Scaling Up Offensive Pipelines
Offered By: Hack In The Box Security Conference via YouTube
Course Description
Overview
Explore the essentials of offensive pipelines and discover an innovative approach to empower red team and purple team operations in this conference talk from Hack In The Box Security Conference. Learn about the challenges solved and how to leverage an offensive CI/CD framework to automate tasks related to offensive tools weaponization. Delve into the design and implementation of a modular, self-managed, and collaborative offensive CI/CD pipeline framework that utilizes Infrastructure as Code (IaC) to fully automate deployment. Understand how the framework incorporates built-in recipes for evading host and network detections, and how it can be customized to fit specific requirements or imitate threat actor TTPs. Gain insights into the use of Gitlab CI/CD and Kubernetes clusters for building and deploying offensive tools at scale. The talk covers topics such as pipeline recipes, infrastructure scalability, Gitlab CI implementation, artifact management, reporting, and cloud cost considerations.
Syllabus
Intro
Context
Needs
Pipeline Recipe
Infrastructure
scalabs
gitlab
Demo
Gitlab CI
fetching the previous artifact
deploying the file
reports log
pipeline created
importing tools
cloud costs
Taught by
Hack In The Box Security Conference
Related Courses
Browser Hacking With ANGLEHack In The Box Security Conference via YouTube Can A Fuzzer Match A Human
Hack In The Box Security Conference via YouTube Biometrics System Hacking in the Age of the Smart Vehicle
Hack In The Box Security Conference via YouTube ICEFALL - Revisiting A Decade Of OT Insecure-By-Design Practices
Hack In The Box Security Conference via YouTube Fuzzing the MCU of Connected Vehicles for Security and Safety
Hack In The Box Security Conference via YouTube