Defensive DevOps Workshop
Master advanced exploitation and defensive techniques to build hardened cloud native infrastructure — containers, AWS, and Kubernetes, hands-on.
About the Workshop
Cloud native infrastructure is changing rapidly. It is difficult to keep up with the latest changes, let alone secure them. Too often, infrastructure is built with default configurations that are open to security attacks.
What you will learn
In this attack and defence workshop, we master skills in finding security misconfiguration in AWS, Kubernetes and Docker. We learn the root causes behind these misconfigurations. We go one step further and attack the weaknesses to understand the impact of each and every insecure configuration. We follow best industry practices to harden the infrastructure. We learn how to actively monitor for insecure configurations in CICD.
At a glance
- For: DevOps engineers, Test engineers, Software engineers, Tech leads, and Penetration testers
- Technology: Terraform, Docker, Kubernetes, AWS
- Duration: 4 half-days
- Delivery: Live online led by Dr. Pedram Hayati
Workshop Modules
A subset of topics is selected based on participants’ skill level and the available class time.
Module 1: Introduction
A quick introduction to cloud infrastructure security and tooling.
4C's of Cloud Native Security: Code, Container, Cluster, and Cloud
Why we have many insecure environments
Defence in depth
Least privileges
Quick introduction to Terraform
Module 2: Rapid Threat Modelling
Build a rapid, effective and actionable threat model early during development
Trust boundary analysis
Five + three threat actors
Discover threats
Common insecure assumptions that are exploited
Rapid Threat Modelling
STRIDE
SecDim's Threat Thinking Matrix
Build a threat model in an attack and defence game
Hack your own program exploitation lab
Module 3: Attack and defend containers
Containers are the second layer of defence in cloud native security. Learn how to identify, exploit and harden insecure containers.
Docker-in-docker exploitation
Compromise host via insecure container
Kernel namespaces and capabilities
Privileged containers and RCE
Root containers vs root in the container
Insecure default container capabilities
SUID binaries in container
Hardening containers
Container security scanning in CICD
Module 4: Attack and defend AWS services
Secure configuration of AWS resources is complex and can be easily overlooked. Learn how an attacker can exploit various AWS services to achieve privilege escalation or remote command execution. Learn to build hardened Terraform deployments that eliminate insecure configurations.
AWS IAM at the heart of security issues
IAM rollback
IAM assume role
IAM attachment
Malicious SQS queue
Insecure Lambda
Misconfigured S3 bucket
Unsegregated SNS
EC2 and SSRF
Terraform AWS hardening best practices
AWS security scanning in CICD
Module 5: Attack and defend Kubernetes
Kubernetes cluster components do not come secure by default. Learn how an attacker can exploit default deployments to achieve remote command execution. Learn how to build hardened deployments.
Privileged container in pod
Insufficient authorisation and authentication
Resource Exhaustion by a malicious service
Insecure Pod policies
Insecure Network policies
Harden k8s components
K8s security scanning in CICD
What is included?
- Step-by-step delivery by a highly qualified instructor
- Large collection of self-paced git-based labs
- Access to an exclusive support forum
- Certificate of completion
- Full access to workshop content
A Three-Month Pathway, Not a One-Off
We forget almost 60% of newly acquired information within a week. You get a practice schedule and mentorship during a three-month pathway, so secure software engineering becomes your habit.

Reserve Your Seat Today
Our workshops are offered only a few times a year — don't miss out. Get in touch with our team to reserve your seat and confirm workshop details.