Crimson Academy
Forge your future. Enhance your expertise. Twenty-four online, self-paced courses in cybersecurity, IT and programming, taught by working operators. Level One assumes no prior experience; the catalog runs through to threat hunting, penetration testing and hypervisor security.
Background
Most security courses assume the student already knows what a process is, what a subnet mask does, and why anyone would open a terminal. That assumption filters out a large share of the people who want into the field, in week one, over prerequisites nobody listed.
Level One assumes none of it. The catalog then continues through programming and automation, defensive operations, offensive tradecraft, and the cloud and hypervisor layers where a growing share of intrusions now occur.
The academy also supplies PenCrimson's own bench. The curriculum is drawn from what the consulting and product teams need people to know, which is why Track 05 covers the same hypervisor and control-plane material TensorOne was built to defend.
Course catalog
Start at whichever level fits. Foundations requires nothing; every track above it states what it expects you to have already.
Track 01 · Foundations
Everything the rest of the catalog assumes. If you have never used a terminal, never configured a network interface and are not sure what a kernel does, this is the entry point.
Linux Fundamentals
Level OneGet hands-on with Linux. Your essential first step to mastering the open-source power behind cybersecurity. Covers the filesystem, permissions, processes, package management and the shell.
Windows Fundamentals
Level OneMaster core Windows skills. An essential first step into the world of IT and cybersecurity. Covers the registry, services, event logs, users and groups, and introductory PowerShell.
Networking Fundamentals
Level OneMaster the language of the internet. Understand how the world connects, starting with network essentials: the OSI model, TCP/IP, DNS, DHCP, routing, and reading a packet capture.
Prepares for CompTIA Network+Computing & Hardware Essentials
Level OneWhat the machine does underneath the operating system. CPU, memory, storage, the boot process, and an introduction to virtualization.
Prepares for CompTIA A+Command Line & Shell Basics
Level OneWorking fluently at the prompt on both platforms. Navigation, pipes and redirection, text processing, remote sessions over SSH, and introductory scripting.
Track 02 · Programming & Automation
Tooling and automation for security work. An analyst who can write a short script handles volumes of work that are otherwise manual.
Git & Version Control
Level OneBranches, merges, history and collaboration. A prerequisite for the rest of this track.
Python for Security
Level TwoPython from syntax through the libraries security work relies on: parsing logs, calling APIs, handling structured data, and packaging small tools for reuse.
Bash & PowerShell Automation
Level TwoAutomating administration and investigation on both platforms. Scheduled execution, remote execution, log triage, and writing scripts safe to run against production.
Web Technologies, HTTP & APIs
Level TwoRequests and responses, sessions and tokens, REST and JSON, TLS, and the browser security model. Prerequisite for Web Application Security in Track 04.
Track 03 · Defensive Operations
Detecting an intrusion, judging whether it matters, and ending it. This track maps most directly to a first role in a security operations centre.
Security Essentials
Level TwoThreats and threat actors, the CIA triad, applied cryptography, identity and access management, risk, and the control families that address each.
Prepares for CompTIA Security+Log Analysis & SIEM Fundamentals
Level TwoLog sources across Windows, Linux, network and cloud; normalization and parsing; and writing queries and detections that produce a workable alert volume.
Endpoint Detection & Response
Level TwoWhat EDR observes and what it misses. Process trees, persistence mechanisms, living-off-the-land binaries, and containment procedure.
Incident Response Fundamentals
Level TwoThe full lifecycle: preparation, identification, containment, eradication, recovery, and the post-incident write-up. Includes running a tabletop exercise.
Digital Forensics Essentials
Level ThreeAcquiring and examining evidence without altering it. Disk and memory imaging, filesystem and registry artifacts, timeline reconstruction, and chain of custody.
Threat Hunting
Level ThreeHypothesis-driven hunting in the absence of an alert. Constructing and testing a hypothesis, pivoting through telemetry, and converting a confirmed hunt into a standing detection.
Track 04 · Offensive Operations
Taught for defenders as well as testers. Every course runs inside lab environments the student is authorized to attack; scope, authorization and the applicable law are covered before any tooling.
Ethical Hacking Fundamentals
Level TwoMethodology, scope, rules of engagement and the legal framework, then reconnaissance, enumeration, exploitation and post-exploitation as a repeatable process.
OSINT & Social Engineering
Level TwoOpen-source reconnaissance, pretexting and phishing mechanics, and the organizational controls that reduce exposure to both.
Network Penetration Testing
Level ThreeAn internal network end to end: scanning, service exploitation, credential capture and relay, pivoting, privilege escalation, and client-ready reporting.
Web Application Security
Level ThreeInjection, broken authentication, access control failures, SSRF and deserialization, identified manually and then remediated in code.
Active Directory Attack & Defense
Level ThreeDomain enumeration, Kerberos abuse, delegation, ACL-based privilege paths and forest-level compromise, each paired with its hardening measure.
Track 05 · Cloud & Infrastructure
The infrastructure layer PenCrimson's own product was built to defend. Most curricula stop at the endpoint.
Cloud Security Fundamentals
Level TwoThe shared responsibility model across the major providers: identity and permissions, network boundaries, storage exposure, logging, and the misconfigurations behind most cloud incidents.
Virtualization & Hypervisor Security
Level ThreeVMware, Proxmox, Nutanix and KVM from the defender's position. Control-plane access, management network exposure, guest isolation, and detecting an intruder who has reached the hypervisor.
Containers & Kubernetes Security
Level ThreeImage supply chain, runtime isolation, RBAC, secrets handling, network policy, and the escape paths between a container, its node and the cluster.
Infrastructure as Code & Secure Deployment
Level ThreeDeclarative infrastructure, policy as code, secrets management, and placing security checks inside a deployment pipeline.
Where to start
The most common admissions question. The answer depends on what you already do.
Capstone and placement
Every track ends in a scoped, graded engagement against a live lab environment.
The capstone produces the artifact the job produces: an incident report, a penetration test report, a detection package, or a hardened build with its justification. The student keeps it and can show it to an interviewer, which a completion badge does little to substitute for.
Students who finish an operator-level track are routed to the rest of PenCrimson where there is a fit. The consulting desk, the Cerebro operator pool and the TensorOne engineering team all recruit from people whose work we have already assessed.
Enrollment
Tell us where you are starting from and what you want to be doing in a year. We will tell you which track to open first, and if the honest answer is that you do not need us, we will tell you that instead.