Peachycloud Security — hands-on AWS, GCP and Kubernetes security training
Built by the Shukla Duo (Anjali & Divyanshu), leads of the
OWASP EKS Goat and OWASP GKE Goat projects.
We teach cloud security by attacking and defending real infrastructure
— not slides.
Anjali founded Kubernetes Village, leads OWASP EKS Goat, and is
a recognised AWS Community Builder. We present
OWASP EKS Goat: Hands-On AWS EKS Security at
Black Hat USA 2026 Arsenal, and have run Arsenal sessions at
Black Hat Europe. We volunteer at Cloud Village at DEF CON.
We also host Container
Security Village at the Seasides conference in Goa — a
dedicated track where Kubernetes and containers meet security, now in its second
edition — and deliver the EKS Goat: AWS EKS Security
Masterclass there as a full-day training.
Start here
- Video tutorials — a chapter-by-chapter AWS EKS
Security Masterclass built on OWASP EKS Goat, plus standalone walkthroughs on
IAM exploitation, WAF bypass, container scanning and SBOM tooling.
- Browse by topic — AWS, GCP, Kubernetes,
containers, supply chain, DevSecOps, AI security.
- Cloud security engineer roadmap
— what to learn, in what order.
Free tools, no signup
- IaC Security Scanner — checks Terraform,
Kubernetes manifests, Dockerfiles and CloudFormation against 200+ rules. Runs
entirely in your browser; your files are never uploaded anywhere.
- Exposed Files Scanner — find
sensitive files reachable on a host.
Open source
OWASP EKS Goat and OWASP GKE Goat are
deliberately vulnerable Kubernetes environments for practising attack and
defence. Alongside them: EKSi-lite, Very Vulnerable Lambda Application, and
Awesome Cloud Security Interview.
All projects ·
GitHub
Where we have spoken
Black Hat USA Arsenal 2026, Black Hat Europe Arsenal (2023, 2025), Nullcon
(2021–2024), BRUCON 2024, OWASP AppSec Days Singapore 2025, CSA Summit
2024, Kubernetes Security Bangalore 2025, Seasides Goa 2025, c0c0n, and BSides
Bangalore, Ahmedabad and Singapore.
Full list of talks
Interview preparation
Cloud security interview questions and scenarios covering AWS and GCP concepts,
Kubernetes RBAC, threat modelling and incident response.
Interview guide
Training for teams
Corporate training for security and platform teams, and a live bootcamp covering
AWS, GCP, Kubernetes, containers and DevSecOps.
Corporate training ·
Live bootcamp ·
Talk to us
Writing
Write-ups on cloud attack paths, WAF bypasses, CTF walkthroughs and threat
modelling. Read the blog
YouTube ·
GitHub ·
All links ·
hello@peachycloudsecurity.com