Back To Schedule
Thursday, May 23 • 11:05 - 11:40
DIY Pen-Testing for Your Kubernetes Cluster - Liz Rice, Aqua Security

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
See how to use kube-hunter to run penetration tests on your Kubernetes clusters, and reveal misconfigurations that might leave you open to attack!

Kube-hunter is an open source tool that simulates what a hacker might do when trying to attack a deployment.

We’ll discuss the motivations behind the project, and some interesting aspects of how it is implemented.

There will be plenty of demos, including:
- Testing for the basics, like an unsecured Kubelet API
- Simulating an attack from within a compromised container
- Re-using credentials from a compromised container

You'll need a basic understanding of Kubernetes components, and with using curl to issue API requests.

You’ll leave this talk ready to test your own cluster, and with new insights into the possible routes that an attacker might attempt. Perhaps you’ll even be inspired to submit a new Hunter to the project!

avatar for Liz Rice

Liz Rice

VP Open Source Engineering, Aqua Security
Liz Rice is the Technology Evangelist with container security specialists Aqua Security, where she works on container-related open source projects. She was Co-Chair of KubeCon + CloudNativeCon 2018 in Copenhagen, Shanghai & Seattle.She has a wealth of software development, team, and... Read More →

Thursday May 23, 2019 11:05 - 11:40
Hall 8.0 B1