This hands-on workshop focuses on real-world attacks and misconfiguration audits of cloud-native CI/CD systems like GitHub Actions, GitLab CI, and Bitbucket Pipelines. As organizations increasingly shift toward SaaS-based development infrastructures, CI/CD pipelines have become a prime target for attackers and a blind spot for defenders. Rapid adoption of these technologies has meant that a lot of the security precautions are thrown out of the window and insecure by default settings are in place.
This course equips attendees with both offensive and auditing skills. This enables them to compromise vulnerable pipelines, identify security misconfigurations, and understand how to harden their DevOps infrastructure. The training progresses from pipeline setup and exploitation to detection, auditing of pipeline design
The course assumes basic familiarity with CI CD and pipeline concepts. Security tooling and specific pipeline details will be covered in the course.
Streamlined begineer to intermediate knowledge enhancement coupled with realistic challenge of CI CD Environments
Don't expect to be hero from zero. we are here to support your journey and provide you enough guidance and resources that you are able to climb the ladder faster
Duration: 3 days