Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Offensive Container Security Workshop

by Anjali & Divyanshu (theshukladuo) at Peachycloud Security

Peachy Cloud Security, by The Shukla Duo

BSides Jaipur 2026 Null & BSides Coimbatore 2026

Command line first. Open source tools only.
https://containersecurity.peachycloudsecurity.com

Hands-on primer on Docker and container security for security, platform, and backend engineers who are comfortable in a Linux shell and need a shared baseline before Kubernetes or deeper cloud work. Day-to-day Docker use helps but is not assumed to be deep. The text rebuilds from how images sit on disk through review, build, runtime risk, scanning, SBOM, and hardening.

Syllabus

  • Welcome
  • Lab: Setup GitHub Codespace
  • Environment Setup
  • Lab: Workshop workspace
  • Foundations
    • Theory: Containers and virtual machines
    • Theory: Images and running containers
    • Theory: Dockerfile
    • Theory: Docker architecture
    • Lab: Dockerfile static analysis
    • Lab: Docker Compose basics
  • Image Build and Delivery
    • Theory: Registry and image lifecycle
    • Lab: Slim Python images
  • Runtime Risk
    • Theory: Host boundary
    • Lab: Attacking Host mounts and privileged containers
    • Lab: Attacking Linux capabilities
    • Lab: Docker socket breakout via CVE-2025-3248
  • Image Audit
    • Theory: Image CVE scanners
    • Lab: Trivy image scan
  • Supply Chain
    • Lab: SBOM with Syft and Grype
  • Hardening
    • Lab: Secure container defaults
  • Thank you

Prerequisites

  • GitHub account with Codespaces enabled.
  • Browser that loads GitHub Codespaces normally.
  • Familiarity with the Linux command line.

⚠️ Important: steps that look like attacks are only for environments you are authorised to test. Do not use them on systems you do not own or lack written permission to assess.

About us

  • Anjali is a seasoned cloud security engineer, experienced in DevSecOps and Kubernetes security (EKS/GKE) as well as AWS, Azure, and GCP security. She is the founder of Container Security Village and Kubernetes Village, communities dedicated to enhancing cloud-native security. As the project lead for OWASP EKS Goat, she focuses on AWS EKS security research and hands-on exploitation paths. Anjali is a recognized AWS Community Builder and actively shares her research through her YouTube channel, @peachycloudsecurity. Her extensive speaking history includes Blackhat USA, Black Hat Spring USA, Black Hat Europe, Nullcon, Seasides Goa, BSides Bangalore, CSA Bangalore, and C0c0n. She has also contributed to the community by volunteering at Cloud Village at DEF CON and various BSides events globally.Reach out at peachycloudsecurity[dot]com

  • Divyanshu is a senior security engineer, experienced in Cloud Security, Kubernetes Security, DevSecops, Web Application Pentesting, and Threat Modelling. Reported multiple vulnerabilities to companies like Airbnb, Google, Microsoft, AWS, Apple, Amazon, Samsung, Zomato, Xiaomi, Alibaba, Opera, Protonmail, Mobikwik, etc, and received CVE-2019-8727 CVE-2019-16918, CVE-2019-12278, CVE-2019-14962 for reporting issues. Currently co-lead of OWASP EKS Goat, OWASP GKE Goat, Author of Burp-o-mation and a very-vulnerable-serverless application. Also part of AWS Community Builder for security and Defcon Cloud Village crew member 2020/2021/2022. Delivered talks at events like Blackhat USA, Europe, Seasides, C0c0n, Nullcon, Brucon, Bsides Bangalore and Bsides Ahmedabad. Also winner of “Cybersecurity samurai 2023” at Bsides Bangalore 2023 & “Cloud Security Champion’’ at CSA Bangalore 2023. Reach out at peachycloudsecurity[dot]com

Contact: Peachycloud Security

💝 Support the Project

Your support helps us maintain and improve this workshop, create more educational content, and continue building open-source security resources for the community.

Ways to Support:

Looking for personalized guidance? Get one-on-one mentorship, interview prep, or custom training sessions through our Topmate platform.

Disclaimer

  • The information, commands, and demonstrations presented in this lab including any course, are intended strictly for educational purposes. Under no circumstances should they be used to compromise or attack any system outside the boundaries of this educational session unless explicit permission has been granted.

    • This course is provided by the instructors independently and is not endorsed by their employers or any other corporate entity. The content does not necessarily reflect the views or policies of any company or professional organization associated with the instructors.
  • Usage of Training Material: The training material is provided without warranties or guarantees. Participants are responsible for applying the techniques or methods discussed during the training. The trainers and their respective employers or affiliated companies are not liable for any misuse or misapplication of the information provided.

  • Liability: The trainers, their employers, and any affiliated companies are not responsible for any direct, indirect, incidental, or consequential damages arising from the use of the information provided in this course. No responsibility is assumed for any injury or damage to persons, property, or systems as a result of using or operating any methods, products, instructions, or ideas discussed during the training.

  • Intellectual Property: This course and all accompanying materials, including slides, worksheets, and documentation, are the intellectual property of the trainers. They are shared under the GPL-3.0 license, which requires that appropriate credit be given to the trainers whenever the materials are used, modified, or redistributed.

  • References: Some of the labs referenced in this workshop are based on open-source material. Additionally, modifications and fixes have been applied using AI tools such as Amazon Q, ChatGPT, and Gemini.

  • Educational Purpose: This lab is for educational purposes only. Do not attack or test any website or network without proper authorization. The trainers are not liable or responsible for any misuse.

  • Usage Rights: Individuals are permitted to use this course for instructional purposes, provided that no fees are charged to the students.