Back to Trainings
    Hands-on · Next batch not scheduled

    Practical Kubernetes Attack Defense Training

    Break a cluster, then harden it. Container escapes, RBAC and cluster enumeration, followed by network policy, admission control, service mesh and runtime detection. Everything runs in the browser.

    Container escapesRBACCluster enumerationNetwork policyAdmission controlIstio mTLSVaultFalcoCIS benchmarksThreat modelling
    See the full outline ↓
    Format
    Online, live
    Labs
    50 across 13 sections
    Next batch
    Not scheduled
    Run it for my team

    We will write once, when a date is set.

    About this training

    Kubernetes moves the attack surface. The application is only one way in, and the cluster around it brings service accounts, RBAC, admission control, a container runtime and a flat network that most teams inherit rather than design. This training works through that surface from both sides.

    You start in Docker, because a container escape is a Linux problem before it is a Kubernetes one: namespaces, cgroups, capabilities and what a mounted socket really grants. From there you compromise a workload through a vulnerable application, enumerate the cluster from inside the pod you landed in, cross namespace boundaries to reach secrets, and escape the container through privileged mode, hostPath, hostPID, hostNetwork, hostIPC and the runtime socket.

    The second half closes what you opened. You scan images and manifests, audit the cluster against CIS with kube-bench and Kubescape, enforce network segmentation and admission policy with Gatekeeper, put mTLS in place with Istio and then attack it, move secrets into Vault, tighten RBAC and service account tokens, apply Pod Security Standards, and watch runtime behaviour with Falco. It closes with STRIDE threat modelling of a cluster.

    Who this is for

    Does one of these read like your own week?

    • You run workloads on Kubernetes and have never attacked your own cluster.
    • You own the platform and inherited its RBAC, network policy and admission config from someone else.
    • You review Kubernetes manifests and want to know which findings actually chain into a compromise.
    • You are moving into cloud native security from dev, ops or SRE and need the attack path end to end.
    • You can drive kubectl and read YAML, and want the security layer on top of that.
    • You run containers day to day and want to go from container security into what changes once they are orchestrated by Kubernetes.

    If so, this training is for you.

    What you’ll do

    50 labs and 12 theory sessions across 13 sections. Theory appears where it is needed for the next lab, not as a lecture block.

    01Cluster setup

    • labSetup Kubernetes Cluster

    02Introduction to Docker

    • labDocker Fundamentals and Container Basics
    • theoryWorking of Docker
    • labDocker Networking
    • labResource Limits with Namespaces and Cgroups
    • labManaging Secrets in Containers

    Static Analysis of Docker Containers (SAST)

    • labExploiting Secrets in Docker
    • labAuditing Docker Host Security Configuration

    03Kubernetes Fundamentals

    Kubernetes Architecture

    • theoryKubernetes Deployments and Services

    OWASP Kubernetes Top 10 (2025)

    • labKubernetes Deployments and Services

    Kubernetes Terminologies

    • labCluster Components Overview

    Pod Types and Controllers

    • labWorking with Pod Controllers

    Linux Basics

    • labContainer Isolation Mechanisms

    04Attacking Kubernetes

    • labSetting Up Intentionally Vulnerable Workloads
    • labCommand Injection to Container Compromise
    • labReconnaissance Inside a Compromised Container
    • labDiscovering Cluster Resources and Permissions
    • labStealing Secrets Across Namespace Boundaries

    05Container Breakout Techniques

    • labPrivileged Container Escape
    • labEscaping via hostPath Volumes
    • labProcess Namespace Escape with hostPID
    • labNetwork Namespace Bypass with hostNetwork
    • labIPC Namespace Exploitation with hostIPC
    • labContainer Runtime Socket Exploitation

    06Kubernetes Networking

    Kubernetes Services

    • labInternal Cluster Communication
    • labNode Port Exposure
    • theoryLoadBalancer Service Concepts
    • labExternal Service Mapping

    Ingress Controllers

    • labIngress Fundamentals with Path-Based Routing

    07Automated Scanning and Audit

    Security Standards

    • theoryCIS Kubernetes Benchmark Assessment
    • labValidating Cluster Security with CIS Standards
    • theoryCluster Security Scanning with Kubescape
    • labRuntime Cluster Security Assessment

    Vulnerability Scanning

    • theoryContainer Image Scanning with Trivy
    • labVulnerability Detection in Container Images
    • theoryInfrastructure as Code Analysis with Checkov
    • labStatic Analysis of Kubernetes Manifests

    RBAC Analysis

    • labRBAC Scanning Tools

    08Helm Package Manager

    Helm Fundamentals

    • labHelm Installation and Basics

    Helm Security Scanning

    • labHelm Chart Security Analysis with Checkov

    09Kubernetes Defense

    Istio Service Mesh

    • labDeploying Service Mesh for mTLS
    • labService Mesh Traffic Control
    • labIstio Security Exploitation
    • theoryNetwork Policies
    • labEnforcing Network Segmentation Rules

