Back to All Events

Agentic AI-aided Kubernetes Attack and Defense (SEPT26-27)


  • secwest.net Vancouver Canada (map)

Course Details

Number of Days: 2

Attendance: In-Person Only

Details below last updated: August 31/2026

 

Description

Learn how to use agentic AI to aid you as you attack and defend Kubernetes, Linux, and containers from Jay Beale, who has led development of the Kubernetes CTF at DEF CON, Bastille Linux, the Center for Internet Security's first Linux security benchmark, and the open source Kubernetes attack tool: Peirates. In this fully hands-on course, we’ll give you access to a computer in our cyber range, complete with an agentic AI framework, Kubernetes clusters, and capture the flag virtual machines, which you will attack and defend. You’ll get to keep the agentic AI framework, Kubernetes clusters and virtual machines. During the class, you’ll also have access to temporary cloud-based Kubernetes clusters.

This well-reviewed training focuses on giving you practical attack skills from real penetration tests, coupled with solid defenses to break attacks. We'll create an agentic AI platform on our machines, creating skills and tools to allow our agents to enumerate a cluster, analyze configuration weaknesses, and recommend attack paths. Every topic in the class has a long attack exercise, where you will first compromise a Kubernetes cluster or application, and a matching short defense exercise, where you will use new skills to break that attack, confident that it will break other attacks.

This class is more than 50% hands-on, where you get a real concept background, but then learn by doing. We start by building a real, true understanding of containers, building a container without Docker or any other container runtime. We then move on to attacks on container images and registries. We see how Kubernetes orchestrates machines running containers, and then use that to learn how to attack clusters at every level.

Before we let AI agents help, we'll compromise our first cluster entirely unaided, ensuring that we're building a foundational understanding of our target technology. Then we'll learn how to set up our agentic AI platform, give our agents both instructions and boundaries, and begin using them to aid our work. Over the course of the class, we'll create skills and configure tools to allow our agents to enumerate a cluster, analyze configuration weaknesses, and recommend attack paths.

Despite our use of AI, our class is geared toward building your subject matter expertise. You'll learn a host of container breakouts. From container breakout, you'll learn to use the host to take control of the Kubernetes cluster and the cloud environment. We also use containers to attack the Kubernetes control plane and the cloud APIs. By the time we're through, you will have compromised at least 7 CTF scenarios. You will also have broken attacks hands-on with the latest in container and Kubernetes security controls.

Our Kubernetes work will include: authorization settings, role-based access control, network policies, and admission controllers like pod security standards, Kyverno, and a custom admission controller that you’ll create with the assistance of AI. These will enable and enforce the powerful technologies we've learned: AppArmor, SecComp, root capability dropping, and filesystem controls. We'll see how both on-prem and cloud-based clusters can be attacked, attack our own clusters, and then harden those Kubernetes clusters to break our attacks.

 

Key Takeaways

  • Attacking Kubernetes and Linux containers, using standard open source tools

  • Defending Kubernetes and Linux containers, using tools and techniques to break exploits

  • A deeper understanding of Kubernetes, Linux and containers

 

Target Audience

Penetration Testers, Red Teamers, Detection Analysts, DevOps engineers, Kubernetes Platform Teams, System administrators, SecOps engineers, Site Reliability Engineers, Kubernetes cluster administrators and architects, IT Security professionals

 

Audience Skill Level

Intermediate/Advanced

 

Student Requirements

Students should bring a working understanding of Linux

 

What Students Should Bring

Students should have a basic working understanding of Linux and comfort with a Linux command line.

 

What Students Will Be Provided With

Students will be given access to a cyber range including a Kali Linux-based attack system, virtual machines, and Kubernetes clusters.

 

About the Instructor: Jay Beale

Jay Beale is CTO and CEO for InGuardians. He works on Kubernetes, Linux and Cloud-Native security, both as a professional threat actor and an Open Source maintainer and contributor. He's the architect of the open source Peirates attack tool for Kubernetes and Bustakube CTF Kubernetes cluster. Jay helps create and run DEF CON's Kubernetes CTF and previously co-led the Kubernetes project's Security Audit Working Group. Since 2000, he has led training classes on Linux & Kubernetes security at public conferences and in private training. Jay can't seem to stop running and, unrelatedly, enjoys talking with people about ADHD and neurodiversity.

 
 
Previous
Previous
September 26

Applied Physical Attacks: Rapidly Prototyping Hardware Implants

Next
Next
September 28

Building an Advanced LLM-Driven Vulnerability Scanning Pipeline for Your Code