YoVDO

Scaling Up Offensive Pipelines

Offered By: Hack In The Box Security Conference via YouTube

Tags

Hack In The Box Security Conference Courses Cybersecurity Courses Kubernetes Courses Infrastructure as Code (IaC) Courses Offensive Security Courses

Course Description

Overview

Explore the essentials of offensive pipelines and discover an innovative approach to empower red team and purple team operations in this conference talk from Hack In The Box Security Conference. Learn about the challenges solved and how to leverage an offensive CI/CD framework to automate tasks related to offensive tools weaponization. Delve into the design and implementation of a modular, self-managed, and collaborative offensive CI/CD pipeline framework that utilizes Infrastructure as Code (IaC) to fully automate deployment. Understand how the framework incorporates built-in recipes for evading host and network detections, and how it can be customized to fit specific requirements or imitate threat actor TTPs. Gain insights into the use of Gitlab CI/CD and Kubernetes clusters for building and deploying offensive tools at scale. The talk covers topics such as pipeline recipes, infrastructure scalability, Gitlab CI implementation, artifact management, reporting, and cloud cost considerations.

Syllabus

Intro
Context
Needs
Pipeline Recipe
Infrastructure
scalabs
gitlab
Demo
Gitlab CI
fetching the previous artifact
deploying the file
reports log
pipeline created
importing tools
cloud costs


Taught by

Hack In The Box Security Conference

Related Courses

Browser Hacking With ANGLE
Hack In The Box Security Conference via YouTube
Can A Fuzzer Match A Human
Hack In The Box Security Conference via YouTube
Biometrics System Hacking in the Age of the Smart Vehicle
Hack In The Box Security Conference via YouTube
ICEFALL - Revisiting A Decade Of OT Insecure-By-Design Practices
Hack In The Box Security Conference via YouTube
Fuzzing the MCU of Connected Vehicles for Security and Safety
Hack In The Box Security Conference via YouTube