Docker and Kubernetes Security Workshop
... > Formazioni > Docker and Kubernetes Security Workshop
Docker and Kubernetes Security Workshop
Do you want to learn how to attack and exploit containers on a Kubernetes cluster? This three-day workshop will teach you how to break out of containers and become a Kubernetes cluster admin by abusing and exploiting common misconfigurations.
During this workshop, the participants will perform various container escape scenarios in our dedicated lab environment. In addition, a vulnerable Kubernetes cluster will be available to the participants which will be attacked. Get insights in how an attacker can abuse your workloads and how to prevent configuration pitfalls when setting up your environment. This is a very interactive workshop with exercises, demonstrations and hands-on material.
Why should you attend?
- Get to know the basics of Docker and Kubernetes security
- Gain an insight in the attack surface of Docker and Kubernetes
- Learn about common security misconfigurations
- Learn to attack and exploit misconfigured containers in our lab
- Learn to attack and exploit a misconfigured Kubernetes cluster in our lab
Intended Audience
This training is suitable for:
- Pentesters
- Developers
- Students
- Security testers
- Security enthusiasts
- General security practitioners
- Anyone with an interest in Docker/Kubernetes and technical affinity
This training is devised for technical personnel. Participants may vary in skill level from no experience to novice in pentesting and working with containers or Kubernetes. A basic understanding of Linux and command line is needed. Experience with Docker or Kubernetes is not required. All basic concepts will be addressed. during the workshop as a refresher.
Required Skills and Expertise
This training is devised for technical personnel. A basic understanding of Linux command line and infrastructure is needed. Experience with Docker or Kubernetes is not required. All basic concepts will be addressed during the workshop as a refresher.
Workshop Program
In this three-day hands-on workshop, we split the day in a morning and afternoon part. Depending on your organization and the skills of the participants, the program and technical-depth of the contents can be adapted.
Required skill and expertise
A basic understanding of Linux command line and infrastructure is needed. Experience with Docker or Kubernetes is not required, as all basic concepts will be covered during the workshop.
Program
This three-day workshop combines technical theory and hands-on labs to explore Docker and Kubernetes security, from container basics to real-world attack scenarios.
Day 1: Docker Security
- Technical deep dive into Docker architecture and commands
- Common Docker misconfigurations and exploitation techniques
Hands-on container escape exercises
Day 2: Kubernetes Essentials
- Introduction to Kubernetes architecture and components
- Deploying containers in a Kubernetes cluster
- Hands-on Kubernetes setup and usage
Day 3: Kubernetes Security
- Misconfigurations in Kubernetes and RBAC issues
- Attacking a Kubernetes cluster through chained exploits
- Hands-on hacking session to gain high-level access
More Information
If you are interested in hosting this interactive and tailored training at your company, please let us know via the contact form, by telephone +31 (0)88 888 31 00 or email cybersecurity@bureauveritas.com.
Related
Crystal Box Kubernetes Pentesting
Discover how Bureau Veritas Cybersecurity's Crystal Box Kubernetes Pentesting service can help you secure the complete setup. We offer comprehensive vulnerability assessment and penetration testing for your Kubernetes configurations.
Cloud Security Training
The course gives a comprehensive overview of the OT security landscape, including new insights, threats and challenges. After the training, you will be equipped to assess and defend industrial control systems.
The top 10 Kubernetes findings of our pentesting team
Security specialist Ilona de Bruin shares the most common vulnerabilities she and her colleagues find during their Kubernetes assessments.
Perché scegliere Bureau Veritas Cybersecurity?
Bureau Veritas Cybersecurity è il vostro partner esperto in materia di sicurezza informatica. Aiutiamo le organizzazioni a identificare i rischi, rafforzare le difese e conformarsi agli standard e alle normative in materia di sicurezza informatica. I nostri servizi riguardano persone, processi e tecnologie, dalla formazione sulla consapevolezza e l'ingegneria sociale alla consulenza sulla sicurezza, la conformità e i test di penetrazione.
Operiamo in ambienti IT, OT e IoT, supportando sia i sistemi digitali che i prodotti connessi. Con oltre 300 professionisti della sicurezza informatica in tutto il mondo, uniamo una profonda competenza tecnica a una presenza globale. Bureau Veritas Cybersecurity fa parte del Bureau Veritas Group, leader mondiale nel settore dei test, delle ispezioni e delle certificazioni.