devsecops

Containers & DevSecOps

Infrastructure as Code Security: Terraform and Misconfigs

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Containers & DevSecOps

CI/CD Pipeline Attacks and Supply-Chain Risk

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Secure Code Review: A Practical Methodology

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Containers & DevSecOps

Preventing and Remediating Secrets in Source Control

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Containers & DevSecOps

Dependency Confusion and Package-Manager Security

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

SAST vs DAST vs IAST: Strengths and Blind Spots

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Containers & DevSecOps

Software Bill of Materials (SBOM) in Practice

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Detection-as-Code with Sigma and CI/CD

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Containers & DevSecOps

Docker Security Fundamentals and Hardening: From Capabilities to Rootless Containers

A practical guide to hardening Docker: Linux capabilities, seccomp, rootless mode, --privileged risks, and image scanning.
Containers & DevSecOps

Securing the Software Supply Chain: SBOM, Sigstore, and SLSA in Practice

A hands-on guide to attacking and defending the software supply chain with SBOM, cosign, Sigstore, and SLSA.
Containers & DevSecOps

Attacking CI/CD Pipelines: Exploiting GitHub Actions and Jenkins

A practical offensive and defensive walkthrough of pwn requests, PPE, secrets exfiltration, and OIDC abuse in GitHub Actions and Jenkins.
Containers & DevSecOps

Secrets Management and Hunting Leaked Secrets in Git

Hunt leaked credentials in git history with gitleaks and trufflehog, then lock them down with HashiCorp Vault.
Containers & DevSecOps

Infrastructure as Code Security: Hunting Bugs in Terraform with tfsec and Checkov

A practical guide to attacking and defending Terraform: state file secrets, drift, least privilege, and IaC scanning with tfsec and Checkov.