Back to All Events

Agentic AI-aided Kubernetes Attack and Defense (SEPT28-29)


  • secwest.net Vancouver Canada (map)

Course Details

Number of Days: 2

Attendance: In-Person Only

Details below last updated: July 27/2026

NOTE: Content Below is NOT FINAL and subject to change.

 

Description

Learn how to use agentic AI to aid you as you attack and defend Kubernetes, Linux, and containers from Jay Beale, who has led development of the Kubernetes CTF at DEF CON, Bastille Linux, the Center for Internet Security's first Linux security benchmark, and the open source Kubernetes attack tool: Peirates. In this fully hands-on course, you'll get an x86 computer to keep, complete with an agentic AI framework, Kubernetes clusters, and capture the flag virtual machines, which you will attack and defend. You'll also get access to our cloud environment, allowing you to attack cloud-based Kubernetes clusters.

This well-reviewed training focuses on giving you practical attack skills from real penetration tests, coupled with solid defenses to break attacks. We'll create an agentic AI platform on our machines, creating skills and tools to allow our agents to enumerate a cluster, analyze configuration weaknesses, and recommend attack paths. Every topic in the class has a long attack exercise, where you will first compromise a Kubernetes cluster or application, and a matching short defense exercise, where you will use new skills to break that attack, confident that it will break other attacks.

This class is more than 50% hands-on, where you get a real concept background, but then learn by doing. We start by building a real, true understanding of containers, building a container without Docker or any other container runtime. We then move on to attacks on container images and registries. We see how Kubernetes orchestrates machines running containers, and then use that to learn how to attack clusters at every level.

Before we let AI agents help, we'll compromise our first cluster entirely unaided, ensuring that we're building a foundational understanding of our target technology. Then we'll learn how to set up our agentic AI platform, give our agents both instructions and boundaries, and begin using them to aid our work. Over the course of the class, we'll create skills and configure tools to allow our agents to enumerate a cluster, analyze configuration weaknesses, and recommend attack paths.

Despite our use of AI, our class is geared toward building your subject matter expertise. You'll learn a host of container breakouts. From container breakout, you'll learn to use the host to take control of the Kubernetes cluster and the cloud environment. We also use containers to attack the Kubernetes control plane and the cloud APIs. By the time we're through, you will have compromised at least 14 CTF scenarios. You will also have broken attacks hands-on with the latest in container and Kubernetes security controls.

Our Kubernetes work will include: authorization settings, role-based access control, network policies and service meshes, and admission controllers like pod security standards, Kyverno, and OPA Gatekeeper. These will enable and enforce the powerful technologies we've learned: AppArmor, SecComp, SELinux, root capability dropping, and filesystem controls. We'll see how both on-prem and cloud-based clusters can be attacked, attack our own clusters, and then harden those Kubernetes clusters to break our attacks. As a bonus, we start the class without any passwords for the computer - in the first exercise, you break into your computer!

 

Key Takeaways

  • Attacking Kubernetes and Linux containers, using standard open source tools

  • Defending Kubernetes and Linux containers, using tools and techniques to break exploits

  • A deeper understanding of Kubernetes, Linux and containers

 

Target Audience

Penetration Testers, Red Teamers, Detection Analysts, DevOps engineers, Kubernetes Platform Teams, System administrators, SecOps engineers, Site Reliability Engineers, Kubernetes cluster administrators and architects, IT Security professionals

 

Audience Skill Level

Intermediate/Advanced

 

Student Requirements

Students should bring a working understanding of Linux

 

What Students Should Bring

Students should have a basic working understanding of Linux and comfort with a Linux command line.

 

What Students Will Be Provided With

Students will be given a computer with virtual machines, including Kubernetes clusters.

 

About the Instructor: Jay Beale

Jay Beale is CTO and CEO for InGuardians. He works on Kubernetes, Linux and Cloud-Native security, both as a professional threat actor and an Open Source maintainer and contributor. He's the architect of the open source Peirates attack tool for Kubernetes and Bustakube CTF Kubernetes cluster. Jay helps create and run DEF CON's Kubernetes CTF and previously co-led the Kubernetes project's Security Audit Working Group. Since 2000, he has led training classes on Linux & Kubernetes security at public conferences and in private training. Jay can't seem to stop running and, unrelatedly, enjoys talking with people about ADHD and neurodiversity.

 
 
Previous
Previous
September 26

Agentic AI-aided Kubernetes Attack and Defense (SEPT26-27)