    Policy Enforcement

    • theoryPolicy Enforcement with OPA Gatekeeper
    • labImplementing Admission Control Policies

    10Secure Containers

    • theorySecurity Context
    • labSecurity Context
    • labRunning Non-Root Containers
    • labAllow Privilege Escalation

    11Kubernetes Hardening

    Secret Management

    • theorySecret Management with HashiCorp Vault
    • labCentralized Secret Management with HashiCorp Vault
    • labService Account Token Security

    Access Control

    • theoryRole-Based Access Control (RBAC)
    • labConfiguring Fine-Grained Access Controls
    • labService Account and RBAC Security
    • labReducing Attack Surface with Distroless Images

    Pod Security Standards

    • labEnforcing Pod Security Baselines

    12Kubernetes Monitoring

    Monitoring

    • labVisualization with Prometheus and Grafana

    Runtime Security

    • labFalco Runtime Threat Detection

    13Threat Modelling of Kubernetes Infrastructure

    Threat Modelling Fundamentals

    • labSTRIDE Threat Modeling Exercise

    Why this one

    Attack, then fix

    Every escape and misconfiguration is followed by the control that stops it, so you leave with both halves rather than a list of demos.

    A real cluster, not slides

    50 labs across 13 sections, on a cluster you break and then repair.

    Nothing to install

    The environment runs in the browser. No local cluster, no VM, no fight with a corporate laptop.

    The tools you will actually be asked about

    Trivy, Checkov, kube-bench, Kubescape, Gatekeeper, Istio, Vault, Falco, Prometheus and Grafana.

    What this training does not cover

    • Managed service internals. EKS, GKE and AKS specifics are their own trainings; this one is about Kubernetes itself.
    • Running Kubernetes in production. This is a security course, not an SRE course.
    • A finished audit of your cluster. You leave with a method and the tooling, not a report about your own environment.
    • Application security in depth. Web vulnerabilities appear only as the way into the cluster.

    What you need

    Read the prerequisites before you book.

    Some trainings require you to bring your own cloud account (AWS, GCP, or both) with billing enabled and admin privileges. Labs will not run without it, so confirm you meet every prerequisite below before the session.

    Hard requirement for corporate laptops: admin permission to install tools, endpoint security and antivirus disabled, and the required lab domains not blocked on your network. Confirm this with your IT team before you register - troubleshooting a locked-down laptop mid-session is not possible.

    • Comfort on the command line, and enough kubectl to list pods and read a manifest. No prior security experience needed.
    • A laptop with a modern browser, at least 8GB RAM, and a stable connection. Labs run in a browser-based cluster, so there is nothing to install locally.
    • A GitHub account, used to launch the lab environment.
    • On a corporate laptop, check that endpoint security, antivirus or VPN are not blocking browser access to GitHub.
    • Curiosity, and willingness to read an error rather than wait to be unblocked.

    What you keep

    Certificate of completion
    Issued after you finish the training.
    The full mdbook
    Every lab and its theory, yours to keep and repeat.
    Session recording
    The live sessions, for a second pass.
    Cluster manifests
    The vulnerable workloads and the hardened versions, to rebuild at work.
    Monthly career workshop
    A free group session, open to anyone who has attended a training.

    Who runs it

    Anjali Shukla

    Anjali Shukla

    Senior Security Engineer · Black Hat and Nullcon trainer

    Founder, Container Security Village. OWASP EKS Goat lead. AWS Community Builder. Women Influencer in Cloud Security, CSA Bangalore 2023. Leads the W3-CS Bengaluru chapter.

    Divyanshu Shukla

    Divyanshu Shukla

    Senior Security Engineer · Offensive cloud and product security

    Co-lead, OWASP EKS and GKE Goat. Author of Burp-o-mation. AWS Community Builder. CVEs reported to Airbnb, Google, Microsoft, AWS, Apple and Samsung.

    Questions

    Do I need my own cluster?

    No. The lab cluster runs in a browser-based environment we provide. You need a GitHub account and a browser.

    How much Kubernetes do I need to know?

    Enough to run kubectl and read a manifest. The fundamentals section covers architecture, workloads and controllers before anything adversarial starts.

    Is this offensive or defensive?

    Both, in that order. You attack the cluster first because the defences only make sense once you have seen what they stop.

    What do I keep afterwards?

    The full mdbook, the session recording, the cluster manifests, and a certificate of completion.

    When is the next batch?

    Not scheduled yet. Join the waitlist and we will let you know first, along with early bird pricing.

    Running this training for a team? See corporate training. Want something customised? Talk to us.

    Want a seat when it runs?

    This batch is not scheduled yet. Join the waitlist and we will write the moment a date is set.

    Support Our Work

    Subscribe, like, and share our videos.

    No Spam. Only updates.