Back to Trainings
    Hands-on · Next batch not scheduled

    Offensive Container Security

    Break out of a container, then close every door you just walked through - namespaces, capabilities, and the image layers attackers dig through.

    Delivered as a workshop at:

    BSides Jaipur 2026, pre-conference workshopBSides Coimbatore, Attacking and Defending Containers

    What you'll do

    9 labs and 7 theory sessions across 7 sections. Theory appears where it is needed for the next lab, not as a lecture block.

    Containers are the unit almost everything ships in now, and most of their security lives in defaults nobody set on purpose. This workshop works through those defaults from both sides.

    You start with what a container actually is against a virtual machine, how an image is built and delivered, and what the host boundary really guarantees. Then you cross it: host mounts, privileged containers and Linux capabilities. The rest is closing what you opened, with static analysis, CVE scanning, an SBOM, and a set of secure defaults you can take back.

    1.Setup

    • LabSet up a GitHub Codespace

    2.Foundations

    • TheoryContainers and virtual machines
    • TheoryImages and running containers
    • TheoryDockerfile
    • TheoryDocker architecture
    • LabDockerfile static analysis
    • LabDocker Compose basics

    3.Image build and delivery

    • TheoryRegistry and image lifecycle
    • LabSlim Python images

    4.Runtime risk

    • TheoryThe host boundary
    • LabAttacking host mounts and privileged containers
    • LabAttacking Linux capabilities

    5.Image audit

    • TheoryImage CVE scanners
    • LabTrivy image scan

    6.Supply chain

    • LabSBOM with Syft and Grype

    7.Hardening

    • LabSecure container defaults

    Work through it yourself

    The full workshop material is public. Work through it at your own pace, or use it to revisit the labs after a session.

    containersecurity.peachycloudsecurity.com →

    How our trainings run

    • Live and instructor-led, with the trainers in the room rather than a recording.
    • Labs run in the browser. Nothing to install, and no fight with a corporate laptop.
    • Attack first, then fix. Every exploited flaw is followed by the control that stops it.
    • You keep the material, the recording, and a certificate of completion.

    Who runs it

    Anjali Shukla

    Senior Security Engineer · Black Hat and Nullcon trainer

    Founder, Container Security Village. OWASP EKS Goat lead. AWS Community Builder. Women Influencer in Cloud Security, CSA Bangalore 2023. Leads the W3-CS Bengaluru chapter.

    Divyanshu Shukla

    Senior Security Engineer · Offensive cloud and product security

    Co-lead, OWASP EKS and GKE Goat. Author of Burp-o-mation. AWS Community Builder. CVEs reported to Airbnb, Google, Microsoft, AWS, Apple and Samsung.

    Want a customised cloud native security course for your team? Contact us.

    Support Our Work

    Subscribe, like, and share our videos.

    No Spam. Only updates.