A high school student analyzing network packet captures across two monitors in a dim lab lit by screen glow and window light

Digital Defense & Forensics

Grades 10-12 · 6 units · 36 weeks · 180 one-hour periods · 180 hours of instruction

Students spend the year as security analysts at a simulated firm, working entirely inside browser-based virtual machines - real Linux and Windows systems they can attack, break, harden, and rebuild with nothing installed on school hardware. Every unit is a case: a compromised account, a vulnerable online store, a network breach in progress, a suspect's seized drive.

The skills build outward in rings: personal security and the attacker's playbook; command-line fluency and system hardening; network defense with live packet analysis; and finally applied cryptography and digital forensics. Unlike survey courses, students go hands-on with both sides - running guided penetration tests against sandboxed servers, then writing the remediation plans that close the holes they found. Python and shell scripting, plus enough SQL to truly understand injection attacks, give students automation depth most secondary programs skip.

The capstone is a full cyber-crime investigation: students image evidence, maintain chain of custody, crack the case, and present prosecutable findings. Career mapping against national cybersecurity workforce frameworks runs throughout, and everything is grounded in a strict white-hat ethical code signed in week one.

Course structure — 6 units, 6 weeks each

In every unit, weeks 1–5 build the skills and week 6 applies them in a project, with a deliverable due at the end of each day.

Unit 1

Know Your Adversary

6 weeks
Unit 2

Command Line Command

6 weeks
Unit 3

Hardening the Storefront

6 weeks
Unit 4

Reading the Wire

6 weeks
Unit 5

Break In to Lock Out

6 weeks
Unit 6

Ciphers, Evidence, and the Case

6 weeks