🚀 Submit a Challenge — SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

Defensive DevOps Workshop

Master advanced exploitation and defensive techniques to build hardened cloud native infrastructure — containers, AWS, and Kubernetes, hands-on.

terminal — workshop lab
$ git clone devops-lab.git$ make exploit✗ Cluster compromised: exposed kubelet$ vim k8s/hardening.yaml$ make test✓ All security tests passed
Why this workshop

About the Workshop

Cloud native infrastructure is changing rapidly. It is difficult to keep up with the latest changes, let alone secure them. Too often, infrastructure is built with default configurations that are open to security attacks.

What you will learn

In this attack and defence workshop, we master skills in finding security misconfiguration in AWS, Kubernetes and Docker. We learn the root causes behind these misconfigurations. We go one step further and attack the weaknesses to understand the impact of each and every insecure configuration. We follow best industry practices to harden the infrastructure. We learn how to actively monitor for insecure configurations in CICD.

At a glance

  • For: DevOps engineers, Test engineers, Software engineers, Tech leads, and Penetration testers
  • Technology: Terraform, Docker, Kubernetes, AWS
  • Duration: 4 half-days
  • Delivery: Live online led by Dr. Pedram Hayati
Curriculum

Workshop Modules

A subset of topics is selected based on participants’ skill level and the available class time.

Module 1: Introduction

A quick introduction to cloud infrastructure security and tooling.

  • 4C's of Cloud Native Security: Code, Container, Cluster, and Cloud

  • Why we have many insecure environments

  • Defence in depth

  • Least privileges

  • Quick introduction to Terraform

Module 2: Rapid Threat Modelling

Build a rapid, effective and actionable threat model early during development

  • Trust boundary analysis

  • Five + three threat actors

  • Discover threats

    • Common insecure assumptions that are exploited

    • Rapid Threat Modelling

    • STRIDE

    • SecDim's Threat Thinking Matrix

  • Build a threat model in an attack and defence game

  • Hack your own program exploitation lab

Module 3: Attack and defend containers

Containers are the second layer of defence in cloud native security. Learn how to identify, exploit and harden insecure containers.

  • Docker-in-docker exploitation

  • Compromise host via insecure container

  • Kernel namespaces and capabilities

  • Privileged containers and RCE

  • Root containers vs root in the container

  • Insecure default container capabilities

  • SUID binaries in container

  • Hardening containers

  • Container security scanning in CICD

Module 4: Attack and defend AWS services

Secure configuration of AWS resources is complex and can be easily overlooked. Learn how an attacker can exploit various AWS services to achieve privilege escalation or remote command execution. Learn to build hardened Terraform deployments that eliminate insecure configurations.

  • AWS IAM at the heart of security issues

  • IAM rollback

  • IAM assume role

  • IAM attachment

  • Malicious SQS queue

  • Insecure Lambda

  • Misconfigured S3 bucket

  • Unsegregated SNS

  • EC2 and SSRF

  • Terraform AWS hardening best practices

  • AWS security scanning in CICD

Module 5: Attack and defend Kubernetes

Kubernetes cluster components do not come secure by default. Learn how an attacker can exploit default deployments to achieve remote command execution. Learn how to build hardened deployments.

  • Privileged container in pod

  • Insufficient authorisation and authentication

  • Resource Exhaustion by a malicious service

  • Insecure Pod policies

  • Insecure Network policies

  • Harden k8s components

  • K8s security scanning in CICD

What is included?

  • Step-by-step delivery by a highly qualified instructor
  • Large collection of self-paced git-based labs
  • Access to an exclusive support forum
  • Certificate of completion
  • Full access to workshop content

Limited offer

You will also get:

  • Access to Learn and Play platforms
  • Practice schedule and mentoring
  • Standard pathway program
  • Assessment of your practices
More than a workshop

A Three-Month Pathway, Not a One-Off

We forget almost 60% of newly acquired information within a week. You get a practice schedule and mentorship during a three-month pathway, so secure software engineering becomes your habit.

SecDim standard three-month pathway program
Workshop

Reserve Your Seat Today

Our workshops are offered only a few times a year — don't miss out. Get in touch with our team to reserve your seat and confirm workshop details.