he's talking about. I'd participate in any of Faan's trainings with my eyes closed.

Kelly A.
"

It's a rare pleasure to encounter a teacher with the alacrity, patience, and capacity to package such dense subject matter in such an accessible format as Faan.

Anthony A.· Senior IT System Engineer
"

The course is clear, well-structured, and presented with a strong, confident grasp of the material. If you want to learn agentic AI and apply it to security in a methodical and hands-on way, he's someone who can genuinely help you deepen your understanding and elevate your practice.

Marc-Andre L.· Cybersecurity Advisor
"

Each lesson is well designed to bring students of all levels up to speed and make complex concepts digestible. His experience and passion impart a contagious desire for learning—fun and thoughtful while maintaining lightheartedness through high-level technical material.

Miles G.· Penetration Tester
"

Very well presented. I would sign up for any future courses by Faan in a heartbeat.

Chris S.· Security Engineer
"

Your passion for this is obvious, and it made the practical stuff actually stick. Thanks, Faan.

Hermon W.· Network Threat Hunter
Start building

The whole system, built end to end.

One payment. Everything below is yours to keep.

The course

17 modules, 106 lessons and 21 hands-on labs, every one written and on video.

The working repository

A complete pre-built harness you configure, run against your own telemetry, and extend as you learn.

Lifetime access

As the architecture evolves and models improve, the course updates with it. You keep access forever.

A private community

A space to connect with other defenders building agentic systems.

Monthly live Q&A

Bring your questions, your environment, your edge cases.

14-day refund

No questions asked. If it is not what you expected, you get your money back.

one-time · lifetime
Opensmid-September 2026
On the list$399$499

Everyone who joins before launch gets $100 off — a code issued against your signup, honoured the day the course opens.

$399 instead of $499 — everyone on the list before launch gets $100 off. No spam, ever.

Frequently asked

Both end up inside it, but neither alone is the point. You build defensive systems that use an agentic layer — and the moment your system reasons with models, they're part of your attack surface, while AI-augmented adversaries are already table stakes. The course teaches the whole system, end to end.

No. The repository ships with pre-built components you configure, run, and extend. The focus is architecture and judgment, not software development.

Model-agnostic — works with frontier APIs all the way down to a locally-run open-weight model. Bring your own key (free options work).

Basic familiarity with security-operations concepts and a willingness to get hands-on. The course walks you through setup.

No — a one-time $499 purchase. Once you're in, it's yours forever, including every future update.

Yes. If you're not satisfied within 14 days of purchase, contact us for a full refund.

Threat hunters, SOC analysts, detection engineers, and blue-team leads ready to build, not just adopt.

The future belongs to those who build.

AIONSEC Learn Agentic Security Engineering
Courses The course Join the list