kdigger: A Context Discovery Tool for Kubernetes Penetration Testing
Loading
0 %
Key | Action |
---|---|
K or space | Play / Pause |
M | Mute / Unmute |
C | Select next subtitles |
A | Select next audio track |
V | Show slide in full page or toggle automatic source change |
left arrow | Seek 5s backward |
right arrow | Seek 5s forward |
shift + left arrow or J | Seek 10s backward |
shift + right arrow or L | Seek 10s forward |
control + left arrow | Seek 60s backward |
control + right arrow | Seek 60s forward |
shift + down arrow | Decrease volume |
shift + up arrow | Increase volume |
shift + comma | Decrease playback rate |
shift + dot or shift + semicolon | Increase playback rate |
end | Seek to end |
beginning | Seek to beginning |
You can right click on slides to open the menu
Share this media
HLS video stream
You can use an external player to play this stream (like VLC).
HLS video streamInformation on this media
Links:
Number of views:
45 (this month: 1)Creation date:
July 6, 2022Speakers:
Mahé TardyLicense:
CC BY-SA v4Description
kdigger, short for "Kubernetes digger", is a context discovery tool for Kubernetes penetration testing. This tool is a compilation of various plugins called buckets to facilitate pentesting Kubernetes from inside a pod.
During this short session, I'll demonstrate a scenario of a multi-tenant attack in a Kubernetes cluster. I will explain the risks, see how to prevent this kind of attack and show how kdigger can speed up the discovery process of the environment.
On top of discovering a new tool, this presentation will give you an idea of how pentesters generally try to pivot in typical Kubernetes clusters
Mahé Tardy is a Security R&D Engineer at Quarkslab specializing in Kubernetes security and enjoying any new tech a bit too much.
Other media in the channel "2022"
19 views, 1 this monthClosingJuly 6th, 2022
38 views, 1 this monthDissecting NTLM EPA & building a MitM proxyJuly 6th, 2022
55 views, 1 this monthFinding Java deserialization gadgets with CodeQLJuly 6th, 2022
74 views, 2 this monthMobSF for penetration testersJuly 6th, 2022
72 views, 1 this monthImprove your Malware Recipes with CyberchefJuly 6th, 2022
249 views, 15 this monthTAPIR : Trustable Artifact Parser for Incident ResponseJuly 6th, 2022