Back to Trainings
    Hands-on · Next batch not scheduled

    Offensive EKS & GKE: Breaking & Defending Managed Kubernetes

    Break EKS and GKE through registry and IAM misconfigurations, then defend with IRSA, Workload Identity, Kyverno, Tetragon and Falco. Compare the two clouds' managed Kubernetes attack surface side by side, and leave with policy-as-code guardrails for both.

    Format
    Online, live
    Labs
    Browser-based
    Next batch
    Not scheduled
    Run it for my team

    We will write once, when a date is set.

    Outline coming soon

    We are writing the lab-by-lab outline for this one. Join the waitlist and you get it as soon as it is published, along with the dates.

    Read the prerequisites before you book.

    Some trainings require you to bring your own cloud account (AWS, GCP, or both) with billing enabled and admin privileges. Labs will not run without it, so confirm you meet every prerequisite below before the session.

    Hard requirement for corporate laptops: admin permission to install tools, endpoint security and antivirus disabled, and the required lab domains not blocked on your network. Confirm this with your IT team before you register - troubleshooting a locked-down laptop mid-session is not possible.

    How our trainings run

    • Live and instructor-led, with the trainers in the room rather than a recording.
    • Labs run in the browser. Nothing to install, and no fight with a corporate laptop.
    • Attack first, then fix. Every exploited flaw is followed by the control that stops it.
    • You keep the material and a certificate of completion.

    Who runs it

    Anjali Shukla

    Anjali Shukla

    Senior Security Engineer · Black Hat and Nullcon trainer

    Founder, Container Security Village. OWASP EKS Goat lead. AWS Community Builder. Women Influencer in Cloud Security, CSA Bangalore 2023. Leads the W3-CS Bengaluru chapter.

    Divyanshu Shukla

    Divyanshu Shukla

    Senior Security Engineer · Offensive cloud and product security

    Co-lead, OWASP EKS and GKE Goat. Author of Burp-o-mation. AWS Community Builder. CVEs reported to Airbnb, Google, Microsoft, AWS, Apple and Samsung.

    Running this training for a team? See corporate training. Want something customised? Talk to us.

    Want a seat when it runs?

    This batch is not scheduled yet. Join the waitlist and we will write the moment a date is set.

    Support Our Work

    Subscribe, like, and share our videos.

    No Spam. Only updates.